How secure is EAPOL registery key?

From: Tim Guy (tim_at_hurtwood.demonREMOVE.SPAM.co.uk)
Date: 10/23/03


Date: Thu, 23 Oct 2003 08:48:55 +0100

I'm looking at implementing wireless 802.1x into a site where the laptops do
not belong to the infrastructure supplier.

I was going to use PEAP with a domain user and password created for the
computer not for the user.

The infrastructure IT dept will put the username, password and root CA into
the laptop for the laptop owner and then the user continues to use the
laptop with the local account.

The problem is how secure is the EAPOL reg key where the PEAP username and
password is kept. If I look with regedit it seams to be encrypted but I'm
not sure if it could be brute forced or not.

If it could I would consider using certificates but I can also see that with
an open laptop these certificates could be exported and import into another
laptop thus making that pretty pointless too.

Any thoughts?

Tim



Relevant Pages

  • Certificates - Multiple machines - one user
    ... I've got a question about users certificates. ... begun issuing certs to users. ... authentication, both for wireless and wired connections. ... key's on the laptop and can therefore not authenticate to the network. ...
    (microsoft.public.security)
  • RE: EPS
    ... are stored in the laptop user's profile directory and protected with a hash ... General information about EFS and data recovery: ... importing of certificates. ... We Encrypt all the folders on the PC. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Certifcate error?!?
    ... think its the website, just on my laptop. ... Windows comes pre-loaded with a set of trusted certificates. ... "Trusted Root Certification Authorities" tab. ...
    (microsoft.public.windowsxp.general)
  • Encrypting with exported keys easily?
    ... I have a laptop running Windows 2000 containing very sensitive data ... that is going to travel twice a week with some not-too-technical users. ... I would like to make that laptop as secure as possible. ... I had intended to use EFS and store the certificates on a pendrive. ...
    (microsoft.public.win2000.file_system)
  • Re: How secure is EAPOL registery key?
    ... > the laptop for the laptop owner and then the user continues to use the ... > laptop with the local account. ... > The problem is how secure is the EAPOL reg key where the PEAP username and ... > an open laptop these certificates could be exported and import into ...
    (microsoft.public.windows.server.security)