Solved

NPS SSL Certificate Issue for Windows 7 Wireless Clients

Posted on 2014-01-22
5
2,493 Views
Last Modified: 2014-02-01
Brand new Windows 7 Enterprise laptops will not connect to 802.1x internal wifi.
I have a GPO that creates the connection profile for the laptops.

I have a DigiCert SSL certificate installed on my NPS server (2008 R2 Enterprise) which is valid until 12/10/2014.  It's selected in the Network Policy under the PEAP (with EAP-MSCHAP v2) configuration.

The certificate was issued by the DigiCert Secure Server CA which is in the Trusted Root Certification Authorities store on the local computer.

As a troubleshooting step I exported the certificate from the NPS server and imported it directly into the Trusted Root CA on one laptop and still was unable to connect.

The event log on the client shows two schannel errors:
Error      1/22/2014 2:37:33 PM      Schannel      36888      The following fatal alert was generated: 45. The internal error state is 552.

Error      1/22/2014 2:37:33 PM      Schannel      36881      The certificate received from the remote server has either expired or is not yet valid. The SSL connection request has failed. The attached data contains the server certificate.

I'm at a complete loss because as far as I can tell the certificate should be trusted.  And as a note the client will not accept clearing the checkbox in the GPO to not check the certificate.

Any ideas?
0
Comment
Question by:sovran
  • 2
  • 2
5 Comments
 
LVL 39

Expert Comment

by:footech
ID: 39801898
Check out the certification path of the certificate.  Perhaps there is an intermediate certificate that needs to be deployed.
Also, if the event contains the cert, can you verify that it is the cert that you think it is?
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39805231
I think you need to uncheck the 'Validate Server Certificate' option in the PEAP properties page.  You'll find this in the GPO you configured.
0
 

Accepted Solution

by:
sovran earned 0 total points
ID: 39813627
I was able to determine root cause of the RADIUS issues with the new Windows 7 machines.  It relates to these MS KB's (http://support.microsoft.com/kb/295663) & (http://support.microsoft.com/kb/2518158) which both show that the builtin Windows wifi supplicant does not automatically trust public CA's for NT authentication.

By running the following command (certutil -dspublish -f C:\digi_global_root_ca.cer NTAuthCA) I was able to set AD to publish the Digicert Root CA as a trusted CA for NT authentication and the three laptops that I've been testing with have connected successfully ever since.
0
 
LVL 39

Expert Comment

by:footech
ID: 39813877
Thanks for posting back the solution you found.
0
 

Author Closing Comment

by:sovran
ID: 39826123
Because this fixed the issue without turning off certificate validation.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now