PEAP-MS-CHAPv2 - mobile devices and certificates


i'm looking secure our wireless infrastructure , chapv2 seems need have couple of concerns.

our external domain company.net our internal domain nps server sit domain.company.local

we have lot of mobile devices - on domain, not. 

i'm happy use internal certificate or 3rd party certificate, given different domain suffixes, going possible?  if use certificate subject name domain clients won't trust it.  if use subject name of company.net, no clients trust nps server.

how domain pcs , domain/non-domain mobile devices trust , connect nps server?

hi,

when deploy 802.1x authenticated wireless access uses peap-ms-chap v2, radius servers must have digital certificates in order perform mutual authentication. issue certificates nps servers have option of deploying private ca on network, or purchasing server certificate third party certification authority.

during peap-ms-chap v2 authentication, ias or radius server supplies certificate validate identity client. client computer , user authentication accomplished passwords, eliminates of difficulty of deploying certificates wireless client computers.

since user authentication performed password-based credentials, not certificates, certificate issued nps use internal domain suffix. non-domain member computers must have private ca certificate manually installed in trusted root certification authorities certificate store them trust certificates, such nps server certificates, issued private ca.

besides, users in internal domain? if users in 2 domains, have 2 options,

  • create a two-way forest trust both sides of trust.
  • install new nps server in external domain.

for detailed information, please refer link below,

create two-way, forest trust both sides of trust

http://technet.microsoft.com/en-us/library/cc778851(v=ws.10).aspx

certificates , nps

http://technet.microsoft.com/en-us/library/cc772401(v=ws.10).aspx

peap-ms-chap v2-based authenticated wireless access design

http://technet.microsoft.com/en-us/library/dd348500(v=ws.10).aspx

hope helps.



steven lee

technet community support



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS