Solved

How does my NPS certificate work?

Posted on 2015-02-19
4
79 Views
Last Modified: 2015-02-20
Hi,

I've had to pick up a NPS RADIUS configuration since a colleague left.

It's all configured but I'm struggling to understand how it's strung together - mainly for the certificate side of things.

There is a "wireless connection" certificate created which apparently is the certificate needed in order to authenticate to the wireless network. This is set to auto enroll.

The issue is, looking at the config on the NPS server, I cannot see anywhere where it actually states that this is the certificate that should be used. Under the connection policy, I can see it requires authentication via a certificate. I assumed it would be a case of telling the policy which cert to use but all I can see is the CA server listed under the settings.

It's the first time I've dealt with certs which is why I'm struggling really.
I have raised another question about an issue I get with being auto enrolled but that's another topic.

How on earth does the policy know which certificate I should have in order to allow me to connect?

Any help/advice would be welcome.

Thanks
0
Comment
Question by:MFAFC
  • 2
4 Comments
 

Author Comment

by:MFAFC
ID: 40619022
Is it because the certificate simply has "server authentication" as one of it's intended purposes that allows me to connect?
0
 
LVL 21

Accepted Solution

by:
Jakob Digranes earned 250 total points
ID: 40619775
Yes --- you're quite right in your own comment. There is no place in the policy that specify what certificate can be used. You'd need the client authentication (or server authentication) intended purpose. If you have only one certificate, windows will select this - if you have multiple - it will ask you to choose using a dialog box that pops up before authentication
0
 
LVL 30

Assisted Solution

by:Rich Weissler
Rich Weissler earned 250 total points
ID: 40619864
The certificate requirement depends on what is being authenticated.  From Microsoft Technet:
"For example, a certificate used for the authentication of a client to a server must be configured with the Client Authentication purpose. Similarly, a certificate used for the authentication of a server must be configured with the Server Authentication purpose. "
0
 

Author Comment

by:MFAFC
ID: 40620727
Thank you both for taking the time to help.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question