RE: EAP-TLS with IAS





"Yvan" wrote:

Sebastian,

I looked into the "certificate mapping" but now I have another problem :

I Replaced the username in the certificate in a username known by AD but
know I have following error :

User lammensy was denied access.
Reason = A certificate chain processed, but terminated in a root
certificate which is not trusted by the trust provider.

Do you know where I can start my search for a solution ?

It looks like your root certificate is not trusted (not contained
in the trusted root certificate store). For a short test you might
try to import your root cert manually using the cert mmc snap-in.


Sebastian


"rt-seb" wrote:


"Yvan" wrote:

Sebastian,

so what you say is that the user for who the certificate is created must be
in Active Directory ?

Yes, the IAS always seems to perform an AD lookup for user/machine accounts.
You might search for "certificate mapping" if that is what you want.


many thanks,
Yvan

"rt-seb" wrote:

Hello Yvan,

"Yvan" wrote:

Hello,

I have a question (problem).

We have in production a wireless network with IAS and PEAP MS-CHAPv2
authentication.
This works fine!

Now we want to move to EAP-TLS.
We have an local CA that is providing user and server certificates and that
all works fine.
EAP-TLS is working on our own domain with our own CA.

Now we want to move to a global solution were a CA in our central
headquarters is providing the User and server certificates.
I have a user and server certificate installed on my machine and a signed
certificate for the server on the IAS, but this doesn't work.

When I try to authenticate I always have this error in the event log :

User ylammens001 was denied access.
Fully-Qualified-User-Name = ulabo\mensch
NAS-IP-Address = 192.54.49.3
NAS-Identifier = Trapeze
Called-Station-Identifier = 00-0B-0E-29-48-80:global
Calling-Station-Identifier = 00-15-00-01-B5-CD
Client-Friendly-Name = wlanswitch02
Client-IP-Address = 192.54.49.3
NAS-Port-Type = Wireless - IEEE 802.11
NAS-Port = <not present>
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = EAP
EAP-Type = <undetermined>
Reason-Code = 8
Reason = The specified user account does not exist.




He is pulling my name out of the certificate and try to find it in our ulabo
domain but it isn't there, he don't have to search it there.

If I well understood IAS doesn't even have to search for my name but can
allow me because he has the signed server certificate.

Am I correct about this ?

How can I prevent IAS to search for my name in the domain ?


Can you help me ?

I'm citing the "Network access authentication and certificates" technet
article
regarding client certificate requirements:

"The client certificate is issued by an enterprise CA or mapped to a user or
computer account in Active Directory."

Sebastian
.



Relevant Pages

  • Re: Need help configuring Wireless Connection profile
    ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless ... Vaillancourt,4155,1,4154,Use Windows authentication for all ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: PEAP-TLS vs EAP-TLS
    ... It covers the deployment of PEAP with digital certificates (what you are ... PEAP-TLS as MS docs pretty much all were about PEAP-MSCAHPV2 or generally ... Of course user certificate authentication used in PEAP-TLS ...
    (microsoft.public.windows.server.security)
  • Re: Need help configuring Wireless Connection profile
    ... Just go there and do a search for 'WPA2'. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Need help configuring Wireless Connection profile
    ... Just go there and do a search for 'WPA2'. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Need help configuring Wireless Connection profile
    ... Well there is an update on the microsoft site for WPA2 encryption but I ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)

Loading