Networking Forums

Networking Forums > Wireless Networking > Wireless Networks > Peap and domain login

Reply
Thread Tools Display Modes

Peap and domain login

 
 
Tech
Guest
Posts: n/a

 
      01-31-2005, 10:56 PM
We just setup wireless in my company and it is working great. Question
i have is we have setup a room with laptops that are using wireless. We
have this setup for Peap and authenticate against a radius server. Is
there a way to log onto the domain via wireless if you never logged onto
the machine before. Keep in mind that the machine is joined to the
domain but it is not using a cached profile at first. We always had to
connect to the wire first.

Any help?
 
Reply With Quote
 
 
 
 
Mark Gamache
Guest
Posts: n/a

 
      02-01-2005, 12:36 AM
Are you using MS-CHAP v2 or a TLS certificate inside of the PEAP connection?
If you are using MS-CHAP v2, there should be no need for the user to logon
via the wire first. If you are using certs, then you need to provision the
cert before they can authenticate, so you would need to have another method
to acquire the cert.

Cheers,

--
Mark Gamache
Certified Security Solutions
http://www.css-security.com



"Tech" <(E-Mail Removed)> wrote in message
news:OdpHhg%(E-Mail Removed)...
> We just setup wireless in my company and it is working great. Question i
> have is we have setup a room with laptops that are using wireless. We
> have this setup for Peap and authenticate against a radius server. Is
> there a way to log onto the domain via wireless if you never logged onto
> the machine before. Keep in mind that the machine is joined to the domain
> but it is not using a cached profile at first. We always had to connect
> to the wire first.
>
> Any help?



 
Reply With Quote
 
Tech
Guest
Posts: n/a

 
      02-01-2005, 12:46 AM
I am using EAP MS-CHAP v2 and a wireless certificate. Does this make
sense? But what i am noticing is that i need to log on the machine
first, configure the wireless with the SSID and PEAP and than except the
certificate. I would like to do all this via group policies but i was
told that i need to have 2003 DC and we are still at 2000.


Mark Gamache wrote:
> Are you using MS-CHAP v2 or a TLS certificate inside of the PEAP connection?
> If you are using MS-CHAP v2, there should be no need for the user to logon
> via the wire first. If you are using certs, then you need to provision the
> cert before they can authenticate, so you would need to have another method
> to acquire the cert.
>
> Cheers,
>

 
Reply With Quote
 
Mark Gamache
Guest
Posts: n/a

 
      02-01-2005, 01:15 AM
The certificate that protects the EAP exchange is the IAS server's
certificate, this is also the certificate that your client uses to
authenticate the IAS server (if you use mutual auth). So the MS-CHAP v2 is
being used inside the TLS tunnel. This means that you don't need a client
cert. You are correct though, in order to configure the client, you do need
to have access to the domain to process the login without cached
credentials.

To achieve this , add the Domain Computers Group (or the Computer accounts
separately) to whatever group you use for wireless authentication. The
computers are then able to authenticate to using their machine accounts.
This access should allow you to process the login while still in the context
of the machine assuming that it retains the previous user's wireless
settings. Some vendors hardware may not support this. The only way to know
for sure is give it a try.

To automatically configure each user's account, you would need a win2003 DC
and actually if you are using WPA, that is currently not supported for auto
config via GPO. That's coming ins 2003 server sp1.

Cheers,

--
Mark Gamache
Certified Security Solutions
http://www.css-security.com



"Tech" <(E-Mail Removed)> wrote in message
news:eu79Ce$(E-Mail Removed)...
>I am using EAP MS-CHAP v2 and a wireless certificate. Does this make
>sense? But what i am noticing is that i need to log on the machine first,
>configure the wireless with the SSID and PEAP and than except the
>certificate. I would like to do all this via group policies but i was told
>that i need to have 2003 DC and we are still at 2000.
>
>
> Mark Gamache wrote:
>> Are you using MS-CHAP v2 or a TLS certificate inside of the PEAP
>> connection? If you are using MS-CHAP v2, there should be no need for the
>> user to logon via the wire first. If you are using certs, then you need
>> to provision the cert before they can authenticate, so you would need to
>> have another method to acquire the cert.
>>
>> Cheers,
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PEAP - Wireless client not a domain member rileymartin Windows Networking 2 03-24-2008 02:20 AM
How to uninstall Cisco PEAP supplicant to use XP default PEAP Delon Wireless Networks 0 05-25-2007 06:50 AM
PEAP username/domain greyed out Bruce Wayne Wireless Networks 1 08-18-2005 09:52 PM
Sometimes users can't login after changing password on domain at first login edg Windows Networking 0 11-12-2004 12:30 AM
Can't login to domain Graeme Wireless Networks 0 10-19-2004 04:01 PM



1 2 3 4 5 6 7 8 9 10 11