802.1x, IAS and SecurID

From: Batkin, Seva (Seva_Batkin_at_canaccord.com)
Date: 09/26/03

  • Next message: freeasabird_13_at_gmx.net: "Re: protect MS Windows 95/98/Me"
    To: security-basics@securityfocus.com
    Date: Thu, 25 Sep 2003 19:54:11 -0700
    
    

    Hi All,

    I apologize in advance if this has been previously discussed. However, here
    are the questions I have.

    I have just completed setting up 802.1x system to secure our wireless
    communications. Specifically I have installed Microsoft IAS, enabled PEAP
    and integrated with our existing Domain Controller. I am currently using
    Windows XP SP1 clients but plan to test this on W2k as well.

    I have noticed strange behavior on the client, specifically persistent
    caching of the login credentials. I have disabled the "use windows logon
    credentials" checkbox in PEAP configuration and was once asked for username,
    password and domain. However it seems that once authenticated, XP requires
    no more intervention. Even if I logoff or reboot the machine, the password
    is still stored. I am wondering if there is anyway that this behavior could
    be changed, ideally I would like the user to enter the passwords much more
    often, at least after a reboot.
     
    The second issue I found is while integrating with RSA's securID system. I
    successfully installed the agent on the IAS server and it seems that the RSA
    module is now enabled. All the connections to the server are fine. The
    problem came when I changed the authentication method for PEAP form MSCHAPv2
    to RSA. The XP consistently tried to login using the same old credentials
    and would completely refused to ask for new login information. On the AP I
    could easily see that the IAS server (through EAP) would reply that previous
    credentials are no longer valid...something that the client appeared to
    ignore. Am I missing something here?
     
    Thanx for all your help

    Seva Batkin
    Sr. Network Engineer
    Canaccord Capital

    "Canaccord Capital Corporation <canaccord.com>" made the following
     annotations on 09/25/2003 07:54:15 PM
    ------------------------------------------------------------------------------
    This message may contain confidential or privileged material. Any use of this
    information by anyone other than the intended recipient is prohibited. If you
    have received this message in error, please immediately reply to the sender
    and delete this information from your computer. Thank you.
    ==============================================================================

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: freeasabird_13_at_gmx.net: "Re: protect MS Windows 95/98/Me"

    Relevant Pages

    • Re: Reason for domain controller not found message
      ... I would check DNS settings on the client, ... login. ... > I have a workstation with a user trying to log on to the domain who gets ... When I log in using my own domain credentials I can log in just ...
      (microsoft.public.windows.server.active_directory)
    • Remote Desktop in a Domain. Why doesnt putting a user in the domain group Remote allow remoting int
      ... and all login credentials used on the clients are domain ones. ... remote desktop enabled on the client computer with no local remote users ... credentials, and remote desktop, we get an error that a Group Policy ...
      (microsoft.public.windows.server.security)
    • RE: force credentials
      ... And my client sends credentials at login, ... not when I post data to the server. ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: BASIC authentication Issues with IE - Part II - Solved but WHY?
      ... it does not know the difference between a request from IE or from ... some other HTTP client. ... Some other authentication schemes are more ... IIS can sometimes remember the token for a particular set of credentials so ...
      (microsoft.public.inetserver.iis.security)
    • Re: Authentication woes
      ... I can not really understand how the client should connect to the DC when they are at work with the 192.x.x.x ip when the server is in 10.x.x.x network. ... If i read the output for the client it is member of domainb.internal and not member of domain.com like the DC, ... If the user logon with cached credentials, ...
      (microsoft.public.windows.server.active_directory)