Certificates downloading to any machine a valid user connects to the wireless

We are set up to download a certificate to PCs over wireless when the user is validated.  No one has ever explained the point of that. It seems like you  do not have 2 factor authentication if you give the second factor away after the first is authenticated.  It has come to a head now with all the IPADs IPhones and are devices the users are carrying.  If they coonect them to the wireless and log in the system asks if they want to download the certificate and it does.  Now we have all these privately owned devices using our company wireless.
So, if it is valid to give out certificates like this, does anyone know how to control which devices they are downloaded to?
Thanks

I think that you may be wrong.
If the authentication method is PEAP for example, only the server side (your radius server) has to show a certificate.
If the clients don't trust by default that cert, they have a pop up asking if they want to trust it/download it.
That's ok.
It's not that you are giving a new certificate to all the clients, you are giving always the same, the server one. And it's ok since your cert is public.
Clients should then only authenticate with credentials.
I have never seen any system where both sides (client and server) authenticate with a certificate but that the client dynamically receive the certificate, that is indeed pointless. I think you need to clarify what exact security mechanism you are using / what EAP method

Similar Messages

  • P6 user name is not valid for connecting to the reporting database

    No data is available because your P6 user name is not valid for connecting to the reporting database
    I am getting above error in the following environment:
    P6 running on wls instance 1.
    BI Publisger running on wls instance 2
    MS SQL server 2005
    Note that the error appears when I clink on the 'Reports' tab in P6. My admin user on P6 has access to report/analyser modules.
    To connect P6 to BI Publisher I am using 'PxRptUser' in the P6 configuration for Bi Publisher. I know as well that the WSDL URL is correct and I can test this in SoapUI tool.
    In BI publisher I have created the PMDB data source using PxRprUser, and the test of this connection works.
    (Because the report samples come with Oracle flavoured SQL that SQL server does not like, I have configured BI Publisher so I have just a single report left that sources it data from an xml file. This works in BI Publisher. It also helps me in that I do not need to add 'WHERE' clauses and parameters required for SQL server?)
    Furthermore, using a DB tool, I can connect to my SQL server using PxRPTUser.
    So why do I get the error above?
    I picked up somewhere that I should not be adding users to BI Publisher. Funny enough, testing the 'login' method the BI Publisher exposes through its WSDL (as above) I noticed I HAD to create the user PxRptUser in BI publisher application itself (on top of PxRptUser in database) for the login web service to work with PxRptUser
    That did not solve the connection between P6 and BI Publisher though. What am I missing ...
    Edited by: user3674522 on 10/11/2011 20:16

    Thought I found something but can't repliacte, som issue is still there:
    Had a look at the wls instance logs where BI publisher is running, and the error I get is:
    111111_023646955][][ERROR] javax.naming.NamingException: Unresolved naming: cn=admin, dc=user, dc=users, dc=principals at [cn=admin]
    That user, admin, is the one I have used to access P6. Why is this passed on to BI Publisher? I thought the idea was that the PxRptUser set in BI Publisher configurations in P6 would be used?
    Edited by: user3674522 on 10/11/2011 20:17

  • SOA EM down after password change - OracleSystemUser is not a valid user principal in the current security realm

