Networking Forums  

Go Back   Networking Forums > Networking Newsgroups > Wireless Internet

eap-tls without active directory

Reply
 
Thread Tools Display Modes
  #1  
Old 11-23-2006, 03:52 PM
Default eap-tls without active directory



hello,
i have a client who provides wireless access to separate entities in
the same building.
Right now he's using LEAP and ACS database. Now he would like to move
toward eap-tls because it's the most secured.

Usually, I install eap-tls within a active directory and distribute
machine certificate via global policy. Now the problem is that his
laptops are not in a Active directory domain because they come from
unrelated entities.

My idea was to use a fictionnal active directory just for the database
purpose, and download machine certificate manually via the web. (the
client gets his hand on each laptop to configure LEAP)

Does anybody have a bright idea to deploy certificates without active
directory; I think that no matter what, we need a database and a CA.

Thank your for your suggestions.



liolemaire@gmail.com
Reply With Quote
  #2  
Old 11-23-2006, 06:42 PM
Peter Boosten
Guest
 
Posts: n/a
Default Re: eap-tls without active directory

In alt.internet.wireless (E-Mail Removed) wrote:
>
> Does anybody have a bright idea to deploy certificates without active
> directory; I think that no matter what, we need a database and a CA.
>


A simple box with linux and freeradius.

Peter

--
http://www.boosten.org

Mail: peter at boosten dot org
Reply With Quote
  #3  
Old 11-26-2006, 08:26 AM
nuzz
Guest
 
Posts: n/a
Default Re: eap-tls without active directory

You could use Zeroshell available at http://www.zeroshell.net/eng/ which is
a small linux distribution available as live cd or compact flash image for
embedded devices. This Linux is easy to use because is web administrable. It
includes a certification authority to distribute x509 certificate and radius
server to authenticate wireless client using 802.1x (eap-tls, peap and
eap-ttls). I am testing it and appears to be very stable and useful. The
best feature I think is the captive portal for hotspots web login.
bye

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> hello,
> i have a client who provides wireless access to separate entities in
> the same building.
> Right now he's using LEAP and ACS database. Now he would like to move
> toward eap-tls because it's the most secured.
>
> Usually, I install eap-tls within a active directory and distribute
> machine certificate via global policy. Now the problem is that his
> laptops are not in a Active directory domain because they come from
> unrelated entities.
>
> My idea was to use a fictionnal active directory just for the database
> purpose, and download machine certificate manually via the web. (the
> client gets his hand on each laptop to configure LEAP)
>
> Does anybody have a bright idea to deploy certificates without active
> directory; I think that no matter what, we need a database and a CA.
>
> Thank your for your suggestions.
>



Reply With Quote
Reply

Tags
active, directory, eaptls

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 10:47 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.