Jobos Posted May 21, 2010 Posted May 21, 2010 Is there a way using GP to hide the network key in the wireless network properties as ticking show characters reveals the key in plain text. I know only admins can see this but I prefer the way XP did it!
prad Posted May 24, 2010 Posted May 24, 2010 I know this isn't a direct answer to your question, but if you used a WPA enterprise style setup, you can get authentication based on computer certificates, and therefore no need for keys It's supposed to be the most secure method for wireless networking. I can provide more info if necessary.
prad Posted May 24, 2010 Posted May 24, 2010 You mean install a radius server? Yeah.... I used to use IAS (Windows Server 2000/2003), and since upgrading to Server 2008 I now use NPS. Both are the same and have a RADIUS server built in.
Jobos Posted May 24, 2010 Author Posted May 24, 2010 Right thanks. This school is moving to Server 2008 soon so will have to take a look at that.
prad Posted May 24, 2010 Posted May 24, 2010 Right thanks. This school is moving to Server 2008 soon so will have to take a look at that. You can do it with 2000/2003
soveryapt Posted May 24, 2010 Posted May 24, 2010 You can do it with 2000/2003 At the risk of sounding dumb .. how? I've been looking for a solution but only on the side of all the other jobs .. lol ..
prad Posted May 24, 2010 Posted May 24, 2010 (edited) At the risk of sounding dumb .. how? I've been looking for a solution but only on the side of all the other jobs .. lol .. So here's the requirements: 1. A certificate server on the domain dishing out certificates to all domain computers (well at least the ones you want to use the wireless policy) 2. IAS installed on a domain controller 3. Wireless Access points that support WPA Enterprise (most do now) In IAS: 1. You need to create a wireless access policy. Mine is based on the group 'Domain Computers'. This allows all computers that are a member of that group access. In that policy setting you will see PEAP options where you select your cerificate server 2. You need to add a RADIUS Client (the access point) and configure a shared secret On the Access Point: 1. Configure WPA Enterprise security.. The only settings are, RADUIS Server IP, and the shared secret. Then either through a GPO or directly on the computers configre the wireless profile for that SSID, selecting WPA (or WPA2), but there's an option to choose PEAP authentication. Check the local certificate by running the 'Certificates' mmc snap in and selecting local computer. The certificate should be the one issued by the same server selected in the IAS wireless policy. That's pretty much it. The logs on the server running IAS will help you troubleshoot if you get any issues. Feel free to give me a shout and I will send you screen shots of all my config. Edited May 24, 2010 by prad spelling error 2
Jobos Posted May 24, 2010 Author Posted May 24, 2010 You can do it with 2000/2003 I don't want to redo it all when the new server arrives.
soveryapt Posted May 24, 2010 Posted May 24, 2010 So here's the requirements: 1. A certificate server on the domain dishing out certificates to all domain computers (well at least the ones you want to use the wireless policy) 2. IAS installed on a domain controller 3. Wireless Access points that support WPA Enterprise (most do now) In IAS: 1. You need to create a wireless access policy. Mine is based on the group 'Domain Computers'. This allows all computers that are a member of that group access. In that policy setting you will see PEAP options where you select your cerificate server 2. You need to add a RADIUS Client (the access point) and configure a shared secret On the Access Point: 1. Configure WPA Enterprise security.. The only settings are, RADUIS Server IP, and the shared secret. Then either through a GPO or directly on the computers configre the wireless profile for that SSID, selecting WPA (or WPA2), but there's an option to choose PEAP authentication. Check the local certificate by running the 'Certificates' mmc snap in and selecting local computer. The certificate should be the one issued by the same server selected in the IAS wireless policy. That's pretty much it. The logs on the server running IAS will help you troubleshoot if you get any issues. Feel free to give me a shout and I will send you screen shots of all my config. I'll take a look at that this week and see what I come up with! Many thanks
User3204 Posted May 24, 2010 Posted May 24, 2010 In Server 2008, they have renamed IAS to Network Protection Server, and it is very Wizardy.. I've been fiddling with it, as I want to move from our current IAS servers on Windows 2003, to Server 2008. Not got very far with it, but it all seems to work the same.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now