Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Windows

Windows forum sponsored by

For all of your Windows problems

Go Back   EduGeek.net Forums > Technical > Windows
Reply
 
LinkBack Thread Tools Search Thread
Sponsored Links
Old 07-08-2008, 04:20 PM   #1
 
ChrisCole's Avatar
 
Join Date: Aug 2008
Location: London
Posts: 4
uk uk wales
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 0 ChrisCole is an unknown quantity at this point
Default 802.1x Wireless User Auth w/ XP Mandatory Profiles?

Hi there,

Anyone ever had problems with 802.1x (EAP-MS-CHAPV2) user authentication over wireless not working when using mandatory user profiles (WinXP, SP3)?

When a user logs on with a mandatory profile the RADIUS server (IAS on 2008) just sees repeated attempts to authenticate, but there's never an IAS_SUCCESS event indicating a proper connection (the clients stall at the 'validating identity' stage). Simply changing the profile to a normal roaming profile (NTUSER.MAN --> NTUSER.DAT, no other changes) results in everything working fine with successful authentication, and connection, etc. Rather odd and rather frustrating - the lack of anything on Google makes me wonder if it mightn't be an SP3 foible, but annoyingly I don't have any SP2 machines immediately to hand...
????: EduGeek.net Forums http://www.edugeek.net/forums/windows/22666-802-1x-wireless-user-auth-w-xp-mandatory-profiles.html

Will crack out Wireshark/Process Monitor tomorrow and figure this out, but kind of hopeful someone here might well have experienced this before?

Cheers,

Chris.
  Reply With Quote
Old 07-08-2008, 04:29 PM   #2
 
FN-GM's Avatar
 
Join Date: Jun 2007
Location: Rochdale, Lancashire
Posts: 6,619
uk uk england
Thanks: 189
Thanked 356 Times in 323 Posts
Rep Power: 77 FN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant futureFN-GM has a brilliant future
Send a message via Skype™ to FN-GM
Default

Have you tired recreating a profile?

Z
  Reply With Quote
Old 16-10-2008, 11:59 PM   #3
 
risbell's Avatar
 
Join Date: Aug 2007
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 risbell is an unknown quantity at this point
Default Having same problem

Did anyone find a fix for this problem. I am having the same thing happen.

Thanks

Ricky
  Reply With Quote
Old 17-10-2008, 08:42 AM   #4
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 5,148
uk
Thanks: 52
Thanked 229 Times in 208 Posts
Rep Power: 60 plexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud ofplexer has much to be proud of
Default

Interesting we use machine authentication here so don't have an issue with user profiles.

Ben
  Reply With Quote
Old 17-10-2008, 09:20 AM   #5
 
ashok's Avatar
 
Join Date: Oct 2005
Location: East Midlands
Posts: 536
uk
Thanks: 6
Thanked 49 Times in 34 Posts
Rep Power: 17 ashok has a spectacular aura aboutashok has a spectacular aura aboutashok has a spectacular aura about
Default

Quote:
Originally Posted by ChrisCole View Post
Hi there,

Anyone ever had problems with 802.1x (EAP-MS-CHAPV2) user authentication over wireless not working when using mandatory user profiles (WinXP, SP3)?

When a user logs on with a mandatory profile the RADIUS server (IAS on 2008) just sees repeated attempts to authenticate, but there's never an IAS_SUCCESS event indicating a proper connection (the clients stall at the 'validating identity' stage). Simply changing the profile to a normal roaming profile (NTUSER.MAN --> NTUSER.DAT, no other changes) results in everything working fine with successful authentication, and connection, etc. Rather odd and rather frustrating - the lack of anything on Google makes me wonder if it mightn't be an SP3 foible, but annoyingly I don't have any SP2 machines immediately to hand...

Will crack out Wireshark/Process Monitor tomorrow and figure this out, but kind of hopeful someone here might well have experienced this before?

Cheers,

Chris.
Hi,

I don;t know if mandatory profile locks down the registry but with that setup the users will need access to HKEY_CURRENT_USER\Software\Microsoft\EAPOL\UserEap Info

Try to see if access is denied to this section of the registry.

Ash.
  Reply With Quote
Old 17-10-2008, 04:01 PM   #6
 
risbell's Avatar
 
Join Date: Aug 2007
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 risbell is an unknown quantity at this point
Default

Quote:
Originally Posted by plexer View Post
Interesting we use machine authentication here so don't have an issue with user profiles.

Ben
Yeah, we have to use Computer Authentication now since SP3. Whatever happened, SP3 it. We had no problem until we upgraded to SP3. Wonder why Microsoft would have disabled 802.1x User Authenication with Mandatory Profiles?

Thanks

Ricky
  Reply With Quote
Old 20-11-2008, 04:04 AM   #7
 
mrayner's Avatar
 
Join Date: Nov 2008
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 mrayner is an unknown quantity at this point
Default

I am also having the same problem.... after taking forever to narrow down...

No one have a proper fix without moving to computer auth or changing to roaming profiles.....?
  Reply With Quote
Old 17-02-2009, 03:39 AM   #8
 
korupt_coupe's Avatar
 
Join Date: Feb 2009
Posts: 1
australia au tasmania
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 korupt_coupe is an unknown quantity at this point
Default

We are also having this issue - what brand of Access Points are you using?

Has there been any solution to this without changing Authentication types?
  Reply With Quote
Reply
Similar Threads
Thread Thread Starter Forum Replies Last Post
Mandatory Profiles jcollings Networks 5 25-02-2009 12:21 PM
Mandatory Profiles leegcvcc Windows 12 09-05-2008 09:45 AM
Wireless 802.1x RADIUS authentication using IAS server ashok Networks 0 03-01-2008 06:15 PM
Wireless - WPA/802.1x wesleyw Hardware 2 04-10-2007 09:34 AM
Mandatory Profiles HodgeHi Windows 2 06-12-2006 11:56 AM


Tags
802.1x mschapv2


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:06 AM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.
Copyright EduGeek.net




website uptime

© 2005 - 2009 EduGeek.net
no new posts