Jump to content

802.11x Authentication with Redirected App data


Recommended Posts

Posted

Hi all,

 

(In the words of Dwight Schrute)

 

Question,

 

Has anyone gone down the road of 802.11x authentication with a redirected app data folder before?

 

We don't have roaming profiles so app data is redirected and stored on one of our servers. This works ok, but when it comes to 802.11x auth the machine will authenticate ok then the user logs in....

 

The user then gets kicked off just after the logon process has completed due to the certificates for EAP-TLS being stored in the %appdata% path.

 

Has anyone got this working? I suppose we could use machine only authentication which would solve this problem, but I would be interested if anyone has come across a solution. (Also not validating server certificates is not a good solution as its a security hole I would not like to open!)

 

James

Posted

Or a better question may be:

 

Has anyone successfully deployed 802.11x authentication with 'Machine with User Re-Authentication' AND have a redirected application data folder......

Posted
Or a better question may be:

 

Has anyone successfully deployed 802.11x authentication with 'Machine with User Re-Authentication' AND have a redirected application data folder......

 

While I have used 802.11x, a lot (site wide), it has only been with machine only authentication. I would however say this, whatever you do with 802.1x don't bother if you are using XP. Vista/7 will hold various policy and login processes while the authentication happens, XP does not. On 7 now, not prefect still, but works nearly all the time (clock issues mostly!).

 

I did use 802.1x with XP, but the faster the machine got, the less likely it was to get everything going in time for policies and scripts to be applied at boot.

  • Thanks 1
Posted
I think machine only authentication will be the answer here, I have tried a lot to get user auth working without having to stick app data back on C: but can't seem to get round the fact that when the machine is disconnected from the network the user account can no longer access its certificates on the server due to the network connection being severed. Seems like a completely stupid thing to do!
Posted

 

We are probably going to use EAP-TLS due to Authentication may not succeed when you use PEAP-MS-CHAP-v2 as the authentication method for an 802.1X connection in Windows Vista, Windows XP, Windows Server 2003, and Windows 2000 which we have previously had problems with (staff coming back after holidays and having hundreds of laptops which then have to be booted with the cable as users can't log on!!).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...