How can I configure radius to allow a non-windows device to authenticate with a certificate?

I currently have a 2008r2 server with NPS acting as a radius server for our wireless network.  The existing rules are setup to allow access based on windows group membership.  I need to get a wireless jetdirect connected to the wifi network.  
If I create a certificate for this device with key usage settings for client auth / server auth, can it authenticate to radius with that cert?  
How would I set up a NPS policy to allow this device, since it's not a domain member and not a member of the windows groups?

Hi there -
I asked the NPS team about this, and following is their response:
Yes, it’s possible but it’s a very manual process.  I will give you the easy steps then the hard ones.
Easy(relative):
 Using a domain joined machine, request a certificate from a template that allows the private key to be exported.
Export the cert with the private key
Import on all workstations/devices that require it.
Pros:
Relatively easy to create the cert and manage the account
Cons:
Single certificate used on multiple machines
Certificate does not accurately reflect the name of the device
Hard:
Create an account in AD
Issue a certificate from a template that allows the private key to be exported
Using name mappings, attach the certificate to the account
Create an SPN that matches the SAN on the certificate..i.e. if the SAN is computer.domain.com, you need to create a SPN on the account host/computer.domain.com
Install certificate on to target workstation/device
Pros:
Relatively, more secure than previous steps as you create a single account/certificate pair per device
Cons:
Not very manageable
Thanks -
James McIllece

Similar Messages

  • TS3672 how can i send readable emoji to other non-ios devices?

    how can i send readable emoji to other non-ios devices?
    whenever i try to send a text message with emoji to other non ios devices it appears question mark (?) on that device,

    Hello, Claire,
    This question would appear to have nothing to do with Apple Remote Desktop, Apple's software for managing networked Macs, so this probably isn't the best place to ask this question. I'd suggest asking in the forum for your version of Mac OS X.
    Please note that unless you own the complete rights to the music you used in the slide show - that is, you composed and performed it yourself, you didn't just buy the track on CD or from a download store - or you purchased the music from one of the "royalty free" services, then it would be a copyright violation and hence illegal to send that slideshow to others unless you remove the music track.
    Regards.

  • How can i configure itunes 11.1.4 in windows 8.1

    itunes 11.1.4 do not open  in windows 8.1 could you help explaining how can i  configure ?

    Hey fhiggins43,
    Thanks for the question. The following article may assist you in achieving your end goal:
    iTunes 11 for Windows: Require a prompt before automatic syncing
    http://support.apple.com/kb/PH12320
    Require a prompt before syncing all iPod, iPhone, and iPad devices
    1. In iTunes, choose Edit > Preferences.
    2. Click Devices.
    3. Select “Prevent iPods, iPhones, and iPads from syncing automatically.”
    To sync your iPod, iPhone, or iPad when a prompt is required, connect your iPod, iPhone, or iPad to your computer, choose your device from the Devices pop-up menu near the top of the iTunes window, and click Sync.
    Thanks,
    Matt M.

  • How can I configure one of the gateway NI9792 Ethernet port to communicate with a cRIO PAC ?

    Hi NI Engineers,
    I intend to use my gateway NI9792 the following way:
    1. One Ethernet port for network connection. That's how I'll develop it, download software and monitor my application through my PC at my desk.
    2. Can the other port be used to communicate with a cRIO device? If so, how can I do it?
    It seems to be a stupid question, but I truly could not work this out!
    Thanks in advance,
    Luiz
    "Together we stand, divided we fall..."
    Certified LabVIEW Associate Developer
    Solved!
    Go to Solution.

    Good afternoon, Luiz
    Follow the first link to guide which module can be used and other links to the best part of bore configuration CRIO. Any questions please contact us.
    How Do I Configure My Time Server on the NI WSN-9791 or NI 9792 Gateway?
    http://digital.ni.com/public.nsf/allkb/44FA322FAFF8D58D862575BD00591A54?OpenDocument
    NI WSN Product and Configuration Guide
    http://zone.ni.com/devzone/cda/tut/p/id/8710
    Configuring the Dual Ethernet Ports on Real-Time Controllers
    http://digital.ni.com/public.nsf/allkb/67F94BB93BCE32CF86257367006B3659?OpenDocument
    video setup and installation CRIO
    http://www.ni.com/swf/demos/us/crio/outofbox/
    Automatic Network Configuration for cRIO-9073 and cRIO-9074 CompactRIO Controllers
    http://digital.ni.com/public.nsf/allkb/37C790309A210A748625757000570938?OpenDocument
    Sincerely,
    Mauro Vera.

