radius server authenication problem

sonoma1993

Diamond Member
May 31, 2004
3,415
21
81
I'm running a Linksys WRT54g router with DDwrt v24 sp1 firmware and running server 2008. in trying to setup a home radius server to test and play around with for my wireless.

my router wireless radius settings arw WPA2 Enterprise
tkip+aes
then it points to my server 2008 internal address of 10.10.20.159
radius port 1812
then the share key

my server 2008 radius settings are set uo
it points to my router internal IP address
same radius share key as the router
for authenication method im using currently using the method smart card or any other ceritifacte, then i just seletced one of my local server certificates.

when i test these settings out with my laptop, it'll connect to the wireless but it stuck in waiting for authenication

during the authenication, i'll get message that addiontal information is require to connect. click here to enter addiotnal information

I click on that, and a box pops up to select two different user ceritifcates. i select one, and nothing happens. i select the other one and nothing happens as well

I created these user certicates by using https://servername/certsrv from my server. install these certs on my laptop and my server

i tried setting the radius to use different certificates from my server but it still wont authenicate and let me connect.

oh and Im using microsoft network policy server that built into server 2008

any suggestions on what to do?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
What EAP method are you using? PEAP? I think you're running into a certificate trust list problem - you're trying to use a cert that isn't trusted.
 

sonoma1993

Diamond Member
May 31, 2004
3,415
21
81
Originally posted by: spidey07
What EAP method are you using? PEAP? I think you're running into a certificate trust list problem - you're trying to use a cert that isn't trusted.

on the server it says Microsoft: Smart card or certifcate

then in the boxes below for the section Less secure Authencation methods
the following are selected by default

Microsoft Encrypted Authentication version 2 Ms Chap v2
user can change password after it has expired
Microsoft ENcryted Authentication MS Chap
User can change password after it has expired

client side forgot to mention, laptop is using windows vista ultiamte
Serivce type WPA2 interprise
encryption type AES

then choose a network authentication method
Microsoft: Smart Card or other certificate, then the setting box next to that
when connection: use a certificate on this computer
the use simple certificate selection is unchecked

then the validate server certificate is checked as well
and I selected the certificates from my server in that list
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
uncheck the "validate server certificate". This is still some kind of trust or cert mismatch. Every single thing has to be just perfect on both ends.

I'm not familiar at all with windows built in wireless support because frankly, it sucks.