Networking Forums

Networking Forums > Wireless Networking > Wireless Networks > Setting up XP+IAS+Auto-enrollment wireless LAN?

Reply
Thread Tools Display Modes

Setting up XP+IAS+Auto-enrollment wireless LAN?

 
 
Al Blake
Guest
Posts: n/a

 
      09-29-2004, 06:12 AM
Environment: Windows 2003 Native AD LAN
12 Windows 2003 servers, inclduing IAS running on W2k3 Enterprise
600 Windows XP SP2 laptops/desktops.

Proposal: Provide seamless, secure wireless connectivity for 250+ XP SP2
Laptops through Cisco 1200 APs.

I have searched around for as much information as I can on technet/MSDN
regarding setting up wireless LANs and securing them using auto-enrolled
certificates from a certificate server....but I am getting confused with
terminalogy and where I need to go next. Most of the white paers and
examples seem to relate to smartcard setup - which we ar enot doing.

So far I have configured a test OU in my AD and placed a single laptop in
there. I have rebooted the laptop and it gets issued with a certificate
automatically which is exactly what I want to happen. Questions:

a) The example I had told me to use a 'User certificate' template to
autoenrol the machine. Is this correct or should I have created a copy of a
'computer' certificate and used that on the machine OU (is there any
difference between a computer certificate and a user certificate in Windows
Certificate services).

b) If we are going to use the autoenrolled certificates as the basis for
security in our WLAN setup do we need to auto-enrol certificates for users
AND computers? (ie should the user OU and the computer OU be setup to issue
certs?)

c) What next? Once I have got certificates automatically issued for the user
and/or the computer how do I setup the whole thing so that the Access points
use them? I have configured the access points to use my IAS server as radius
for authentication and know that is working form the point of view of
authenticating my telnet login to the AP....but what do I need to tell them
to use the certs?

d) Can someone confirm whether we still need WEP if we are using EAP?

e) What do we need to setup on the IAS server to support EAP?

I am sorry this is so vague but I thought I had it sorted for a while and
then just got more confused with all the terminalogy and options.
If anyone can point me at a white paper 'setting up IAS to support EAP and
autoenrolled certificates' I would really appreciate it!

Regards
Al Blake, Canberra, Australia


 
Reply With Quote
 
 
 
 
Paul Adare - MVP - Microsoft Virtual PC
Guest
Posts: n/a

 
      09-29-2004, 09:04 AM
In article <#(E-Mail Removed)>, in the
microsoft.public.windows.server.security news group, Al Blake
<(E-Mail Removed)> says...

> I am sorry this is so vague but I thought I had it sorted for a while and
> then just got more confused with all the terminalogy and options.
> If anyone can point me at a white paper 'setting up IAS to support EAP and
> autoenrolled certificates' I would really appreciate it!
>

http://www.microsoft.com/technet/Sec.../pkiwire/swlan
..mspx
--
Paul Adare
This posting is provided "AS IS" with no warranties, and confers no
rights.
 
Reply With Quote
 
David Cross [MS]
Guest
Posts: n/a

 
      09-29-2004, 12:21 PM
To add:

auto-enrollment:
http://www.microsoft.com/technet/pro.../autoenro.mspx

MSS wireless:
http://www.microsoft.com/downloads/d...displaylang=en

Wireless PEAP:
http://www.microsoft.com/downloads/d...displaylang=en



--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

"Paul Adare - MVP - Microsoft Virtual PC" <(E-Mail Removed)> wrote in
message news:(E-Mail Removed) om...
> In article <#(E-Mail Removed)>, in the
> microsoft.public.windows.server.security news group, Al Blake
> <(E-Mail Removed)> says...
>
>> I am sorry this is so vague but I thought I had it sorted for a while and
>> then just got more confused with all the terminalogy and options.
>> If anyone can point me at a white paper 'setting up IAS to support EAP
>> and
>> autoenrolled certificates' I would really appreciate it!
>>

> http://www.microsoft.com/technet/Sec.../pkiwire/swlan
> .mspx
> --
> Paul Adare
> This posting is provided "AS IS" with no warranties, and confers no
> rights.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless network connection setting switches from auto connect tomanual Billy Wireless Networks 1 09-29-2009 10:57 PM
Auto Shipping Auto Shipping Scheduling:car moving auto transport linkswanted Wireless Internet 0 02-16-2008 01:40 AM
Manual or Auto channel setting? Clive Wireless Internet 2 04-14-2007 06:54 PM
windows 98 auto proxy setting. gd Windows Networking 0 01-14-2005 07:29 AM
setting VPN Client to auto connect at startup in windows 98???? Somebody out there... Windows Networking 0 08-25-2004 10:24 PM



1 2 3 4 5 6 7 8 9 10 11