Re: 802.1x EAP - TLS authentication with AD Computer Account WM2003/5



Did you get anywhere with this? I would like to do something similar; hence
the interest.

Thanks
Roger

"Roland Knoerl" <RolandKnoerl@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:88212C4C-8031-4BF4-80E8-210995CC8C10@xxxxxxxxxxxxxxxx
Installation:
- Windows 2003 Server with AD and IAS
- AD with computer account (user account not allowed for PDA)
- Computer certificate on PDA with computer account FQDN
- Certificate was installed on the PDA in the certificate store

Hello all,
we were able to install a computer certificate in the certificatestore on
a
Windows Mobile 2003/05 PDA.
We tried to get WLAN access via WPA/TKIP/802.1x, but the IAS-RADIUS-Server
can not find the account for that FQDN in AD.
The problem is, that the IAS always searches for a user account and not
for
a computer account to verify the PDA. The reason for that is, that IAS
does
not get the authentication string "host/accountname.domain.local", the PDA
always sends the "accountname.domain.local" string to authenticate as a
user
and not as computer. We also tried to let the PDA authenticate with a
username like "host/computeraccountname" and its domain. But that also
doesn't work.

Is it possible to let a Windows Mobile PDA authenticate via 802.1x/EAP-TLS
with a computer account and certificate ?

Hope you guys can help us.

Thanks in advance !

Regards,
Johannes and Roland



.



Relevant Pages

  • RE: Help - Cant Get Software to Put Calendar on my Pocket PC
    ... I understand that after disabled SSL, the HTTP_403 error occurs when you using ActiveSync on the PDA. ... please make sure that you're properly configured your CEICW to make your public domain name ... or public IP address as your certificate. ... >> Exchange server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Activesync 3.8 and HTTP_401 error
    ... I have run the wizard and made a certificate. ... importing to the PDA as it still isn't working correctly. ... >> exchange 2003 using the cradle and USB which nobody seems to know the ... >>> reconfigure your PPC to connect Exchange server to see if the issue can ...
    (microsoft.public.windows.server.sbs)
  • RE: Help - Cant Get Software to Put Calendar on my Pocket PC
    ... I am trying to do two things overall - one is a general synch when the PDA ... Proceed to the web certificate page and make sure that you're using your public domain name or public IP address as your certificate. ...
    (microsoft.public.windows.server.sbs)
  • Re: Synchronization failed due to an incorrect SSL certificate common name
    ... If I disable SSL checking, ... The problem now is I can't work out which certificate is the correct one to ... Authorities on the server and workstations, and imported it into the PDA, ... To sync with the self generated ...
    (microsoft.public.pocketpc.activesync)
  • Re: Using SSL with Smartphone Emulator
    ... you could validate the certificate in your code by ... The server is an internal development server and the PDA ... >> not trust the server?! ...
    (microsoft.public.dotnet.framework.compactframework)