    Hello,
    I've got a SOA Suite development environment set up and whilst trying to change the weblogic password using this tutorial a problem arose with my soa managed server.
    Firstly I was unable to start the Managed SOA server due to mismatching passwords, and after I modified the boot.properties file, now I cant start the usermessagingserver and soa_infra applications due to the following error:
    Error 1
    Getting weblogic deployment manager.
    Got weblogic deployment manager.
    Invoking Start Up operation.
    Start Up operation for application usermessagingserver on target soa_server1 RUNNING.
    Start Up operation for application usermessagingserver on target soa_server1 FAILED.
    weblogic.application.ModuleException: Exception preparing module: EJBModule(sdpmessagingclient-ejb-parlayx.jar)
    Unable to deploy EJB: MessagingClientParlayX from sdpmessagingclient-ejb-parlayx.jar:
    The run-as security principal, 'OracleSystemUser', chosen for the EJB 'MessagingClientParlayX(Application: usermessagingserver, EJBComponent: sdpmessagingclient-ejb-parlayx.jar)' is not a valid user principal in the current security realm. Please specify a valid user principal for the EJB to use.
    Getting weblogic deployment manager.
    Got weblogic deployment manager.
    Invoking Start Up operation.
    Start Up operation for application soa-infra on target soa_server1 RUNNING.
    Start Up operation for application soa-infra on target soa_server1 FAILED.
    weblogic.application.ModuleException: Exception preparing module: EJBModule(hw_services_wls_ejb.jar)
    Unable to deploy EJB: ASNSInteraction from hw_services_wls_ejb.jar:
    The run-as security principal, 'OracleSystemUser', chosen for the EJB 'ASNSInteraction(Application: soa-infra, EJBComponent: hw_services_wls_ejb.jar)' is not a valid user principal in the current security realm. Please specify a valid user principal for the EJB to use.
    I've checked both weblogic and OracleSystemUser users and their groups are (respectfully) Administrators and OracleSystemGroup.
    I've searched for an answer to this problem and found this other support article but couldn't resolve the issue.
    The weblogic server version is 10.3.2.0 and it's running on RedHat Linux.

    @Sri_Sonti
    In the Admin Console, I can see both users in the security realm with the following configs:
    weblogic:
    all atributes with the "value" column blank
    groups: Administrators
    OracleSystemUser
    all atributes with the "value" column blank
    groups: OracleSystemGroup
    Also I have not found the system-jazn-data.xml file you mentioned. In that folder there's only a readme.txt file.
    Best Regards,
    luismcs
    Enter Cookie as format:
    (ex: name=val;) separate with ';'
    OKCancel

  • HT4061 I can not connect to ITunes Store to download updates. I have no trouble connecting to the internet. It worked OK up to about a last month. can any body help.

    I can not connect to ITunes Store to download updates. I have no trouble connecting to the internet. It worked OK up to about a last month. can any body help.

    Hi there bigyellowdigger!
    I have an article here that can help you troubleshoot this issue with your connection to the iTunes Store. That article can be found right here:
    Can't connect to the iTunes Store
    http://support.apple.com/kb/ts1368
    Take care, and thanks for visiting the Apple Support Communities.
    -Braden

  • Is their any way to restrict user from overriding  the graphs in SAP APO?

    Dear All,
    As we know, we can copy the graphs to other users using /n/sapapo/sdp_graph. But is their any way to restrict user from overriding the graph to particular user.
    Scenarios:
    In a project we have super user and semi-super user, whenever super user uses above t-code to copy graph to all users (he has included semi-super user id to target user list) but semi-super user does not want to override his graph by super user.
    Do we have such function in APO to restrict?
    Hope it is clear to understand.
    Regards,
    Pravin Tikar

    Hi Amol,
    thanks,
    I have checked SP Note 400434 - Authorizations in APO demand planning Also.
    Will check the authorization and will update the same.
    regards,
    Pravin Tikar

  • ITunes tells me there is an update (5.1) but it never gets any further than trying to connect to the iPad server. I've tried updating directly from my iPad and it too times out saying it cannot connect to any server. My regular Apple updates work fine.

    iTunes tells me there is an iOS update (5.1) but it never gets any further than trying to connect to the iPad server. I've tried updating directly from my iPad and it too times out saying it cannot connect to any server. My regular Apple updates work fine.

    I haven't updated yet. Apple's download servers have been too busy. Did you know you can update via wifi instead of connection to your computer?
    Here's a description of the update. Not a lot of changes for iPad 1/2.
    iOS 5.1 Software Update
    http://support.apple.com/kb/DL1504
    You can wait a while & update at your convenience.
     Cheers, Tom

  • How to make Adobe acrobat feature to convert SAP  Pages to PDF available for multiple users connected to the same server

    We have installed Adobe Acrobat X Pro- English,Francais,Deutsch version 10.1.9 in our test environment and tried  testing it for converting SAP pages into PDF with a few pilot users. In doing so we faced a challenge, where only one user at a time can use Adobe Acrobat PRO to convert SAP pages in to PDF.As long as the first user who  is connected to Adobe Acrobat Pro via SAP isn’t logged off, other users connected to the same  server  are not being able to get the “Save As” dialog box to save the PDF in their preferred location.
    This is a business requirement and we need an urgent solution for the same. Can anyone help us in telling us if this is possible and if yes the how to go about?

