Solved

802.1x Without Certificates

Posted on 2013-02-04
2
707 Views
Last Modified: 2013-02-05
Hi Experts,

I am using 802.1x to authenticate domain users through NPS and RADIUS.
This is currently working, with certificates however and I do not wish to use certificates.

I do not wish to use certificates because that means I need to either deploy the certificate via GPO which I cannot do since not all the machines are part of the domain.
OR
I have to manually install the certificate on all the devices which is not an option.
OR
I have to do what I am doing currently and uncheck the "validate certificate" option on each client manually.

So I basically want to do exactly what I am doing now but without certificates.

All help appreciated!
0
Comment
Question by:Gex010
2 Comments
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 38851494
You don't mention what authentication method you're using, but whether you're using (P)EAP-TLS or PEAP-MSCHAPv2, they both require a certificate on the NPS.  Your only options for the clients are to get them to trust the NPS cert, uncheck the "validate server certificate" box, or use a cert for the NPS from a publicly trusted CA (which the clients will already trust).  If you don't want certificates at all, don't use 802.1x.
0
 

Author Closing Comment

by:Gex010
ID: 38854180
I figured I wouldn't have much of a choice but I will stick with 802.1x since this is for a BYOD solution and so far Macbooks, android and apple mobile devices are all able to bypass the problem by offering a pop up to ignore the certificate, including windows mobile devices, so hopefully Windows 8 will get around this problem.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question