RE: 802.1x, Computers, Wired Security
- From: v-mileli@xxxxxxxxxxxxxxxxxxxx (Miles Li [MSFT])
- Date: Tue, 19 Aug 2008 10:55:19 GMT
Hello,
As the User authentication using PEAP/MSCHAPv2 is working, the 802.1X wired
service on the Windows XP SP3 should functions properly. However, because
the TLS with certificates needs the certificate that enrolled from the CA.
Please verify the certificates on the client machine that connect to 802.1x
wired network as I mentioned in my previous post.
814394 Certificate requirements when you use EAP-TLS or
PEAP with EAP-TLS
http://support.microsoft.com/kb/814394
Client side:
1. Is there a computer certificate that enrolled from the domain CA?
2. Does computer certificate on the client chain to a trusted root? Can you
verify the certificate path successfully?
- You can select the trusted root certification authorities in the
Network Connection--->properties--->authentication tab--->PEAP settings
(PEAP properties).
3. Do you select the Smart card or other certificate (you used to use
MSCHAPv2) as the Authentication method for PEAP?
4. Does the computer certificate have the Client Authentication purpose?
Server side:
1. Does the option "validate server certificate" is chosen on the client?
If yes, please verify the IAS
Server's computer certificate for Server Authentication purpose and its
certificate path .
Hope it helps. If you have any questions or concerns, please do not
hesitate to let me know.
Best regards,
Miles Li
Microsoft Online Partner Support
Microsoft Global Technical Support Center
Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
.
- Follow-Ups:
- RE: 802.1x, Computers, Wired Security
- From: doubleH
- RE: 802.1x, Computers, Wired Security
- References:
- RE: 802.1x, Computers, Wired Security
- From: doubleH
- RE: 802.1x, Computers, Wired Security
- From: Miles Li [MSFT]
- RE: 802.1x, Computers, Wired Security
- From: doubleH
- RE: 802.1x, Computers, Wired Security
- From: Miles Li [MSFT]
- RE: 802.1x, Computers, Wired Security
- From: doubleH
- RE: 802.1x, Computers, Wired Security
- From: Miles Li [MSFT]
- RE: 802.1x, Computers, Wired Security
- From: doubleH
- RE: 802.1x, Computers, Wired Security
- Prev by Date: Re: Adding a Windows 2003 R2 DC into a 2000 Domain
- Next by Date: Re: Query Based Distribution Group
- Previous by thread: RE: 802.1x, Computers, Wired Security
- Next by thread: RE: 802.1x, Computers, Wired Security
- Index(es):
Relevant Pages
|