RE: PEAP based 802.1x LAN authentication

From: Won, Henry # PHX (henry.won_at_ndchealth.com)
Date: 04/06/05

  • Next message: Wes DiBlasi: "RE: Windows Server 2003 Service Pack 1"
    Date: Wed, 6 Apr 2005 12:13:07 -0700
    To: "Rodrigo Blanco" <rodrigo.blanco.r@gmail.com>, <focus-ms@securityfocus.com>
    
    

    We are using MS CA with IAS and only enhanced key usage listed is server
    authentication. If I remember correctly the RSA key size had to be 1024
    bits long. If it is bigger, try generating a new certificate with 1024
    bits instead.

    -----Original Message-----
    From: Rodrigo Blanco [mailto:rodrigo.blanco.r@gmail.com]
    Sent: Wednesday, April 06, 2005 8:42 AM
    To: focus-ms@securityfocus.com
    Cc: rodrigob@myway.com
    Subject: PEAP based 802.1x LAN authentication

    Hello list,

    I am currently trying to configure an Active Directory (w2K server) both
    for windows auth and also as RADIUS server (IAS) for LAN 802.1x
    authentication. I have successfully tried 802.1x with auth methods such
    as PAP, CHAP... and now am trying to move to PEAP so I can have joint
    AD/802.1x auth. with a single logon.

    According to
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/S
    erverHelp/9d8b61c9-a870-4627-a8f2-148625fd7fba.mspx
    I should install MS CA and generate a certificate for the win2K server
    acting as AD/IAS.

    I do not want to use this CA, but openssl instead (XCA, in fact). With
    this, I have created a certificate with key usage = Server auth and
    installed both the CA certificate and this certificate through the
    browser.

    When I try to configure PEAP in the IAS Dial-in profile, I get an error
    message stating: "A certificate could not be found that can be used with
    this Extensible Authentication Protocol". I think some key usage or
    extended key usage attributes must be missing, or that I have created /
    installed the certificate wrong, but did not find the problem.

    Any help or ideas would be more than welcome.

    Thanks in advance,
    Rodrigo.

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    This E-mail message is for the sole use of the intended recipient(s) and may contain confidential and privileged information.  Any unauthorized review, use, disclosure or distribution is prohibited.  If you are not the intended recipient, please contact the sender by reply E-mail, and destroy all copies of the original message.
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Wes DiBlasi: "RE: Windows Server 2003 Service Pack 1"

    Relevant Pages

    • Re: Need help configuring Wireless Connection profile
      ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless ... Vaillancourt,4155,1,4154,Use Windows authentication for all ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
      (microsoft.public.windowsxp.general)
    • Re: Need help configuring Wireless Connection profile
      ... "point" the info of the Radius authentication to your current Radius server. ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
      (microsoft.public.windowsxp.general)
    • Re: OWA 2003 w/ Smart Card Authentication.
      ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
      (microsoft.public.exchange.connectivity)
    • Need help configuring Wireless Connection profile
      ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
      (microsoft.public.windowsxp.general)
    • Re: Need help configuring Wireless Connection profile
      ... "point" the info of the Radius authentication to your current Radius server. ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
      (microsoft.public.windowsxp.general)