Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Wireless Networking > IAS PEAP Wireless - Stand Alone CA

Reply
Thread Tools

IAS PEAP Wireless - Stand Alone CA

 
 
tweaked540@gmail.com
Guest
Posts: n/a
 
      02-16-2007
Is it possible to have a stand alone win2k3 CA produce certificates
for the IAS server to use for PEAP? When we try to authenticate to
the WAP, we get these errors on our IAS box: (It looks as if the
certificates are no good)

Event Type: Error
Event Source: IAS
Event Category: None
Event ID: 20168
Date: 2/15/2007
Time: 10:08:45 AM
User: N/A
Computer: Computer
Description:
Could not retrieve the Remote Access Server's certificate due to the
following error: No credentials are available in the security package

Event Type: Error
Event Source: IAS
Event Category: None
Event ID: 3
Date: 2/15/2007
Time: 10:08:43 AM
User: N/A
Computer: Computer
Description:
Access request for user was discarded.
Fully-Qualified-User-Name = test
NAS-IP-Address = 192.168.21.9
NAS-Identifier = WAP
Called-Station-Identifier = 0003.45f7.3210
Calling-Station-Identifier = 0555.5056.55b5
Client-Friendly-Name = WAP
Client-IP-Address = 192.168.21.9
NAS-Port-Type = Wireless - IEEE 802.11
NAS-Port = 267
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Reason-Code = 300
Reason = No credentials are available in the security package

 
Reply With Quote
 
 
 
 
Greg Lindsay [MSFT]
Guest
Posts: n/a
 
      02-16-2007
Hi,

It looks like there is a problem with your certificate.

Make sure all the following are true:

For the computer certificates installed on the IAS servers, the following
must be true:
. They must be installed in the Local Computer certificate store.

. They must have a corresponding private key. When you view the
properties of the certificate with the Certificate snap-in, you should see
the text You have a private key that corresponds to this certificate on the
General tab.

. The cryptographic service provider for the certificates supports
SChannel. If not, the IAS server cannot use the certificate and it is not
selectable from the properties of the Smart Card or Other Certificate EAP
type from the Authentication tab on the properties of a profile for a remote
access policy.

. They must contain the Server Authentication certificate purpose
(also known as an Enhanced Key Usage [EKU]). An EKU is identified using an
object identifier (OID). The OID for Server Authentication is
"1.3.6.1.5.5.7.3.1".

. They must contain the fully qualified domain name (FQDN) of the
computer account of the IAS server computer in the Subject Alternative Name
property.


Additionally, the root CA certificates of the CAs that issued the wireless
client computer and user certificates must be installed in the Certificates
(Local Computer)\Trusted Root Certification Authorities\Certificates folder.

http://www.microsoft.com/technet/pro...y/ed80211.mspx

I hope this helps.

--
Greg Lindsay [MSFT]

Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.

<> wrote in message
news: oups.com...
> Is it possible to have a stand alone win2k3 CA produce certificates
> for the IAS server to use for PEAP? When we try to authenticate to
> the WAP, we get these errors on our IAS box: (It looks as if the
> certificates are no good)
>
> Event Type: Error
> Event Source: IAS
> Event Category: None
> Event ID: 20168
> Date: 2/15/2007
> Time: 10:08:45 AM
> User: N/A
> Computer: Computer
> Description:
> Could not retrieve the Remote Access Server's certificate due to the
> following error: No credentials are available in the security package
>
> Event Type: Error
> Event Source: IAS
> Event Category: None
> Event ID: 3
> Date: 2/15/2007
> Time: 10:08:43 AM
> User: N/A
> Computer: Computer
> Description:
> Access request for user was discarded.
> Fully-Qualified-User-Name = test
> NAS-IP-Address = 192.168.21.9
> NAS-Identifier = WAP
> Called-Station-Identifier = 0003.45f7.3210
> Calling-Station-Identifier = 0555.5056.55b5
> Client-Friendly-Name = WAP
> Client-IP-Address = 192.168.21.9
> NAS-Port-Type = Wireless - IEEE 802.11
> NAS-Port = 267
> Proxy-Policy-Name = Use Windows authentication for all users
> Authentication-Provider = Windows
> Authentication-Server = <undetermined>
> Reason-Code = 300
> Reason = No credentials are available in the security package
>



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to uninstall Cisco PEAP supplicant to use XP default PEAP =?Utf-8?B?RGVsb24=?= Wireless Networking 0 05-25-2007 05:50 AM
Wireless Computers Can't Connect to Stand Alone Printer crs Wireless Networking 4 02-22-2006 10:17 PM
PEAP Configuration Woes - PEAP configuration help jester Cisco 1 12-20-2005 02:04 PM
stand alone executable using pp doesn't stand alone Plotinus Perl Misc 2 12-17-2004 01:09 AM
IAS fails with certs from Stand Alone CA Harrison Midkiff Wireless Networking 2 07-22-2004 09:45 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57