Wireless Access

last person joined: 21 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

802.1x authentication with mschapv2 it is need install certificate?

This thread has been viewed 5 times
  • 1.  802.1x authentication with mschapv2 it is need install certificate?

    Posted Sep 28, 2012 07:05 AM
      |   view attached

    Hi All,

     

    I still new for Aruba user authentication. Currently i have implement 802.1x authentication for my customer by using Microsoft Peap. I have configure Windows 2008 R2 RADIUS server (NPS) use Microsoft peap and also already configure the Aruba controller AAA authentication profile (as below attached screen capture).

     

    I use the laptop try connect to broadcasted SSID (802.1x authentication). It take a while (10 to 30 sesconds) to complete connect the SSID but after that windows prompt to install Aruba controller certificate.

     

    My customer say it is possible don't prompt to install the certificate? Because they end user don't like this annoying thing. 

    Attachment(s)

    docx
    802dot1x.docx   81 KB 1 version


  • 2.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    EMPLOYEE
    Posted Sep 28, 2012 07:08 AM

    On the Client, uncheck "Validate Server Certificate".  

     



  • 3.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    Posted Sep 28, 2012 08:51 AM

    Hi Joseph,

     

    Ok, i will try on that. 

     

    Btw, about the Windows 2008 R2 RADIUS server, it is neccesary install and configure CA server and self generate the certificate? Because i have go through the Aruba user guide it stated need to do so. 

     

    But i does not install, configure and self generate the certificate.



  • 4.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    EMPLOYEE
    Posted Sep 28, 2012 09:01 AM

    @jordontin wrote:

    Hi Joseph,

     

    Ok, i will try on that. 

     

    Btw, about the Windows 2008 R2 RADIUS server, it is neccesary install and configure CA server and self generate the certificate? Because i have go through the Aruba user guide it stated need to do so. 

     

    But i does not install, configure and self generate the certificate.


    To install it properly, you should install the Radius Server Certificate, just like the guide states, and then uncheck Termination in the Aruba 802.1x profile.

     



  • 5.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    Posted Sep 30, 2012 11:39 PM
      |   view attached

    Hi Jospeh,

     

    After i uncheck the "Validate Server Certificate" the laptop successful do the authentication provide need to "Check or tick" the "Microsoft Encrypted Authentication Version 2 (MS-CHAP v2) on the WIndows 2008 R2 radius server. 

     

    If i uncheck or untick the "Microsoft Encrypted Authentication Version 2 (MS-CHAP v2) on the WIndows 2008 R2 radius server", windows client always keep on asking key in the password.

     

    it is possible uncheck or untick the Microsoft Encrypted Authentication Version 2 (MS-CHAP v2) on the WIndows 2008 R2 radius server", then it would not always prompt to key in the password.

    Attachment(s)

    docx
    Doc1.docx   73 KB 1 version


  • 6.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    EMPLOYEE
    Posted Sep 30, 2012 11:46 PM

    @jordontin wrote:

    Hi Jospeh,

     

    After i uncheck the "Validate Server Certificate" the laptop successful do the authentication provide need to "Check or tick" the "Microsoft Encrypted Authentication Version 2 (MS-CHAP v2) on the WIndows 2008 R2 radius server. 

     

    If i uncheck or untick the "Microsoft Encrypted Authentication Version 2 (MS-CHAP v2) on the WIndows 2008 R2 radius server", windows client always keep on asking key in the password.

     

    it is possible uncheck or untick the Microsoft Encrypted Authentication Version 2 (MS-CHAP v2) on the WIndows 2008 R2 radius server", then it would not always prompt to key in the password.


    You can uncheck the mschapv2 on the server.  Who issued the server certificate to the Radius Server?  What is the CA?  The clients must have the CA certificate in their trusted store, for it to stop asking to accept.

     



  • 7.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    Posted Oct 03, 2012 11:30 PM

    I already put the CA certificate on the trusted store. But it still prompt to accept the certificate of the "securelogin.arubanetworks.com" certificate instead the radius servercertificate, if i check "validate Server Certificate".

     

    About the CA certificate was auto generate when i setup the windwos RADIUS server but the CA certificate was issued by HQ CA server.



  • 8.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    EMPLOYEE
    Posted Oct 04, 2012 01:18 AM

    In Configuration> Security> layer2 Authentication> 802.1x profiles, find your 802.1x profile and make sure 802.1x termination is disabled (unchecked).



  • 9.  RE: 802.1x authentication with mschapv2 it is need install certificate?

    Posted Nov 21, 2012 01:01 PM

    "To install it properly, you should install the Radius Server Certificate, just like the guide states, and then uncheck Termination in the Aruba 802.1x profile."

     

    I need to do this exact thing. Where can I find this "guide" ? 



  • 10.  RE: 802.1x authentication with mschapv2 it is need install certificate?