Re: EAP types

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 12/09/04


Date: Thu, 9 Dec 2004 19:49:12 +1100

You can do that.

1. You can disable reauthentication through Wireless GPO (set Computer
Authentication to Computer Only). There is a corresponding registry key.
2. I believe you can create two separate IAS policies for users and
computers. this would be a better approach, as you cannot trust
computer-only authentication - computers can be cloned easily.

-- 
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-
"MToddH" <MToddH@discussions.microsoft.com> wrote in message
news:12900A9F-0D08-4513-A042-59BC13DF7785@microsoft.com...
> I am working on implementing 802.1x with EAP-TLS.  My requirement is that
the
> authentication requires a client certificate, not just server side.  My
> understanding is that EAP-TLS requires both user & computer certifcates.
> This is nice, but a little overkill for our implementation.  Is there a
way
> to implement EAP that only requires a computer certificate for the
clients,
> but uses user name and password for user authentication?  Can  I implement
> PEAP to do this?


Relevant Pages

  • Re: OWA boots my clients out
    ... It happens on both the Internet and Intranet using forms based authentication. ... I have checked the registry key in question and it is set for 20. ...
    (microsoft.public.exchange.admin)
  • OK, now it works with the registry key, it was my fault
    ... now it works with the registry key LoginMode setting. ... that after reinstalling MSDE SP3 there are no network protocols active. ... > authentication. ...
    (microsoft.public.sqlserver.msde)
  • Re: OWA boots my clients out
    ... >> I have checked the registry key in question and it is set for 20. ... >>> Is there any difference if you login to OWA on the Internet or Intranet? ... >>> Are you using forms based authentication? ... >>> the client will time out after 15 minutes. ...
    (microsoft.public.exchange.admin)
  • Re: EAP-TLS without user certificate?
    ... The settings for the authentication mode are controlled by the registry key ... A short description of the behavior for each of the AuthMode values is ... machine auth, say validating server certificate, it will offer the pop-up to ...
    (microsoft.public.win2000.security)
  • Re: Need for encryption in WSE 3.0 if using SS-avoid man-in-middle
    ... for client certificate authentication, simply require SSL client certificates in IIS (directory security tab). ... If you use WSE message layer security, the "mutualCertificate10" and ...
    (microsoft.public.dotnet.framework.aspnet.security)