RE: PEAP based 802.1x LAN authentication

From: Menicucci, Dan (dan0_at_pitt.edu)
Date: 04/07/05

  • Next message: Rodrigo Blanco: "Re: PEAP based 802.1x LAN authentication"
    Date: Wed, 6 Apr 2005 19:27:57 -0400
    To: "Rodrigo Blanco" <rodrigo.blanco.r@gmail.com>, <focus-ms@securityfocus.com>
    
    

    Hi Rob,

    We do it wih a Verisign certificate. The trusted root needs to be on
    the client machines and the certificate needs to be installed under the
    Personal folder of the Computer section of the certificate snapin.

    Thanks,
    Dan

    -----Original Message-----
    From: Won, Henry # PHX [mailto:henry.won@ndchealth.com]
    Sent: Wednesday, April 06, 2005 3:13 PM
    To: Rodrigo Blanco; focus-ms@securityfocus.com
    Cc: rodrigob@myway.com
    Subject: RE: PEAP based 802.1x LAN authentication

    We are using MS CA with IAS and only enhanced key usage listed is server
    authentication. If I remember correctly the RSA key size had to be 1024
    bits long. If it is bigger, try generating a new certificate with 1024
    bits instead.

    -----Original Message-----
    From: Rodrigo Blanco [mailto:rodrigo.blanco.r@gmail.com]
    Sent: Wednesday, April 06, 2005 8:42 AM
    To: focus-ms@securityfocus.com
    Cc: rodrigob@myway.com
    Subject: PEAP based 802.1x LAN authentication

    Hello list,

    I am currently trying to configure an Active Directory (w2K server) both
    for windows auth and also as RADIUS server (IAS) for LAN 802.1x
    authentication. I have successfully tried 802.1x with auth methods such
    as PAP, CHAP... and now am trying to move to PEAP so I can have joint
    AD/802.1x auth. with a single logon.

    According to
    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/S
    erverHelp/9d8b61c9-a870-4627-a8f2-148625fd7fba.mspx
    I should install MS CA and generate a certificate for the win2K server
    acting as AD/IAS.

    I do not want to use this CA, but openssl instead (XCA, in fact). With
    this, I have created a certificate with key usage = Server auth and
    installed both the CA certificate and this certificate through the
    browser.

    When I try to configure PEAP in the IAS Dial-in profile, I get an error
    message stating: "A certificate could not be found that can be used with
    this Extensible Authentication Protocol". I think some key usage or
    extended key usage attributes must be missing, or that I have created /
    installed the certificate wrong, but did not find the problem.

    Any help or ideas would be more than welcome.

    Thanks in advance,
    Rodrigo.

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    This E-mail message is for the sole use of the intended recipient(s) and
    may contain confidential and privileged information.  Any unauthorized
    review, use, disclosure or distribution is prohibited.  If you are not
    the intended recipient, please contact the sender by reply E-mail, and
    destroy all copies of the original message.
    ------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Rodrigo Blanco: "Re: PEAP based 802.1x LAN authentication"

    Relevant Pages

    • Re: New Event Log Errors!
      ... Somehow along those lines I'd also installed the Certificate Authority ... Did you apply the last Server Pack for SBS Server? ... Please install Windows Support Tools on the win2k3 sp1 problematic ... Microsoft is providing this information only as a convenience to you: ...
      (microsoft.public.windows.server.sbs)
    • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
      ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
      (microsoft.public.exchange.admin)
    • Re: Terminal Services over a VPN
      ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
      (microsoft.public.windows.terminal_services)
    • Re: Outlook RPC over HTTp deosnt work
      ... Go to remote web workplace (or Outlook Web Access), accept the certificate prompt, 'view', and 'install' the certificate - accepting all the defaults. ... > when you try to use RPC over HTTP to connect the Exchange Server. ...
      (microsoft.public.windows.server.sbs)
    • Re: windows mobile 6
      ... I installed a GoDaddy certificate on the sbs server with no problem. ... The problem is that the certificate is a .crt file and my WM6 device doesnt recognise this file extention. ... The question is how do i install the certificate. ... When a computer uses RWW it downloads the certificate automatically from the server, why doesnt WM6 do the same? ...
      (microsoft.public.windows.server.sbs)