Click here to get back home

eap-tls without active directory

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
eap-tls without active directory liolemaire 11-23-2006
Posted by liolemaire on November 23, 2006, 10:52 am
Please log in for more thread options
hello,
i have a client who provides wireless access to separate entities in
the same building.
Right now he's using LEAP and ACS database. Now he would like to move
toward eap-tls because it's the most secured.

Usually, I install eap-tls within a active directory and distribute
machine certificate via global policy. Now the problem is that his
laptops are not in a Active directory domain because they come from
unrelated entities.

My idea was to use a fictionnal active directory just for the database
purpose, and download machine certificate manually via the web. (the
client gets his hand on each laptop to configure LEAP)

Does anybody have a bright idea to deploy certificates without active
directory; I think that no matter what, we need a database and a CA.

Thank your for your suggestions.


Posted by Peter Boosten on November 23, 2006, 1:42 pm
Please log in for more thread options
In alt.internet.wireless liolemaire@gmail.com wrote:
>
> Does anybody have a bright idea to deploy certificates without active
> directory; I think that no matter what, we need a database and a CA.
>

A simple box with linux and freeradius.

Peter

--
http://www.boosten.org

Mail: peter at boosten dot org

Posted by nuzz on November 26, 2006, 3:26 am
Please log in for more thread options
You could use Zeroshell available at http://www.zeroshell.net/eng/ which is
a small linux distribution available as live cd or compact flash image for
embedded devices. This Linux is easy to use because is web administrable. It
includes a certification authority to distribute x509 certificate and radius
server to authenticate wireless client using 802.1x (eap-tls, peap and
eap-ttls). I am testing it and appears to be very stable and useful. The
best feature I think is the captive portal for hotspots web login.
bye

> hello,
> i have a client who provides wireless access to separate entities in
> the same building.
> Right now he's using LEAP and ACS database. Now he would like to move
> toward eap-tls because it's the most secured.
>
> Usually, I install eap-tls within a active directory and distribute
> machine certificate via global policy. Now the problem is that his
> laptops are not in a Active directory domain because they come from
> unrelated entities.
>
> My idea was to use a fictionnal active directory just for the database
> purpose, and download machine certificate manually via the web. (the
> client gets his hand on each laptop to configure LEAP)
>
> Does anybody have a bright idea to deploy certificates without active
> directory; I think that no matter what, we need a database and a CA.
>
> Thank your for your suggestions.
>



Similar ThreadsPosted
auditing active directory not working properly directory serviceaccess October 21, 2005, 7:47 pm
Linking PKI directory accounts with Active Directory? February 11, 2007, 5:29 am
Active Directory December 28, 2005, 7:00 am
Active Directory May 1, 2008, 11:11 am
Active Directory Server August 12, 2005, 3:49 pm
Active Directory Questions. November 24, 2006, 12:09 am
Published Certificates in Active Directory February 9, 2006, 6:53 pm
Active Directory Schema Permissions October 17, 2006, 4:59 pm
Group Policy without Active Directory February 27, 2007, 3:31 pm
SAMR Interface Calls and Active Directory March 29, 2006, 8:16 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap