RE: Problem with machine authentication on Windows 2000usingfreeradius, eap-tls, wireless

2004-02-03 Thread Wieck, Owen
#x27;re using Win2K... does the certificate CN match the machine > name? I discovered that Windows 2000 actually seems to > enforce that the > CN or subjAltName match the name of the machine (ie, NetBIOS name or > FQDN DNS name). > > --Mike > > > On Tue, 2004-02-03 at 15:3

RE: Problem with machine authentication on Windows 2000usingfreeradius, eap-tls, wireless

2004-02-03 Thread Wieck, Owen
sure. I don't suppose there's a way to bypass that? Is it just a Win2k thing? > > > On Tue, 2004-02-03 at 15:30, Wieck, Owen wrote: > > Thanks for the quick response. Yes to both questions. The > CA cert is in the Trusted Root section and the client cert is >

RE: Problem with machine authentication on Windows 2000 usingfreeradius, eap-tls, wireless

2004-02-03 Thread Wieck, Owen
machine. Also, you have to make sure > that the root CA cert is in the Trusted Root CA section for > the computer > account. Otherwise, the 802.1x client will be unable to verify the > authenticity of the network and will refuse to connect. > > --MIke > > > On Tue,

Problem with machine authentication on Windows 2000 using freeradius, eap-tls, wireless

2004-02-03 Thread Wieck, Owen
First, a brief description of my setup. I'm using freeradius (v0.9.1) as backend AAA to secure our wireless network. We're using eap-tls with the certificates, etc. The setup was done per the guides out on the 'net. Works great, but... I'm having trouble getting freeradius to interoperate wi