  • How can I use iTunes purchased music on non PC devices?

    I have an audio component that is a music server that is connected to my home audio system. The hard drive based music server has a front disc tray that you can use to rip CDs to its hard drive, but you can also copy music to it from a PC, as the server is connected to my home network.
    How can I get music that I purchase in iTunes onto this server? The server only accepts MP3s, and is not compatable with ACC. And its a music server, not a true PC, so dont see anyway how I could "authorize" it.
    Is there any way to get the ACC into MP3 format? Or if I burn the purchased music to CD, and then rip the CD back to a PC or the server itself, does it come back out as ACC again or MP3?
    If anybody can be of any help, it would be much appreciated. Thanks
      Windows XP  

    Burn the tracks out to an audio CD (make sure it's set to burn an audio CD, not a data CD, in the iTunes preferences). That CD can then be reimported as MP3.

  • How can I configure Lion server or mail.app to show IMAP subfolders with mailboxes?

    I'm sure we've all seen the weird IMAP glitch where mail subfolders appear down lower on the mail.app pane instead of nested neatly under the mailbox itself.  Usually you can get around this by changing the Inbox IMAP prefix to "" or "INBOX" or "/" or some such path that the server recognizes as the root path to your IMAP folder.  Unfortunately, this sometimes means you are unable to work with those folders or introduce other problems.
    Since I am running Lion (Client) and Lion Server as my mail host, I would think that there is an appropriate answer to this either on the mail.app client settings, or perhaps with a Lion Server configuration through DOVECOT.  I don't mind if the solution is a command-line one, but I need to be able to easily set up my mailboxes so that mail subfolders appear properly under each mailbox, instead of being hidden away lower on the page where it is very inconvenient to find, especially when you are using multiple email accounts.
    Client Machine Lion 10.7.3
    Server Machine Lion Server 10.7.3
    Please Help!!!!

    I've tried editing /etc/dovecot/conf.d/10-mail.conf on Lion Server to add the following:
    namespace private {
      type = private
      separator = /
      prefix = INBOX/
      inbox = yes
    This puts me in a catch-22:
    If I leave the "IMAP Path Prefix" setting in the account Advanced tab empty, I can see the subfolders and move messages in and out of them, but can't add or edit the folders or heirarchy.
    If I set the "IMAP Path Prefix" to "INBOX" I can add and edit subfolders, but they don't appear nested under my inbox.
    Please help!

  • How can I configure ReFS to NOT fail read operations when a checksum error is detected (on non-Storage-Spaces volumes where data integrity streams are enabled)?

    According to William Stanek, in his Windows Server 2012 R2 Inside Out: Configuration, Storage & Essentials book, this is apparently possible: (pg. 615 - here it is on Google Books: https://books.google.ca/books?id=0IyfBAAAQBAJ&pg=PT819&lpg=PT819&dq=read+operation )
        Integrity can be enabled when the system is not running on Storage Spaces. When
        integrity is enabled and ReFS detects a checksum mismatch, ReFS logs an event and
        fails the read operation by default. If you don’t want the read operation to fail, you
        can configure ReFS to continue with the read operation. A related event will be logged
        regardless.
    So then how do I configure it to do that???
    (And just to make it super-clear, I'm NOT using Storage Spaces, so there is no redundancy via mirroring/parity, and I'm not expecting any file repair - just detection of corruption. It's just a basic volume formatted with ReFS and
    with integrity streams enabled, via format E: /fs:ReFS /i:enabled
    For those who want more details, here's the situation: 
    I try to perform a read operation on a file with corrupted data (purposely done for testing using a low-level disk editor), I get a the following error message:
    And an event ID 133 from ReFSv1 gets logged in the System log:
    Clicking "Try Again" just brings up the same message, and clicking "Skip" skips the operation entirely.
    This is indeed the correct default behaviour.
    What I want instead is for the read operation to be allowed to complete, with corrupt data and all, and ONLY for the event to be logged. And according to William Stanek, this is supposed to be configurable somewhere - and after hours of searching, I haven't
    been able to find anything.

