NPS-RADIUS problems with authentication methods.
hi! have next scenario:
pki infrastructure: 1 offline standalone root ca (server a) , 1 enterprise subordinate ca (serverb). both windows server 2008 r2 enterprise. serverb 1 use give certificates.
servidor nps-radius (serverc): windows server 2008 r2, certificate of server issued serverb using template workstation.
access point (ap-radius): configured radius client on serverc.
the authentication method i'm using, is: eap-tls; clients i'm issuing certificates, either workstation or user certificate. both templates version 1 (windows 2000).
when connect access radius, prompts me user/pwd (maybe because have 2 rules, 1 has condition of 'domain users' , other asks 'domain computers'). here added rule in nps named 'only certificates':
under network policies:
condition: nas port - wireless ieee 802.11
policy enabled, grant network access.
restrictions: authentication methods: eap types: smart card or certificate - (eap-tls)
processing order: 2 (the 1st policy auths domain computers eap-tls, , 3rd, domain users)
note: on network request policy section, don't have enabled 'invalidate configuration of network authentication policy' (sorry i'm translating spanish) on policy.
but, when connect again on non-domain computer, still prompts me user/pwd. if type data, denies me access. when check log on nps-radius server, on event viewer find: motive code: 22 motive: client can't authenticated because server can't process eap type.
the question is: shouldn't asking me credentials, right? in event, shows me using network policy defined recently.
hi luis,
thanks posting here.
which windows version running on client computers ?
since these non-domain joined computer , should import ca client accessing ca website first. , suspect might not set network authentication method client either. suggest take links below , following introduction configure client:
configure wireless computers running windows vista use eap-tls
http://technet.microsoft.com/en-us/library/dd283057(ws.10).aspx
configure computers running windows xp use eap-tls
http://technet.microsoft.com/en-us/library/dd283002(ws.10).aspx
thanks.
tiger li
technet subscriber support in forum
if have feedback on our support, please contact tngfb@microsoft.com
please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.
Windows Server > Security
Comments
Post a Comment