    It's not something we deal with here, the LiveCycle products are a different world. Key points: Adobe LiveCycle is a range of products, some desktop, some server. LiveCycle PDF Generator is the one you should look at, it comes in 3 editions. License terms are by negotiation. Key management is via its Java API.

  • I bought my iphone 5 in the USA but am living in the UK. When I was trying to download apps, it said i need to connect to the uk apple store, how do i do that?

    I bought my iphone 5 in the USA but am living in the UK. When I was trying to download apps, it said i need to connect to the uk apple store, how do i do that?

    Settings > iTunes & App Stores
    Tap on your Apple ID at the top
    Tap "View Apple ID"
    Enter password if needed
    Tap "Country/Region"
    Tap "Change Country or Region"
    You may need to change to a UK credit card.

  • Since downloading iSO 5 i can no longer connect to a wireless network.

    since downloading iSO 5 i can no longer connect to a wireless network. I have tried both at home and at other wireless hotspots. it would appear that none of the previous wireless connections work either? i just get the error "unable to connect to "x"
    i have tried to "forget" and rejoin but that has not worked either.
    what to do pleeeease?

    Did you already try to reset the phone by holding the sleep and home button until the Apple logo comes back again?
    Did you try to reset the network settings on your device?

  • I have a MacBook Pro and all of a sudden  I cannot get wireless internet connectivity to my router or any other router, I get connectivity through the ethernet port but not wireless. This was working well till this morning

    I  have a MacBook Pro and all of a sudden  I cannot get wireless internet connectivity to my router or any other router, I get connectivity through the ethernet port but not wireless. This was working well till this morning

    BXB1905 wrote:
    I tried the Apple diagnostics it did not work.
    What do you mean it did not work!  What were the results of the diagnostic tests?
    Have you contacted your ISP to determine if the problem is on their end?  
    Have you changed your router channel?  Sometimes this resolves wireless problems.
    Your profile confirms you are using Lion.  Check out the following: 
    Troubleshooting Wi-Fi issues in OS X Lion and Mac OS X v10.6
    Configuring 802.1X in Mac OS X Lion and Later

  • I need to upgrade my 10.5.1 os on my G4/1.25 (I'm having some audio-midi setup problems), but it's a machine that is not connected to the internet.  Do I have any options?  Thanks!

    Friends,
    I'm having some audio-midi setup problems on my G4/1.25/10.5.1 machine.  I'm thinking that a routine OS upgrade might help.  However, this machine is not connected to the internet.  Are there any alternate methods for upgrading system software?  Thanks in advance!

    OK, what you should do is download the updates on another machine and burn them to a disc.  Start at this link http://support.apple.com/downloads/#leopard for downloads and find, among other things, the 10.5.8 combo updater that works on PPC machines, plus security, QuickTime and other updates.  Going from 10.5.1 to 10.5.8, there will probably be a bunch of things that you should install.  Being off the internet with the machine, you can't have Software Update sort it out, so something might get missed, unfortunately.
    My suggestion is this: if it looks like you might need a download, get it onto that disc.

  • Multiple users connected to the same server

    Hi there,
    I was wondering if this scenario would be possible to be implemented on a Snow Leopard Server installed on Mac Mini 2.66:
    - one iphone developer that needs to be remotely connected to the server to develop apps
    - one project manager that will handle the project files and documentation. He will login to the server and upload/download files
    - one app GUI designer that will login from time to time, to make the design in photoshop.
    Can these 3 users be logged in the same time on the same server without any lag? Or this version of server will only support one user at a time?
    Thank you!

    Yes, you can do ssh and terminal connections, but I'm guessing that's not what you want here; I'm guessing you're headed over from X Windows or (more likely) Windows Terminal Services.
    Google for Aqua Connect and related for the path that you're headed toward.
    In general, Apple Mac OS X and Mac OS X Server runs one seat and one keyboard and one display per station, whether it's an Xserve server or a MacBook or whatever.