    Hi Tommy,
    >>How can I configure ReFS to NOT fail read operations when a checksum error is detected
    We can use PowerShell command Set-FileIntegrity to configure this. The specific parameter for controlling this behavior is
    -Enforce <Boolean>which indicates whether to enable blocking access to a file if integrity streams do not match the data.  
    Regarding this point, the following article can be referred to as reference.
    Set-FileIntegrity
    https://technet.microsoft.com/en-us/library/jj218351.aspx
    Best regards,
    Frank Shen
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • HT4623 please help!! how can i configure my iphone 3gs because i've been updated a new version i did it but it's hard to activate it again.

    please help!! how can i configure my iphone 3gs because i've been updated a new version, i did it but it's hard to activate it again. this message i always recieved in my iphone
    "We're sorry, we are unable to continue with your activation at this time."

    You phone was hacked. You can not get help with it here. Hacking / Jailbreaking voids any warraty and forfeits your right to support. Discussing jailbroken / hacked devices is forbidden by the terms of service here.

  • How can I configure iCloud so it doesn't restore deleted or moved emails on my Mac?

    I moved to iCloud, and so far it looks like everything is where it's supposed to be. My question is about syncing. When I delete an email on my Mac, iCloud restores it. How can I configure iCloud so that changes I make on my Mac and my iPhone stay changed?

    On the Mac in System Preferences > iCloud
    Make sure Mail & Notes is selected.
    ON the iPhone tap Settings > iCloud
    Make sure Mail is switched on.
    And try restarting your Mac and iPhone.

  • How can I configure my new Mac Pro to output the timeline via HDMI

    How can I configure my new Mac Pro to output the timeline in FCP 7 (yes, I have X, but I'm using 7 right now). I have two monitors running from TB2, but want to have the third for a client monitor.
    If I use all three via TB2, it's literally three monitors, and I want to edit on my CineDisplay. I only want the client to see the timeline video on the third monitor. When I hook up HDMI I get no signal, in fact, I can't have the HDMI cable hooked up for TB2 to work with the third.
    Thanks,
    GEvans
    DarthPro
    3.7 QCIntelXeonE5
    12 GB
    AMD FirePro dual D300 2048MB
    OSX 10.9.2

    If you use all ThunderBolt displays, or stick with DisplayPort and Mini DisplayPort (free conversion between the two with only a cheap cable) you can have up to six displays.
    If you attach "legacy" displays with "any-old adapter", you can have up to two, and the built-in HDMI counts as one if you use it.
    Any more requires ACTIVE Adapters.
    The US$100 Apple ACTIVE Mini DisplayPort to Dual-Link DVI adapter works in every case, even displays over 1920 wide.
    StarTech and Accell make US$35 ACTIVE adpters that work for displays up to 1920 wide.

  • HT4356 How can I configure the printer to print only grey tones from my iPad 2? Printer=Hp6520

    How can I configure printer with iPad to print only grey tones? This works fine from my laptop - not air printing from that one though.  I can't find anywhere on the iPad how to do printer settings and this also seems not to be available as an option when doing a printout.  In fact, no options seem to be available.  Thanks in advance for reacting!
    Hermi

    There is currently no option for this. You can give Apple feedback here:
    http://www.apple.com/feedback/ipad.html

  • How can I configure a VM to boot from USB key in Virtual PC of Windows 7?

    Hi all,
    I want to boot up with a USB key to install a new VM on Windows 7. I heared that Microsoft Virtual PC begins to support USB device on Windows 7. How can i configure it? I don't find any virtual USB device in VM settings on my Windows 7 box.
    Thanks for any help.
    Scorprio
    TechNet Software Assurance Managed Newsgroup MCTS: Windows Vista | Exchange Server 2007 MCITP: Enterprise Support Technician | Server & Enterprise Admin

    Hi all,
    I want to boot up with a USB key to install a new VM on Windows 7. I heared that Microsoft Virtual PC begins to support USB device on Windows 7. How can i configure it? I don't find any virtual USB device in VM settings on my Windows 7 box.
    Thanks for any help.
    Scorprio
    TechNet Software Assurance Managed Newsgroup MCTS: Windows Vista | Exchange Server 2007 MCITP: Enterprise Support Technician | Server & Enterprise Admin
    Virtual PC does not support USB.  Windows 7 XP Mode Virtual Machine supports the use of USB devices.  Virtual PC and Windows 7 XP Mode VM are not the same thing!

