Wireless Authentication using Computer Certificate


hi all,

my background in networking quite weak feel free correct me @ point.

we're implementing 802.1x wireless clients, using computer certificates authentication.  have enterprise ca architecture, , auto-enrollment setup through group policies.

my questions are:

1) brand new devices, necessary connect them wired network obtain computer certificate first time, because wouldn't able connect wirelessly?  workaround this?

2) same necessary when computer certificate expire?  how devices computer certificate has expired (e.g. unused computers)?

3) how wireless group policies (in win2k8 domain) play in scenario?

thanks in advance.


 

hi,

thanks posting here.

>1) brand new devices, necessary connect them wired network obtain computer certificate first time, because wouldn't able connect wirelessly?  any workaround this?

are referring windows based devices? if going enroll via group policy yes, have make wired connect domain controller in order obtain certificate , other wireless network settings form domain controller. can manually import or obtained web enrollment tool . please refer link below:

http://social.technet.microsoft.com/forums/en-us/winservernap/thread/3d09809b-ca5d-4486-845d-fe061547ddba

certificates , nps

http://technet.microsoft.com/en-us/library/cc772401(ws.10).aspx

>2) same necessary when computer certificate expire?  how devices computer certificate has expired (e.g. unused computers)?

then can renewal via group policy if domain member host:

configure certificate autoenrollment

http://technet.microsoft.com/en-us/library/cc731522.aspx

>3) how wireless group policies (in win2k8 domain) play in scenario?

this manage permission , apply wireless settings dedicate hosts.

for more information please refer guide below:

802.1x authenticated wireless access

http://technet.microsoft.com/en-us/library/cc771455(ws.10).aspx

thanks.

tiger li


tiger li

technet community support



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS