Windows Thread, 802.1x Wireless User Auth w/ XP Mandatory Profiles? in Technical; Hi there,
Anyone ever had problems with 802.1x (EAP-MS-CHAPV2) user authentication over wireless not working when using mandatory user profiles ...
-
7th August 2008, 04:20 PM #1
- Rep Power
- 0
802.1x Wireless User Auth w/ XP Mandatory Profiles?
Hi there,
Anyone ever had problems with 802.1x (EAP-MS-CHAPV2) user authentication over wireless not working when using mandatory user profiles (WinXP, SP3)?
When a user logs on with a mandatory profile the RADIUS server (IAS on 2008) just sees repeated attempts to authenticate, but there's never an IAS_SUCCESS event indicating a proper connection (the clients stall at the 'validating identity' stage). Simply changing the profile to a normal roaming profile (NTUSER.MAN --> NTUSER.DAT, no other changes) results in everything working fine with successful authentication, and connection, etc. Rather odd and rather frustrating - the lack of anything on Google makes me wonder if it mightn't be an SP3 foible, but annoyingly I don't have any SP2 machines immediately to hand...
Will crack out Wireshark/Process Monitor tomorrow and figure this out, but kind of hopeful someone here might well have experienced this before?
Cheers,
Chris.
-
-
7th August 2008, 04:29 PM #2 Have you tired recreating a profile?
Z
-
-
16th October 2008, 11:59 PM #3
- Rep Power
- 0
Having same problem
Did anyone find a fix for this problem. I am having the same thing happen.
Thanks
Ricky
-
-
17th October 2008, 08:42 AM #4 Interesting we use machine authentication here so don't have an issue with user profiles.
Ben
-
-
17th October 2008, 09:20 AM #5 
Originally Posted by
ChrisCole
Hi there,
Anyone ever had problems with 802.1x (EAP-MS-CHAPV2) user authentication over wireless not working when using mandatory user profiles (WinXP, SP3)?
When a user logs on with a mandatory profile the RADIUS server (IAS on 2008) just sees repeated attempts to authenticate, but there's never an IAS_SUCCESS event indicating a proper connection (the clients stall at the 'validating identity' stage). Simply changing the profile to a normal roaming profile (NTUSER.MAN --> NTUSER.DAT, no other changes) results in everything working fine with successful authentication, and connection, etc. Rather odd and rather frustrating - the lack of anything on Google makes me wonder if it mightn't be an SP3 foible, but annoyingly I don't have any SP2 machines immediately to hand...
Will crack out Wireshark/Process Monitor tomorrow and figure this out, but kind of hopeful someone here might well have experienced this before?
Cheers,
Chris.
Hi,
I don;t know if mandatory profile locks down the registry but with that setup the users will need access to HKEY_CURRENT_USER\Software\Microsoft\EAPOL\UserEap Info
Try to see if access is denied to this section of the registry.
Ash.
-
-
17th October 2008, 04:01 PM #6
- Rep Power
- 0

Originally Posted by
plexer
Interesting we use machine authentication here so don't have an issue with user profiles.
Ben
Yeah, we have to use Computer Authentication now since SP3. Whatever happened, SP3 it. We had no problem until we upgraded to SP3. Wonder why Microsoft would have disabled 802.1x User Authenication with Mandatory Profiles?
Thanks
Ricky
-
-
20th November 2008, 05:04 AM #7
- Rep Power
- 0
I am also having the same problem.... after taking forever to narrow down...
No one have a proper fix without moving to computer auth or changing to roaming profiles.....?
-
-
17th February 2009, 04:39 AM #8
- Rep Power
- 0
We are also having this issue - what brand of Access Points are you using?
Has there been any solution to this without changing Authentication types?
-
-
1st October 2009, 01:16 PM #9
Solution!
Just been working on this issue myself, and have found a solution.
Microsoft have released a hotfix to solve the problem, which allows user authentication to take place using 802.1x on Windows XP SP3.
A Windows XP Service Pack 3-based client computer cannot use the IEEE 802.1x authentication when you use PEAP with PEAP-MSCHAPv2 in a domain
Hope this helps.
-
-
1st December 2009, 06:03 PM #10
- Rep Power
- 0
Hiya
we had a similar problem, dont have time to check if its same as the one posted above but ours turned out to be a server2008 issue.
search for and read up on KB969111, sorry if its the same as already posted
Dave
-
SHARE:
Similar Threads
-
By jcollings in forum Networks
Replies: 7
Last Post: 9th September 2009, 03:36 PM
-
By leegcvcc in forum Windows
Replies: 12
Last Post: 9th May 2008, 09:45 AM
-
By spc-rocket in forum Networks
Replies: 0
Last Post: 3rd January 2008, 07:15 PM
-
By wesleyw in forum Hardware
Replies: 2
Last Post: 4th October 2007, 09:34 AM
-
By HodgeHi in forum Windows
Replies: 2
Last Post: 6th December 2006, 12:56 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Tags for this Thread
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules