Results 1 to 7 of 7

Thread: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

  1. #1
    Join Date
    Apr 2010
    Posts
    210

    Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    I am trying to utilize a smartcard to substantiate a person on a Wi-Fi 802.1X substantiation using PEAP. The smartcard is the Portuguese Identity Card that was residential for sustaining SSL client side authentication. On the other hand, when I utilize the Intel ProSet Wi-Fi tool, it does not be familiar with the existence of appropriate smartcard for client side authentication. The roots CAs make available by the RADIUS server contain the root CA of the smartcard's certificates, which is GTE CyberTrust Global Root. What dangerous characteristic is Intel PROSet looking in the smartcard, or in the individual CAPI CSP (if using it), that it does not locate or, rephrasing my question, how does ProSet looks for credentials in the smartcard.

  2. #2
    Join Date
    May 2009
    Posts
    1,084

    Re: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    Extensible Authentication Protocol, or EAP, is a verification framework regularly used in wireless networks and Point-to-Point associations. It is distinct in RFC 3748, which complete RFC 2284 obsolete, and was reorganized by RFC 5247. EAP is an verification framework providing for the transport and procedure of keying material and parameters engender by EAP methods. There are numerous methods defined by RFCs and a number of vendor unambiguous methods and innovative proposals exist. EAP is not a wire protocol; as an alternative it merely defines message formats. Every protocol that uses EAP defines a method to encapsulate EAP messages within that protocol's messages.

  3. #3
    Join Date
    Jul 2009
    Posts
    1,118

    Re: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    LEAP uses a customized version or description of MS-CHAP, an substantiation protocol in which user credentials are not powerfully protected and are consequently easily compromised. By the side of these lines, an exploit tool called ASLEAP was unconstrained. Cisco suggests that customers that completely must utilize LEAP do so merely by means of adequately complex passwords, although complex passwords are complicated to administer and enforce. Cisco's current general suggestion is to utilize newer and stronger EAP protocols such as EAP-FAST, PEAP, or EAP-TLS.

  4. #4
    Join Date
    Jul 2009
    Posts
    1,179

    Re: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    The EAP-Transport Layer Security (EAP-TLS), distinctive in RFC 5216, is an IETF open customary, and is well sustained or maintained among wireless vendors. The sanctuary of the TLS protocol is strong, make available the user understands potential warnings regarding false credentials. It uses PKI to protected communication to a RADIUS verification server or an additional type of authentication server. So even although EAP-TLS provides tremendous sanctuary, the overhead of client-side certificates might be its Achilles' heel.

  5. #5
    Join Date
    Apr 2008
    Posts
    2,276

    Re: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    EAP-TLS is the innovative, customary wireless LAN EAP authentication protocol. Even though it is infrequently deployed, it is tranquil considered one of the most protected EAP standards obtainable and is universally sustained or maintained by the entire manufacturers of wireless LAN hardware and software. The requirement for a client-side certificate, on the other hand unpopular it might be, is what gives EAP-TLS its substantiation strength and illustrates the classic convenience vs. security trade-off. A conciliation password is not sufficient to break into EAP-TLS facilitated systems for the reason that the intruder tranquil requirements to have the client-side private key.

  6. #6
    Join Date
    Oct 2005
    Posts
    2,393

    Re: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    The highest sanctuary obtainable is when client-side keys are housed in smart cards. This is for the reason that there is no method to steal a certificate's equivalent private key from a smart card without stealing the card itself. It is considerably additional probable that the physical theft of a smart card would be noticed (and the smart card instantaneously revoked) than a (representative) password theft would be noticed. There are client and server accomplishments of EAP-TLS in Microsoft, Cisco, Apple, and open source operating systems. EAP-TLS is natively sustained or maintained in Mac OS X 10.3.

  7. #7
    Join Date
    May 2008
    Posts
    518

    Re: Client Smart Card authentication with 802.1X and PEAP on Windows XP Media Center

    The IEEE and wireless industry in progress developing innovative protocols and standards. They came up by means of the 802.11i, a standard to in conclusion put into practice a fully secure encryption mechanism for wireless LANs. Previous to it was accomplished; the Wi-Fi Alliance released the Wi-Fi Protected Access (WPA) encryption customary, loosely based on 802.11i using TKIP for the underlying encryption. Afterward they released WPA2, which contains full hold up for 802.11i using AES/CCMP encryption.

Similar Threads

  1. Graphic Card update for Windows Media Center
    By LFC18 in forum MediaCenter
    Replies: 4
    Last Post: 30-05-2013, 10:37 AM
  2. Replies: 4
    Last Post: 11-02-2012, 12:44 PM
  3. How to Use PEAP for wireless authentication
    By Ameeryan in forum Networking & Security
    Replies: 3
    Last Post: 28-10-2009, 12:53 PM
  4. How to disable Smart Card authentication in Vista
    By Fernandoa in forum Networking & Security
    Replies: 3
    Last Post: 21-07-2009, 08:34 PM
  5. PEAP user authentication failed - need help
    By zvone2000@gmail.com in forum Windows Server Help
    Replies: 4
    Last Post: 20-06-2009, 12:18 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,929,212.61404 seconds with 17 queries