I think group policies would help out there.

Regards,

Frank

-----Original Message-----
From: Tom Rixom [mailto:[EMAIL PROTECTED] 
Sent: Thursday, February 08, 2007 10:07 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: [WIRELESS-LAN] PEAPv0 questions

Hi all,

If we are going to talk about PEAP, could someone maybe answer me the
following questions?

Are these PEAPv0 implementations also used on public computers (accessible
by different users, without admin privileges)?

And if so can those non-admin users access the PEAP configuration via the
network properties window? Or can this for example be disabled by a domain
policy?

The reason I ask is that in my experiments with PEAP on Windows I could
change the configuration regardless of my privileges. This allowed me to 
configure PEAP to not validate the server certificate allowing
the so called man-in-the-middle attack to take place.

Regards,

Tom Rixom

**********
Participation and subscription information for this EDUCAUSE Constituent
Group discussion list can be found at http://www.educause.edu/groups/.

**********
Participation and subscription information for this EDUCAUSE Constituent Group 
discussion list can be found at http://www.educause.edu/groups/.

Reply via email to