PEAP-MS-CHAPv2 - mobile devices and certificates
i'm looking secure our wireless infrastructure , chapv2 seems need have couple of concerns.
our external domain company.net our internal domain nps server sit domain.company.local
we have lot of mobile devices - on domain, not.
i'm happy use internal certificate or 3rd party certificate, given different domain suffixes, going possible? if use certificate subject name domain clients won't trust it. if use subject name of company.net, no clients trust nps server.
how domain pcs , domain/non-domain mobile devices trust , connect nps server?
hi,
when deploy 802.1x authenticated wireless access uses peap-ms-chap v2, radius servers must have digital certificates in order perform mutual authentication. issue certificates nps servers have option of deploying private ca on network, or purchasing server certificate third party certification authority.
during peap-ms-chap v2 authentication, ias or radius server supplies certificate validate identity client. client computer , user authentication accomplished passwords, eliminates of difficulty of deploying certificates wireless client computers.
since user authentication performed password-based credentials, not certificates, certificate issued nps use internal domain suffix. non-domain member computers must have private ca certificate manually installed in trusted root certification authorities certificate store them trust certificates, such nps server certificates, issued private ca.
besides, users in internal domain? if users in 2 domains, have 2 options,
- create a two-way forest trust both sides of trust.
- install new nps server in external domain.
for detailed information, please refer link below,
create two-way, forest trust both sides of trust
http://technet.microsoft.com/en-us/library/cc778851(v=ws.10).aspx
certificates , nps
http://technet.microsoft.com/en-us/library/cc772401(v=ws.10).aspx
peap-ms-chap v2-based authenticated wireless access design
http://technet.microsoft.com/en-us/library/dd348500(v=ws.10).aspx
hope helps.
steven lee
technet community support
Windows Server > Network Infrastructure Servers
Comments
Post a Comment