  • Time Machine works on Ethernet connection but not wireless

    Hi,
    This weekend I setup time machine to work with a NAS drive connected to my wireless router. If I connect my macbook to the router directly via an ethernet cable, and start a backup, it works fine. If I however try to start a backup when only on wireless it always fails. Here's what messages I'm getting:
    Starting standard backup
    Attempting to mount network destination using URL: afp://;AUTH=No%20User%20Authent@Backup%20to%20Iomega-0cd217.afpovertcp.tcp.local/backups
    NetAuthConnectToServerSync failed with error: 64 for url: afp://;AUTH=No%20User%20Authent@Backup%20to%20Iomega-0cd217.afpovertcp.tcp.local/backups
    Attempting to mount network destination using URL: afp://;AUTH=No%20User%[email protected]/backups
    Mounted network destination using URL: afp://;AUTH=No%20User%[email protected]/backups
    Warning: Destination /Volumes/backups does not support TM Lock Stealing
    Warning: Destination /Volumes/backups does not support Server Reply Cache
    QUICKCHECK ONLY; FILESYSTEM CLEAN
    Disk image /Volumes/backups/Garys-MacBook-Pro_xxxxxxxxxxxx.sparsebundle mounted at: /Volumes/MAC Backups
    Backing up to: /Volumes/MAC Backups/Backups.backupdb
    Stopping backupd to allow ejection of backup destination disk!
    Error: (5) getxattr for key:com.apple.backupd.SnapshotState path:/Volumes/MAC Backups/Backups.backupdb/Gary's MacBook Pro/2011-01-15-042811
    Error: (5) getxattr for key:com.apple.backupd.SnapshotContainer path:/Volumes/MAC Backups/Backups.backupdb/Gary's MacBook Pro/2011-01-15-042811
    Error: (5) getxattr for key:com.apple.backupd.SnapshotState path:/Volumes/MAC Backups/Backups.backupdb/Gary's MacBook Pro/2011-01-15-171318.inProgress
    Error: (5) getxattr for key:com.apple.backupd.SnapshotContainer path:/Volumes/MAC Backups/Backups.backupdb/Gary’s MacBook Pro/2011-01-15-171318.inProgress
    Error: (5) getxattr for key:com.apple.backupd.SnapshotState path:/Volumes/MAC Backups/Backups.backupdb/Gary’s MacBook Pro/2011-01-15-042811
    Error: (5) getxattr for key:com.apple.backupd.SnapshotContainer path:/Volumes/MAC Backups/Backups.backupdb/Gary’s MacBook Pro/2011-01-15-042811
    Error: (5) getxattr for key:com.apple.backupd.SnapshotState path:/Volumes/MAC Backups/Backups.backupdb/Gary’s MacBook Pro/2011-01-15-171318.inProgress
    Error: (5) getxattr for key:com.apple.backupd.SnapshotContainer path:/Volumes/MAC Backups/Backups.backupdb/Gary’s MacBook Pro/2011-01-15-171318.inProgress
    Backup canceled.
    [SnapshotUtilities mountPointForVolumeRef] FSGetVolumeInfo returned: -35
    Failed to eject volume (null) (FSVolumeRefNum: -179; status: -35; dissenting pid: -1)
    [SnapshotUtilities mountPointForVolumeRef] FSGetVolumeInfo returned: -35
    Failed to eject volume (null) (FSVolumeRefNum: -178; status: -35; dissenting pid: -1)
    I've x'ed out the mac address from the sparsebundle name. Any help would be much appreciated as I can't understand why it's working when connected but not when on wireless.
    Thanks!

