Jump to content

Recommended Posts

Posted

Ok,

 

I may be being special here, after an unforeseen side effect of removing an old Certificate Authority, after new one had been publishing since November.

 

The wireless GPO is set up to do the following:

-Auto-enrol a certificate but no certificate templates defined in the GPO

-set up a wireless profile to connect to SSID but using EAP to connect only if this cert was present.

 

Symptoms:

If the workstation does not have a current cert from the new CA it just doesn't even try and connect and comes up with the troubleshooting wizard.

 

Surely the wireless profile should be setup to connect using the certificate no EAP to the RADIUS server?

 

This has lead to us having to drop all other plans and get our almost 1000 windows laptops, find a live port, connect switches, GPUPDATE or enrol the certificate and then restart the wireless adapter. We managed to do 200 in 2 1/2 hours today after the issue was highlighted.

 

Can anyone see if this is actually correct or should we be authenticating with the certificates?

 

This probably explains the years of issues with having to GPUDATE to get laptops back on the wireless. This is the last bit of the post BSF setup that I am picking apart now. (2 years on)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...