Solved

RADIUS Server Certificate

Posted on 2014-03-23
7
287 Views
Last Modified: 2014-03-25
Hello Experts:

I will be installing and configuring a RADIUS server on either Windows Server 2003 or Windows Server 2008 R2.  It is due to a migration from Windows 2003.  

I need to find out if the current RADIUS Server running on Windows 2003 has a certificate or uses a certificate.  Please let me know how I find that one out.

Also, does a RADIUS server need a certificate to work properly?

Thanks
Willie
0
Comment
Question by:willie0-360
  • 4
  • 3
7 Comments
 
LVL 21

Expert Comment

by:Jakob Digranes
ID: 39949697
If you need a certiticate or not depends on how authentication is set up. But if you use (and you really should use this) PEAP - then you need a certificate on radius server. With PEAP the client and Radius server sets up a secure encrypted tunnel where user credentials can be exchanged, either this be ms-chapV2 or EAP-TLS.

To find what cert the 2003 is using, you can go to administrative tools - Internet Authentication Services - go to network policies - choose edit profile - authentication, there you should see it (sorry - I might be a bit rusty, been some time since I've worked with 2003 radius)

You can also start MMC and add snap-in certificates - local machine - and see under personal if a RAS/IAS certificate, or server/computer certificate is enrolled - then it might be used with radius
0
 

Author Comment

by:willie0-360
ID: 39950523
Thanks for your response jakob_di.

Your response raises the question of how do I determine if I am using PEAP or any other.

Also, I did what you suggested in your second paragraph.  I went to Administrative Tools --> Internet Authentication Services, but I was not able to find Network Policies and what follows after that.

I also tried starting the MMC, but when I tried to snap in a certificate, it seems that it wants to  create/install a new certificate.

I need more help.


Thanks.
Willie
0
 
LVL 21

Assisted Solution

by:Jakob Digranes
Jakob Digranes earned 500 total points
ID: 39951022
sorry --- my bad. remembered it wrong. See attached pictureias 2003
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Author Comment

by:willie0-360
ID: 39951165
Based on that, I would say we are using PEAP.  Please see the attached word document with the pictures I included.

Figure 1indicates I am using PEAP.  However, Figure 1 shows that a certificate could not be found that can be used with this EAP, even though it is using PEAP.  In your first post, you indicated that if using PEAP a certificate is required.  Then, what does that message about a certificate not found means?

Also, Figure 2 has Microsoft Encrypted Authentication version 2 (MS-CHAP v2), does that mean anything regarding the use of certificates?

Thanks.
Willie
wireless.experts.exchange.docx
0
 
LVL 21

Accepted Solution

by:
Jakob Digranes earned 500 total points
ID: 39951266
yes - you're not using PEAP - at least any more. It might be that the certificate is expired and thus not found anymore.
But you're using mschap v2 only.
ms-chapV2 can in fact be broken, and should not be used without PEAP
0
 

Author Comment

by:willie0-360
ID: 39953390
Thanks a lot for your help jakob_di.  I hope to find you again in the future.


Willie
0
 
LVL 21

Expert Comment

by:Jakob Digranes
ID: 39953438
Excellent .... Glad to help :-)

jakob
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Setup router as access point - no internet 5 59
Scammer phone call - detect IP based on the phone number? 13 76
WAP requirements 5 49
Radius Debug Error 16 58
With the purchase of CloudCommand by Comcast customers are left in a bind as subscriptions expire and render the AP's disabled. The following will explain how to flash your Ubiquiti AP's with CloudCommand firmware back to Ubiquiti firmware. HOWTO…
DECT technology has become a popular standard for wireless voice communication. DECT devices are not likely to be affected by other electronic devices and signals because they operate in a separate frequency-band.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now