PEAP-TLS: same settings in PEAP Properties and Smart Card & Cert Properties?


when setting gpo wireless network profile via gpmc in windows 2008 r2, in protected eap properties window there check boxes validate server certificate , do not prompt user authorize new servers or trusted certification authorities, textbox connect these servers, , selections list trusted root certification authorities.

all these configurable options show again if click on configure when using smart card or other certificate as authentication method.  can set them wish there, different peap properties even.

my question is, set of options takes precedence? sane person keep them same, why have confusion in interface?

hi roland,

all of these 2 settings take effect.

peap eap method addresses security issue first creating secure channel both encrypted , integrity-protected tls. then, new eap negotiation eap method occurs within secure channel, authenticating network access attempt of access client.

therefore, first settings the settings of tls secure channel (outer layer), , second settings settings of new eap negotiation (inner layer). if choose "smart card or other certificate" authentication method of peap, there 2 tls secure channel actually.

for detailed information, please refer link below,

extensible authentication protocol overview

http://technet.microsoft.com/en-us/library/bb457039.aspx

best regards.



steven lee

technet community support



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file