RE: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-05 Thread ktaillon
[mailto:[EMAIL PROTECTED] Sent: Wednesday, April 04, 2007 5:29 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate Yes, if you purchase a commercial cert from one of the CAs who's certs are included with the OS, all the user has to do

Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-05 Thread Kevin Miller
. Ken -Original Message- From: Michael Griego [mailto:[EMAIL PROTECTED] Sent: Wednesday, April 04, 2007 11:27 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate Just be aware that not validating the certificate opens you up to fairly

802.1x With A One-Way Certificate

2007-04-04 Thread ktaillon
We are trying to implement a WPA/TKIP Wireless authentication. We are using ACS Solution Engine which backs into AD for Authentication. We are currectly using WEP. We are looking for the least amount of client setup to make this change. Cisco has told us to use the PEAP MSCHAPv2 connection with

Re: 802.1x With A One-Way Certificate

2007-04-04 Thread Rick Coloccia
Yes. We aren't using the wpa-tkip with acs, but we do use ias (windows) for radius, we have our clients uncheck the 'Validate Server Certificate' option and away they go. http://www.geneseo.edu/CMS/display.php?page=5200dpt=cit http://www.geneseo.edu/CMS/display.php?page=5198dpt=cit

Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-04 Thread Doug Payne
Rick Coloccia wrote: Yes. We aren't using the wpa-tkip with acs, but we do use ias (windows) for radius, we have our clients uncheck the 'Validate Server Certificate' option Why? (i.e. why not ensure that the cert is valid?) ** Participation and subscription information for this

Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-04 Thread Michael Griego
Just be aware that not validating the certificate opens you up to fairly easy session hijacking attacks since anyone can come up with a cert and get your clients to connect to their APs instead of yours (since the client is not checking cert validity)... The attacker would then have

Re: 802.1x With A One-Way Certificate

2007-04-04 Thread Rick Coloccia
Well, to ensure the cert is vaild, a trusted root ca cert must be one client. We used a locally generated cert for the ias server. We haven't yet rolled out our local trusted root ca cert. Once it gets out we won't worry about that exact setting. Until we do, we needed a way to get

Re: 802.1x With A One-Way Certificate

2007-04-04 Thread Rick Coloccia
Yes, that liability was indeed considered... -Rick Michael Griego wrote: Just be aware that not validating the certificate opens you up to fairly easy session hijacking attacks since anyone can come up with a cert and get your clients to connect to their APs instead of yours (since the

RE: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-04 Thread Emerson Parker
AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: [WIRELESS-LAN] 802.1x With A One-Way Certificate We are trying to implement a WPA/TKIP Wireless authentication. We are using ACS Solution Engine which backs into AD for Authentication. We are currectly using WEP. We are looking for the least

RE: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-04 Thread ktaillon
the client setup as simple as possible but not in a way that lowers security. Ken -Original Message- From: Michael Griego [mailto:[EMAIL PROTECTED] Sent: Wednesday, April 04, 2007 11:27 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate

Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-04 Thread Lelio Fulgenzi
-LAN] 802.1x With A One-Way Certificate Here are our instructions. We ask users to check off the appropriate CA and it works fine for us. No need to manually download or approve anything. It's worked for us

Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate

2007-04-04 Thread Michael Griego
the client setup as simple as possible but not in a way that lowers security. Ken -Original Message- From: Michael Griego [mailto:[EMAIL PROTECTED] Sent: Wednesday, April 04, 2007 11:27 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] 802.1x With A One-Way Certificate