  • How can i configure advance payment to vendors through cash jounal

    how can i configure advance payment to vendors through cash jounal pls its urgent for me kindly help me out

    HI,
    I think u need not configure anyting new for this, you can use the existing Business Tran. Type K and rename it as Vendor Advance for separate identity. You can do the normal FBCJ posting.
    But doing this you will not have separate identity for the Advances paid.
    Thanks
    VK

  • How can i configure STMS with out physical systems

    Dear Experts ,
    please solve my doubts
    here i installed one system in AIX and named it as DEV system in that system i need to perform post-installaion Activities
    and i started some activities also
    presently my doubt is in STMS configuration
    here i have only one system (DOMINE CONTROLLER) and we need to other systems while configuration but we dont have other systems like quality and production how can i configure that systems in my landscape
    this is my first implementation Experience please suggest me with some valuable suggestions
    my doubts:
    while creating systems we need to take for virtual systems or Extended systems
    which transport routes can i prefer for Dev to Qly systemand also Qly to Prd
    please reply me
    Regards

    Hi,
    If you have decided the SID's of the QUA and PRD systems then you can configure TMS with the virtual systems. Here are the steps to do so.
    Login to the domain controller
    Execute tcode STMS
    Goto the menu overvie --> systems (Shift+F6)
    SAP SYStems --> Create --> Virtual system
    Enter the SID and description and then save ur entries.
    Now the new virtual system will be created. Do the above for the others systems in the landscape.
    Again execute STMS and then click SHIFT+F7. You will goto the transport route window. Now you can configure TMS for the systems in the list as usual.
    Hope this helps.
    Regards,
    Varadharajan M

  • How can I configure NI PCI 6221 and DAQ SCB-68 for pressure sensors?

    Hello
    everybody,
    I am using the measuring board (NI PCI 6221) and DAQ
    SCB-68 for the data acquisition.
    With the DAQ-Assistant I created AI for the voltage of
    pressure sensors. In a big indicator panel from this DAQ-Assistant I see the
    voltage for both sensors in the correct size. But if I set sensors in the
    blockdiagramm to control the signals for sensor one I get a wrong voltage size
    and for sensor 2 nothing.
    How can I configure this data acquisition equipment to
    get the correct signals?
    Thanks a lot for your help.

    I do not know the type of sensor you are using. But pressure transducers may have a very low output voltage(in the mVolt range). They also need an excitation voltage. Here is an introduction. http://focus.ti.com.cn/cn/lit/an/sloa034/sloa034.pdfThen working with pressure sensors I always use 3 stages in the circuit.
    1 Instrumentation Amplifier as a preamp
    2 filterstage
    3 Final amp and output buffer
    (you may combine stage 2 and 3)
    Besides which, my opinion is that Express VIs Carthage must be destroyed deleted
    (Sorry no Labview "brag list" so far)

Maybe you are looking for

  • Problems with parameter button in Crystal Report Server  2008

    Dear all, I have problems with parameter button in Crystal Report Server 2008. when I created some parameters and groups in Crystal Report 2008, they showed both parameters in 'Parameter button' and group in 'Group button'  on the left, so I can choo

  • Drill down problem in EC-CS when moved 4.7c  to ECC 5.0

    Hi We are still using EC-CS and upgraded to ECC 5.0. We  have customised report for consolidated BS and income.While running the report thru GR55, we come across a screen ( during drill down ) which is like CX34, we can see that the dimension and ver

  • VM not started if invoke is used in a C++ Daemon

    Hi, I'm trying to load the VM (JDK 1.4) in a C++ program which is using fork() to create a new process. The JNI_CreateJavaVM Call is working as long as it is used in the main process, if I do it in the forked background proc it is failing without any

  • Send With Map of Attachments & Map Variable

    I'm trying to send multiple attachments using "Send With Map of Attachments" Service.  I've setup a map variable (attachments_map) of sub-type string to hold the path and file name for each file (represented as <full_path>/<file_name>.pdf).<br /><br

  • Lost contact after shut down and start up

    What can be done to get it back ?