Re: Wireless Security



"Redleg6" <redleg6@xxxxxxxxxxxxxxxx> wrote in
news:ONtzmeZ8IHA.5712@xxxxxxxxxxxxxxxxxxxx:

In our hospital we have a Win2003 domain with about 150
workstations.Six workstations are "Cows" (computer on wheels) that use
a wireless connection to pass senstive medical information. AP's are
Cisco. The wireless part of the connection is secured using EAP-TLS
with user certificates. We are using an Enterprise CA to issue the
certificates. We cannot use autoenrollment for certificates because we
do not have a Window2003 Enterprise server.

We are considering expanding the use of wireless workstations to 50 or
more. This presents an issue for our very small IT staff. Each
wireless workstation is used by about 20 people which means 20 user
certificates have to be installed/manged on each COW.

Question: is there another design that would still provide EAP-TLS
level security for our wireless network with having so many
certificates to manage? Or is there a way to install the certificates,
in-mass, rather than one at a time.


I see two choices, switch from EAP/TLS to PEAP, which only requires a
cert on the RADIUS server, or swtich the machines to do machine
authentication only via the registry:

HKLM\Software\Microsoft\EAPOL\Parameters\General\Global\AuthMode=2

HTH,

Wayne Tilton
.



Relevant Pages

  • Re: Certificates for Wireless Networks
    ... You are growing to the number of workstations where autoenrollment is the ... wireless part of the connection is secured using EAP-TLS with user ... We are using an Enterprise CA to issue the certificates. ...
    (microsoft.public.windows.server.security)
  • Certificates for Wireless Networks
    ... workstations are "Cows" that use a wireless connection ... the connection is secured using EAP-TLS with user certificates. ... We are considering expanding the use of wireless workstations to 50 or more. ...
    (microsoft.public.windows.server.security)
  • Wireless Security
    ... workstations are "Cows" that use a wireless connection ... the connection is secured using EAP-TLS with user certificates. ... We are considering expanding the use of wireless workstations to 50 or more. ...
    (microsoft.public.windows.server.networking)
  • Re: Certificates for Wireless Networks
    ... authentication instead of user authentication for the wireless access. ... Even though EAP-TLS implies use of both computer and user certificates, ... You are growing to the number of workstations where autoenrollment is the ...
    (microsoft.public.windows.server.security)
  • Re: Wireless connection (WPA-EAP) stops working after a while
    ... I have a problem with my wireless connection. ... At home using the Atheros card together with a FreeBSD based ... What works in the case of the Ralink USB adapter is simply unplugging ...
    (freebsd-current)

Quantcast