MS-CHAP V2 and server certs



I have a question about IAS, PEAP
MS-CHAP V2, and wireless. I am using MS-CHAP V2 to authenticate PDAs
on our wireless network. Because we are using MS-CHAP V2, we are using

AD credentials to authenticate the clients. Everywhere I have read it
states that we have to install the server certificate onto the device.
I have found a loop hole though. Both on the wireless PDA and laptops,

we can choose not to validate the server certificate. I can still
authenticate to the IAS server (wireless) but I have not installed the
server cert onto the device (because I have unchecked the validate
server checkbox both in zero config and the wireless application).
This is my question, if we don't validate the server and if we don't
have the server cert, won't the transmission of the user account and
password be in clear text? Is there a way on the IAS server that we
have to force the clients to have the server cert or they wont be
authenticated?

Thanks,
Peter Kim

.



Relevant Pages

  • Re: help with server config
    ... Wireless cards can complicate a things a bit in that often the wireless ... the startup process [both computer and user authenticate to the domain]. ... resources until a domain controller can be contacted which it usually can be ... > in one) and am using 1 PCI wireless NIC in the server. ...
    (microsoft.public.cert.exam.mcse)
  • question about IAS and PEAP MS-CHAP V2 (wireless authentication)
    ... MS-CHAP V2, and wireless. ... I am using MS-CHAP V2 to authenticate PDAs ... AD credentials to authenticate the clients. ... states that we have to install the server certificate onto the device. ...
    (microsoft.public.security)
  • Aironet 1200/MS Radius Help - Yet Again
    ... Your collective help thus far has made me understand more about wireless ... RADIUS/IAS Server. ... I also got a certificate from verisign to install on one of the two IAS ... there are communications between the client and access ...
    (microsoft.public.internet.radius)
  • Re: Requiring User Name and Password for Connection to Network Res
    ... If you don't have a matching account on the server, and if the Guest account on ... then the server should request that you authenticate ...
    (microsoft.public.windowsxp.network_web)
  • Re: Allowing Mail from an appliance &/or other Mail server
    ... this virtual server and restrict by the ip address for the security. ... accomplished by limiting which IP addresses can connect to your SMTP ... Outlook users do not need smtp connectivity to Exchange servers - they ... your smtp relay server configured to authenticate as well. ...
    (microsoft.public.exchange.connectivity)