    GT777 wrote:
    Hi,
    Hi, and welcome to the forums.
    This weekend I setup time machine to work with a NAS drive connected to my wireless router.
    Time Machine doesn't work well, if at all, with many NASs. See the pink box in #2 of [Time Machine - Frequently Asked Questions|http://web.me.com/pondini/Time_Machine/FAQ.html] (or use the link in *User Tips* at the top of this forum).
    There are several threads in the Snow Leopard > Time Machine forum with what appear to be similar problems with Iomega NASs.
    If I connect my macbook to the router directly via an ethernet cable, and start a backup, it works fine. If I however try to start a backup when only on wireless it always fails.
    An indication of a bad wireless connection or interference, but could also be the setup of the NAS or compatibility with the way the router works in wireless mode.
    Mounted network destination using URL: afp://;AUTH=No%20User%[email protected]/backups
    After an initial failure, it did connect.
    Warning: Destination /Volumes/backups does not support TM Lock Stealing
    Warning: Destination /Volumes/backups does not support Server Reply Cache
    You've posted in the Leopard forum, and didn't specify what version of OSX you're on. But those messages usually indicate that your NAS is not fully compatible with the Time Machine requirements on Snow Leopard.
    Error: (5) getxattr for key:com.apple.backupd.SnapshotState path:/Volumes/MAC Backups/Backups.backupdb/Gary's MacBook Pro/2011-01-15-042811
    Those are errors reading from the backups; specifically, getting extended attributes from the backups on your NAS (a "snapshot" is Time Machine's name for a backup folder).
    First, contact the maker of the NAS for updated software/firmware compatible with Snow Leopard.
    That might fix the problem. If not, all we can tell you is, it may be some problem with the setup of the NAS, and/or compatibility with the wireless function of your router. See the maker's instructions/Help/support.

  • Trying to download cc desktop app but it wont connect to the server.

    I've tried several times now to re-download the Creative Cloud desktop app, but i get to the loading dialog box and it freezes saying "trying to connect to the server". What is wrong? i have a secure internet connection.

    Ashlette21 for information on how to resolve the connection error please see Sign in, activation, or connection errors | CS5.5 and later.  You are welcome to update this discussion if you have any questions regarding the steps listed within the document.

  • I keep getting a download update and it runs but never connects to the server. What do I do to correct this problem?

    Firefox won't update. I keep getting a download request and it tries to connect to the server but it just keeps on running and never downloads any thing.

    If there are problems with updating then best is to download the full version and uninstall the currently installed version.
    Download a fresh Firefox copy and save the file to the desktop.
    * Firefox 6.0.x: http://www.mozilla.com/en-US/firefox/all.html
    * Uninstall your current Firefox version.
    * Do not remove personal data when you uninstall the current version.
    Remove the Firefox program folder before installing that newly downloaded copy of the Firefox installer.
    * It is important to delete the Firefox program folder to remove all the files and make sure that there are no problems with files that were leftover after uninstalling.
    Your bookmarks and other profile data are stored elsewhere in the Firefox Profile Folder and won't be affected by a reinstall, but make sure that you do not select to remove personal data if you uninstall Firefox.
    * http://kb.mozillazine.org/Profile_folder_-_Firefox
    * http://kb.mozillazine.org/Profile_backup

Maybe you are looking for

  • Duplicate Cell Contents n-times based on value in neighboring cell?

    I have a sheet/table that contains ~150 rows of 2 columns: A B COUNT CONTENT I am looking for a way to duplicate each CONTENT in a new sheet/table COUNT times, and do this for each row. For example A B 2 RED 1 BLUE 3 GREEN Would give me a sheet/table

  • SM58 Errors due to Work Item/Task

    Hello, we are getting a lot of sm58 error messages related to a workflow task TS00007989 (Error during outbound processing). All the errors carry the same message "Work item 000000549001: Task TS00007989 locked for  instantiation" What could be the r

  • Multiple language DVD - Help!!

    Hey everyone, I started a project in 2.0.  It is a basic menu screen with 19 buttons for different languages each linked to a different subtitle track, so 19 tracks in all.  This is a 16x9 project, and I noticed that Encore can only handle 16 subtitl

  • Gallery strange behaviour...

    In an effort to stop lots of my pictures and videos in a folder on my memory card appearing in the gallery I used Y Browser to mark the folder hidden... In the gallery it then said I still had the same number of pics/videos but all the ones that were

  • Illegal operation occures running a 'Write Digital Line' vi in Test Executive

    I'm switching a single line of a PCI DIO 96.