Re: AW: Noone anny idea fot --> TLS Athentifikation before Domain, Logon XP?

2006-01-10 Thread Alan DeKok
=?iso-8859-1?Q?Armin_Kr=E4mer?= <[EMAIL PROTECTED]> wrote: > I posted 3 days ago an mesage with 2 logfiles out of radius. Because this is > a part of my Projekt for my final exam as an IT-Engineer it is verry > important for me getting this working. If I help you, do I get a passing grade? > In

AW: Noone anny idea fot --> TLS Athentifikation before Domain, Logon XP?

2006-01-10 Thread Armin Krämer
anny idea fot --> TLS Athentifikation before Domain, Logon XP? Sorry, forgotte to attach the files... Okay, i tested on and found an difference. I attach 2 Files. One is the output with an normal Client-Certificate the other with an Certifikate with the OID 1.3.6.1.4.1.311.17.2. In both ca

Noone anny idea fot --> TLS Athentifikation before Domain, Logon XP?

2006-01-06 Thread Armin Krämer
add OID as a second OID to the certifikate? Thanks for helping. :-) -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Gesendet: Freitag, 6. Januar 2006 21:11 An: [EMAIL PROTECTED] Betreff: Re: Noone anny idea fot --> TLS Athentifikation before Domain, Logon

AW: Noone anny idea fot --> TLS Athentifikation before Domain, Logon XP?

2006-01-06 Thread Armin Krämer
certifikate? Thanks for helping. :-) -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Gesendet: Freitag, 6. Januar 2006 21:11 An: [EMAIL PROTECTED] Betreff: Re: Noone anny idea fot --> TLS Athentifikation before Domain, Logon XP? Hello, - login as local administrat

Re: Noone anny idea fot --> TLS Athentifikation before Domain Logon XP?

2006-01-06 Thread Alan DeKok
"Timothy J. Miller" <[EMAIL PROTECTED]> wrote: > The correct OIDs are: > > RADIUS server certificate: 1.3.6.1.5.5.7.3.1 (TLS Server Authentication) > > Client certificate: 1.3.6.1.5.5.7.3.2 (TLS Client Authentication) For *user* logins. The *machine* login uses the other OID's. Alan DeKok.

Re: Noone anny idea fot --> TLS Athentifikation before Domain Logon XP?

2006-01-06 Thread Timothy J. Miller
Armin Krämer wrote: I tried out the registry patch AuthMode with a value of 2 whch causes windows to authenticate with the machine certificate only. Then I generated a client certificate with openssl with the special OID 1.3.6.1.4.1.311.17.2 which was posted in the mailing list some time ago.

Noone anny idea fot --> TLS Athentifikation before Domain Logon XP?

2006-01-06 Thread Armin Krämer
Does noone have got any idea how to solve this problem?   Greetings Armin  Hi, i searched the whole archive about this Problems but can not find an real answert to my Problem. I want Windows XP to authenticate to Freeradius when before the user Logs on the domain otherwise he would have