Jump to content

Recommended Posts

Posted

Does anybody here have a wireless network set up with EAP-TLS authentication?

 

I've set up a Windows CA, with computer and user templates that AutoEnrol then set up a policy on Cisco ISE with EAP-TLS authentication for the SSID

 

All this works fine apart from one major issue!

 

I build a brand new Windows 10 laptop, and then add it to the domain through a wired connection, so it can grab the Root CA certificate and stick it in the Trusted Root store. After a couple of reboots it then manages to AutoEnrol for it's computer certificate and can then join the wireless network as soon as it gets to the login screen.

 

However, once a user account logs in that is a member of an AD group that is allowed to authenticate to the wireless it seems to drop the computer wireless connection at some point between the user logging in at the login screen and the desktop - it seems as if at some point during this stage the user certificate auto enrolment should be taking place but it obviously can't as it has lost the wireless and therefore connection to the network to do so! If I do the same process with a wired connection into the laptop it all works fine, the user account receives their certificate.

 

I can't work out how to get around the issue without cheating and just telling everyone to plug in a cable the first time they login to a device which would be a bit of a headache considering that could be up to 2000+ users across various sites some of whom struggle to locate the power button let alone the ethernet socket!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...