Alan, Thanks for the quick response. The reason I generated my own certs was that if we can get 802.1x to work, when we move to production we will want to have the certificate signed by our Windows CA. So I wanted this to be part of the test plan.
I looked at that webpage at least three times today. I think I am so glued to the issue that the xpextension are missing or wrong, but when I view the certificate issued by our CA, it does have the attributes there with an OID of 1.3.6.1.5.5.7.3.1 for Server Certificate Requirements. http://freeradius.1045715.n5.nabble.com/file/n3340698/cert.jpg Are you referring to the Debugging it yourself section? I am in the process of installing screen and going through those steps. Thanks -Robert -- View this message in context: http://freeradius.1045715.n5.nabble.com/FW-Problem-with-PEAP-MS-ChapV2-against-AD-tp3340563p3340698.html Sent from the FreeRadius - User mailing list archive at Nabble.com. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html