Solved

RODC with EAP and Radius

Posted on 2011-09-22
3
2,011 Views
Last Modified: 2012-05-12
I have a domain, let’s call it Domain.local.  On this domain I have a domain controller called DC-Prime, and a read-only domain controller called RODC-Zeta.

I have 2 cisco wireless APs, using RADIUS to authenticate users to the domain.  When they are pointed to Prime, they authenticate, and everything is sunshine and unicorns.  When I point them to Zeta, the server reports the following from Event Viewer:

Negotiation failed. Requested EAP methods not available

I have exported the EAP settings from Prime and imported them to Zeta, but I still get the same results.  I think it has to do with Zeta being a Read Only DC, but google and various searches have come up empty.
0
Comment
Question by:UnityPG
  • 2
3 Comments
 
LVL 13

Expert Comment

by:khairil
ID: 36582310
Hi,

RODC have special handling with user account and password, you can get more idea here, http://blogs.technet.com/b/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx

You might want to change the Password Replication Policy of RODC and give another try to authenticate user. More on password replication policy, http://technet.microsoft.com/en-us/library/cc730883(WS.10).aspx

BTW, what radius are you using? If you are using NPS for radius authentication then it will be no problem.
0
 

Accepted Solution

by:
UnityPG earned 0 total points
ID: 36586790
The issue was that the RODC server had no certificate for authentication.   Installing a CA on Prime and exporting the cert to Zeta fixed it.

Thanks,
0
 

Author Closing Comment

by:UnityPG
ID: 36715231
Fixed it, sorry guys.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now