Re: Security - WLAN WPA(2) 802.1x, PKI/CA, IAS/Radius, Windows 2003 AD



Friedrich Stockhammer <fritz@xxxxxxxxxxxxxx> wrote in
news:1tnpq29p95shpk331jr18mr1j8p04m5ak3@fqdn:

Hi,
two questions:
Need the IAS/radius server (runs on a windows 2003 DC) a own
certificate when we want to use a WLAN - WPA(2) 802.1x

The clients and the user have your own certificate.

On the DC/IAS server are an old, expired certificate.

We (admins, domainadmin's, enterpriseadmin's) cannot renovate this
certificate or request a new certificate.

It comes an error: .... you dont have the required rights ....

Which additional rights are needed to request certificates for
servers?

On CA server
On the server who request
In active directory

fup2: microsoft.public.internet.radius

Hi Friedrich --

You need membership in both the Enterprise Admins and the root domain's
Domain Admins group.

You might want to just configure auto-enrollment for IAS servers. The
directions on how to do this are in the following whitepaper:

"Enterprise Deployment of Secure 802.11 Networks Using Microsoft Windows"
at
http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/ed80211.mspx

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: Need help configuring Wireless Connection profile
    ... and I can only use the intel OR windows utility, not both at the same time. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Cannot sync Windows mobile with sbs2003 server
    ... Windows Mobile OS to the SBS2003 server at work so that he can read e-mails. ... What certificate do Microsoft recommend here, and where can this be bought? ...
    (microsoft.public.pocketpc)
  • Re: Issues with SSL on Win CE 5.0
    ... There is a Certificate in the HKCU under MY. ... This posting is provided "AS IS" with no warranties, and confers no rights. ... creating the .pfx file, the private keys need to be marked as exportable ... the server certificate you're trying to add is present under ...
    (microsoft.public.windowsce.embedded)
  • Re: Need help configuring Wireless Connection profile
    ... Now life is good in the Windows wireless world. ... now have a secure wireless setup within my small business server environment. ... "point" the info of the Radius authentication to your current Radius server. ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: EAP-TLS with windows CE
    ... credentials at the login prompt for Windows Server 2003 on the server ... The certificate is a public thing, ... When the server asks the Windows CE device to identify itself, ... I could easily steal your authentication information. ...
    (microsoft.public.windowsce.platbuilder)