Re: Weird IAS error with EAP-TLS



Res <Jagerkin@xxxxxxxxx> wrote in
news:dd53af17-5d7b-41e1-b193-c80ac024dbae@xxxxxxxxxxxxxxxxxxxxxxxxxxxx:

I had IAS on a Windows 2003 domain controller working with EAP-TLS and
computer certificates to authenticate Wireless clients a while back.
Since then many things have been messed with, so I'm open to any
suggestions on where to look. Upon trying to login wirelessly
recently, I get difficult to interpret errors:

Event Log:
-------------------------
Access request for user host/laptop.test.com was discarded.
Fully-Qualified-User-Name = test.com/Computers/LAPTOP
NAS-IP-Address = 192.168.1.100
NAS-Identifier = eap-ap
Called-Station-Identifier = 001c.0f83.09d0
Calling-Station-Identifier = 0040.96a3.b9ab
Client-Friendly-Name = AP1242AG
Client-IP-Address = 192.168.1.10
NAS-Port-Type = Wireless - IEEE 802.11
NAS-Port = 318
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Reason-Code = 1
Reason = An internal error occurred. Check the system event log for
additional information.
-------------------------

RASTLS:
-------------------------
RasEapGetInfo

EapTlsBegin(SSCN\NETWORKS-LZ$)
SetupMachineChangeNotification
Verifying caller...
Unauthorized use of TLS attempted
-------------------------

IASSAM
-------------------------
Creating EAP session
NT-SAM Names handler received request with user identity host/
laptop.test.com.
Successfully cracked username.
SAM-Account-Name is "TEST\LAPTOP$".
NT-SAM Authentication handler received request for TEST\LAPTOP$.
Validating Windows account TEST\LAPTOP$.
Sending LDAP search to dc1.test.com.
Successfully validated windows account.
NT-SAM User Authorization handler received request for TEST\LAPTOP$.
Using downlevel dial-in parameters.
Sending LDAP search to dc1.test.com.
Inserting attribute msNPAllowDialin.
Successfully retrieved per-user attributes.
Allowed EAP type: 13
Setting max. packet length to 1396.
RasEapBegin failed: Access is denied.
Caught COM exception: Access is denied.
-------------------------

I have validated that the group policy trusts third party and
enterprise trusted certificate authorities on the domain controllers.
I've made sure that the certificates listed on
http://support.microsoft.com/kb/293781/ were installed. I've tried
uninstalling and reinstalling, and I've tried installing fresh on a
different domain controller and copying over the configuration. (That
sums up the advice I've found online pertaining to this problem.)

Any ideas?

-- Res



Hi Res --

I pinged the product team with your question and received the following
response:

"The only time I have seen this is when an unsigned DLL is being used. In
this case, its RASTLS.dll, which should be fine, unless it was replaced by
a third party application (not unheard of).

"The easiest way to fix this is to reapply the latest service pack."


--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • RE: IAS server blues (Cant get 802.1x to work)
    ... clients. ... and it appears that the certificates are deploying correctly. ... Proxy-Policy-Name = Use Windows authentication for all users ... IAS Log Sample ...
    (microsoft.public.windows.server.general)
  • Re: Stronger password based HTTP client authentication?
    ... > That is as far as the SSL authentication goes. ... Well, SSL is able to authenticate the clients, too, with client X.509 ... it is not always feasible to distribute certificates to clients. ...
    (comp.security.misc)
  • Weird IAS error with EAP-TLS
    ... computer certificates to authenticate Wireless clients a while back. ... Proxy-Policy-Name = Use Windows authentication for all users ... NT-SAM Authentication handler received request for TEST\LAPTOP$. ... I've made sure that the certificates listed on http://support.microsoft.com/kb/293781/ ...
    (microsoft.public.internet.radius)
  • Re: Authenticating clients
    ... This can be done via certificates generated by client and verified by ... client and server authentication and encryption/decryption services to any ... > I have a client/server remoting setup, where only certain clients ...
    (microsoft.public.dotnet.framework.remoting)
  • Re: pine program and mail services with FC6 System
    ... protocols = imap imaps pop3 pop3s ... # Directory where authentication process places authentication UNIX sockets ... # chroot login process to the login_dir. ... # what most of your IMAP clients are. ...
    (Fedora)

Quantcast