Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

NPS Radius authentication problem

Posted on 2010-11-24
5
Medium Priority
?
1,707 Views
Last Modified: 2013-11-12
After a server crash on my old NPS server, I imported the xml configuration file to my new nps server. It is used with a Cisco WLC for web authentication on our guest lan.
But since I moved the nps to a new server, I keep getting "No reversibly encrypted password is stored for the user account", I even tried to select "use reversibly encryption in AD", which is not what I want, but I still get the same error in the NPS log.
I have imported the certificate to the new nps server and configured it for PEAP-MS-CHAP v.2.
If I select "Accept users without validating credential" in NPS Connection request policy my ad users can log on, but I quickly learned that you could then write anything in username and password and still get in.
The log file for NPS only says "No reversibly encrypted password is stored for the user account", I even tried to select "use reversibly encryption in AD", no matter what I try, even if I selct unencrypted authentication in NPS.
What could be wrong?
0
Comment
Question by:Ducknaldi
  • 4
5 Comments
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 34210664
Did you reset the RADIUS client password on the new NPS server? It won't come over in the XML file for security reasons.
0
 
LVL 1

Author Comment

by:Ducknaldi
ID: 34211272
I tried to reset the shared secret, no luck:(
0
 
LVL 1

Author Comment

by:Ducknaldi
ID: 34211315
I now tried a 3´rd server with the same configuration. It seems no matter what I do it wants a reversibly encrypted password to be stored in AD. This is not an option for obvious reasons and would also require all users to change their password before it would work.
0
 
LVL 1

Accepted Solution

by:
Ducknaldi earned 0 total points
ID: 34212832
Ok, I solved the problem with a Cisco Secure Access Server instead.
The NPS stinks when it comes to logging what´s going on and I could have been guessing forever.
0
 
LVL 1

Author Closing Comment

by:Ducknaldi
ID: 34237161
The real problem was never soved with NPS.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This program is used to assist in finding and resolving common problems with wireless connections.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question