IAS forwarding / Multi-Forest / CA Requirement - trusted authority in PEAP properties



Hello,

Scenario:

* Setup for 802.1x machine only authentication. "Protected PEAP"
* 2 forests, 1 domain in each.
* IAS is setup to forward requests to other domain if a computer
starts 802.1x authentication on it's switch.
* Forwarding is working great between forests.

Problem:

As part of the migration strategy, I need to manually check the CA
root to trust in the PEAP properties on the client machines for cross-
forest forwarding between IAS servers. This is fine to do with a few
clients, but need to automate this because there are alot. Here is
the location:

Network Connections --> Local Area Connection --> Properties -->
Authentication Tab --> Properties --> "Trusted Root Authority"

a) I need to be able to automate the selection of the Root Certificate
Authority. Otherwise I have to check this manually during the
migration (and co-existance). How do I do this?

I have looked into a registry key and placed the thumbprint hash of
the CA in it with no success:

IEEE 802.1x Certificate Authority for Machine Authentication
HKLM\Software\Policies\Microsoft\Windows\Network Connections\8021X!
8021XCARootHash

b) Is there a special format for this HASH value other than the obious
"aa bb cc dd" ???

c) With this registry key present, will this work even if the box is
not visually checked?

Thanks in advance!

-Greg

.



Relevant Pages

  • Re: RADIUS (IAS) and Cisco Concentrator? (PDF Attachment)
    ... The order the radius statements in IOS will determine the order the ... IAS servers are checked. ... RADIUS client what policy to use? ... I'm not sure what this is, but if it refers to a secure authentication ...
    (microsoft.public.windows.server.active_directory)
  • RE: check group membership in Connection Request Policy
    ... The access request does not contain a valid user password, ... Authentication is done at the VPN3000, ... So what data does the VPN3000 send to the IAS? ... a custom IAS extension would be really a solution. ...
    (microsoft.public.internet.radius)
  • Re: 802.1X/EAP authentication issue with XP client
    ... I also tried adjusting the IAS remote access policy framed MTU param ... client, same scenario, is not getting a successful authentication. ... or system event logs. ...
    (microsoft.public.internet.radius)
  • Re: RADIUS (IAS) and Cisco Concentrator? (PDF Attachment)
    ... so I simple copy the settings to another IAS server and register in AD then the new one will be a failover? ... Registering IAS with AD effectively tells AD not to accept External Authentication requests from other sources. ... You can have multiple IAS servers registered at the same time, so you can tell your Concentrator to follow a chain of servers if the first one doesn't respond. ... At the bottom of the properties window, select "Grant remote access permission" and then click OK. ...
    (microsoft.public.windows.server.active_directory)
  • RE: check group membership in Connection Request Policy
    ... The access request does not contain a valid user password, ... We already do 802.1x authentication with our Enterasys switches, ... IAS is not able to do authentication, since digital certificates are used on ... I am intereseted in your custom IAS extension. ...
    (microsoft.public.internet.radius)

Loading