Hi,
I'm trying to set up a wireless network where the clients authenticate using
computer certificates. However, when the client tries to connect to the
network, I get the message "Windows was unable to find a certificate to log
you on to the network <SSID>."
MMC.EXE Certificates snap-in on the client shows both the machine cert
(under "Personal") and the enterprise CA under Trusted Root Certification
Authorities. The machine cert contains the key usage token Client
Authentication (1.3.6.1.5.5.7.3.2), is signed by the enterprise CA, and has
the client computer's DNS name in the Subject Alternative Name field.
How can I troubleshoot this? I have tried netsh ras set tracing * enabled,
but I have not found any trace logs that show the certificate selection
process. Is it possible to get logs of this? Or is there anything else I can
check that might explain why the client might be failing to retrieve the
correct certificate?
Thanks,
-Graham
|