Article ID: 814394 - Last Review: October 30, 2006 - Revision: 3.4 Certificate requirements when you use EAP-TLS or PEAP with EAP-TLSOn This PageINTRODUCTIONThis article describes the requirements that your client certificates and your server certificates must meet when you use Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) or Protected Extensible Authentication Protocol (PEAP) with EAP-TLS. MORE INFORMATIONWhen you use EAP with a strong EAP type, such as TLS with smart cards or TLS with certificates, both the client and the server use certificates to verify their identities to each other. Certificates must meet specific requirements both on the server and on the client for successful authentication.
One requirement is that the certificate must be configured with one or more purposes in Extended Key Usage (EKU) extensions that match the certificate use. For example, a certificate that is used for the authentication of a client to a server must be configured with the Client Authentication purpose. Or, a certificate that is used for the authentication of a server must be configured with the Server Authentication purpose. When certificates are used for authentication, the authenticator examines the client certificate and looks for the correct purpose object identifier in EKU extensions. For example, the object identifier for the Client Authentication purpose is 1.3.6.1.5.5.7.3.2. Minimum certificate requirementsAll certificates that are used for network access authentication must meet the requirements for X.509 certificates, and they must also meet the requirements for connections that use Secure Sockets Layer (SSL) encryption and Transport Level Security (TLS) encryption. After these minimum requirements are met, both the client certificates and the server certificates must meet the following additional requirements.Client certificate requirementsWith either EAP-TLS or PEAP with EAP-TLS, the server accepts the client's authentication when the certificate meets the following requirements:
Server certificate requirementsYou can configure clients to validate server certificates by using the Validate server certificate option on the Authentication tab in the Network Connection properties. When a client uses PEAP-EAP-MS-Challenge Handshake Authentication Protocol (CHAP) version 2 authentication, PEAP with EAP-TLS authentication, or EAP-TLS authentication, the client accepts the server's certificate when the certificate meets the following requirements:
REFERENCESFor more information about wireless network technologies, visit the following Microsoft Web site: http://www.microsoft.com/whdc/connect/wireless/default.mspx
(http://www.microsoft.com/whdc/connect/wireless/default.mspx)
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
313242
(http://support.microsoft.com/kb/313242/
)
How to troubleshoot wireless network connections in Windows XP
APPLIES TO
| Article Translations
|
Back to the top
