Networking Forums

Networking Forums > Computer Networking > Windows Networking > Configure Second IAS-Radius in WS2003EE

Reply
Thread Tools Display Modes

Configure Second IAS-Radius in WS2003EE

 
 
Harry
Guest
Posts: n/a

 
      09-09-2005, 07:41 AM
I had a redundant server pair and added Wireless WPA-TKIP using IAS-EAP with
Certificate.

Following the Word document "Step-by-Step guide for Setting Up Secure
Wireless Access in a TestLab" the PDC went like a charm and my wireless
laptops get secure Internet out of thin air (auto enroll)!

Wanting redundancy, I tried to do enable my secondary domain controller as
RADIUS server and just can not get a certificate from the enterprise root CA
on the PDC. Second DC can successfully obtain user certificates. The PDC can
see stored certificates on the Secondary DC.

Symptoms:
Auto-enrolling Domain Controllers give Event Source: AutoEnrollment, Event
ID: 13 "Automatic certificate enrollment for local system failed to enroll
for one Domain Controller certificate (0x80070005). Access is denied."

Starting Certificate for local computer, Request certificate, DOmain
controller etc. gives: The certificate request failed because of the
following conditions:
- The vcertificate request was submitted to a Certification Authority (CA)
that is not started
- Yu do not have the permissions to request certificates from the
available CAs.

The CA knows nothing of the requests.

How do I troubleshoot? Do I need separate certificates?

Grateful for any wisdom!
-Harry
 
Reply With Quote
 
 
 
 
James McIllece [MS]
Guest
Posts: n/a

 
      09-09-2005, 08:22 PM
"=?Utf-8?B?SGFycnk=?=" <(E-Mail Removed)> wrote in
news:3DFCBDA4-1160-47C3-93D9-(E-Mail Removed):

> I had a redundant server pair and added Wireless WPA-TKIP using
> IAS-EAP with Certificate.
>
> Following the Word document "Step-by-Step guide for Setting Up Secure
> Wireless Access in a TestLab" the PDC went like a charm and my
> wireless laptops get secure Internet out of thin air (auto enroll)!
>
> Wanting redundancy, I tried to do enable my secondary domain
> controller as RADIUS server and just can not get a certificate from
> the enterprise root CA on the PDC. Second DC can successfully obtain
> user certificates. The PDC can see stored certificates on the
> Secondary DC.
>
> Symptoms:
> Auto-enrolling Domain Controllers give Event Source: AutoEnrollment,
> Event ID: 13 "Automatic certificate enrollment for local system failed
> to enroll for one Domain Controller certificate (0x80070005). Access
> is denied."
>
> Starting Certificate for local computer, Request certificate, DOmain
> controller etc. gives: The certificate request failed because of the
> following conditions:
> - The vcertificate request was submitted to a Certification
> Authority (CA)
> that is not started
> - Yu do not have the permissions to request certificates from the
> available CAs.
>
> The CA knows nothing of the requests.
>
> How do I troubleshoot? Do I need separate certificates?
>
> Grateful for any wisdom!
> -Harry
>


Hi Harry --

After installing IAS on the second DC, did you add the IAS server to the AD
group "RAS and IAS servers"? Once you do that and you refresh group policy,
I believe that the server certificate should be installed. Once it is
installed, you can go into the IAS console, add RADIUS clients and create a
remote access policy that uses the cert for PEAP authentication.

If the cert is not visible in the IAS console, then either the cert was not
originally configured properly or it did not autoenroll. If you have that
problem, let me know and I will work through it with you next week.

But the main thing is making sure the IAS server is registered in AD by
adding it to the group.

--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
I need help to configure a radius server on a linux box..... A_A_K Linux Networking 2 05-18-2009 05:56 AM
windows 2003 radius proxy and windows 2000 radius server JluisVelasco Windows Networking 2 01-18-2008 09:16 AM
RADIUS rahulkumbhar@gmail.com Windows Networking 1 07-07-2006 01:14 PM
RADIUS Cameron Davison Wireless Internet 1 09-03-2004 04:43 PM
RADIUS ? Madhusudan Singh Wireless Internet 2 01-24-2004 01:35 AM



1 2 3 4 5 6 7 8 9 10 11