Validate server certificate

I know it's not a strictly cisco-based question and maybe is a dumb one, but I've got no other place where I can go :-(( In an environment with a wireless supplicant (windows xp native, aegis, odyssey, windows mobile or others), a cisco ap and a windows 2003 server with ias and certificate server I'm not able to make it work with the option "evaluate the server certificate" active, this applies however with both eap-tls and eap-peap. If I leave this option unchecked all works fine, if I check the option I see in the event viewer something like "wrong username or password". What's going on? Do I need a computer certificate in order to check the server one? Tnx, Tosh.

Reply to
Tosh
Loading thread data ...

When you selected "Validate Server certificate" the client will only accept certificates from CA's it trusts.

Hence you need to install the CA's root certificate on the client, if you want to validate the server certificate.

Unchecking the option will allow any CA's certificate to be used by the Authentication server.

Reply to
Vivek

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.