RE: 802.1X configuration for IAS and Cisco WLC 4402

Tech-Archive recommends: Fix windows errors by optimizing your registry



=?Utf-8?B?TGlicmFyeSBTeXNhZG1pbg==?=
<LibrarySysadmin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:0D8C112A-EF7D-490C-B325-54BCA01AB769@xxxxxxxxxxxxx:

James,

I read through at least a dozen Technet and Cisco documents pertaining
to the various aspects of this configuration.

In looking at the ones that I have bookmarked, they don't specifically
state that PEAP-MSCHAPv2 needs a certificate. I think it's just that
these docs are describing several configurations and when you start
walking through the steps to configure everything, it's easy to miss
the line that PEAP-MSCHAPv2 doesn't need a cert and continue on.

Rick

OK, thanks for the followup, Rick.

For others who aren't familiar with PEAP-MS-CHAP v2, if you want to use
mutual authentication, where the client authenticates the IAS/NPS server in
addition to the server authenticating the client/user, the IAS or NPS
server must have a server certificate that meets the minimum server
certificate requirements. Also, client computers must be configured to
validate the server certificate. (Ideally client configurations are pushed
to clients with Group Policy.)

Thanks --

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
.



Relevant Pages

  • Re: Joining client to domain
    ... I was checking messages and came across this post, because I have ran MS virtual PC on many occasions to test for configurations or beta testing (just recently server 2008) and I was wondering if I could add my 2 cents. ... However when you try to join the workstation (assuming that is what you are calling your client pc), have you tried just entering the domain controller name only. ... Click More to change the primary Domain Name System (DNS) suffix. ...
    (microsoft.public.cert.exam.mcsa)
  • RE: Client based Certificates
    ... | a server certificate why would you have to go and buy ... certificate is to security context like a user account. ...
    (microsoft.public.inetserver.iis.security)
  • em/amd64 on 6.0-RC1
    ... under several different configurations to try and pin down ... pinging from the server to the client works. ...
    (freebsd-current)
  • Re: SSL Query
    ... both the client and server in situation ... Server will have Server Certificate and Client ... public key and Client will encrypt a message using Server's public key. ...
    (microsoft.public.security)
  • Re: How to ensure Im doing lwp with https correctly?
    ... SSL_connect:before/connect initialization ... SSL_connect:SSLv2/v3 write client hello A ... SSL_connect:SSLv3 read server certificate A ...
    (comp.lang.perl.misc)