Computer authentication after login for 802.11i

Computer authentication after login for 802.11i

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Computer authentication after login for 802.11i jpriganc 02-28-2007
Posted by on February 28, 2007, 2:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We are trying to setup a new wireless network using 802.11i
standards. We set up IAS to authenticate the computer and the user to
the domain. We are using PEAP with MS-CHAP v2 for authentication.
What we want to do is have the computer re-authenticate when the user
tries to connect. Right now, any user that is in the permitted list
could connect from a computer that is not even in the domain. Any
suggestions on how to make sure both the user and computer are
authenticated would be appreciated.


Posted by =?Utf-8?B?UnlhbiBIYW5pc2Nv?= on June 1, 2007, 9:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
To do that, your best bet is to use EAP and authenticate against the user and
computer certificates. You can deploy certs automatically by deploying a CA.
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
Chicago, IL

Remember: Marking helpful answers helps everyone find the info they need
quickly.


"jpriganc@gmail.com" wrote:

> We are trying to setup a new wireless network using 802.11i
> standards. We set up IAS to authenticate the computer and the user to
> the domain. We are using PEAP with MS-CHAP v2 for authentication.
> What we want to do is have the computer re-authenticate when the user
> tries to connect. Right now, any user that is in the permitted list
> could connect from a computer that is not even in the domain. Any
> suggestions on how to make sure both the user and computer are
> authenticated would be appreciated.
>
>

Posted by S. Pidgorny on June 2, 2007, 7:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
That is a good approach but actually that won't solve the problem: the users
will be able to authenticate with their certificates even if compputer
authentication hasn't happened. There's nothing in the standards that will
enforce dual computer/user authentication.

There is a solution, and it indeed involves certificates: make it impossible
for the users to move their certificates off certain computer systems. For
example - place user authentication certs in a TPM.

--
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> To do that, your best bet is to use EAP and authenticate against the user
> and
> computer certificates. You can deploy certs automatically by deploying a
> CA.
> --
> Ryan Hanisco
> MCSE, MCTS: SQL 2005, Project+
> Chicago, IL
>
> Remember: Marking helpful answers helps everyone find the info they need
> quickly.
>
>
> "jpriganc@gmail.com" wrote:
>
>> We are trying to setup a new wireless network using 802.11i
>> standards. We set up IAS to authenticate the computer and the user to
>> the domain. We are using PEAP with MS-CHAP v2 for authentication.
>> What we want to do is have the computer re-authenticate when the user
>> tries to connect. Right now, any user that is in the permitted list
>> could connect from a computer that is not even in the domain. Any
>> suggestions on how to make sure both the user and computer are
>> authenticated would be appreciated.
>>
>>



Similar ThreadsPosted
two-factor authentication for both local and remote login July 7, 2006, 6:12 am
Computer to Computer NtLmSsp authentication errors ? October 6, 2006, 5:25 pm
If my computer is a single PC with ADSL connection, can I leave the password blank when I login the XP? November 10, 2006, 8:20 am
Computer cert/User cert 802.x Authentication query August 7, 2007, 5:20 am
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:41 pm
Computer Hacker is illegally creating a new logon on my computer November 10, 2007, 9:32 pm
User Permissions Differ from Computer to Computer October 24, 2005, 7:16 pm
Login Reports June 22, 2005, 10:25 am
Login without password... June 22, 2005, 2:25 pm

The site map in XML format XML site map

Contact Us | Privacy Policy