PEAP-MS-CHAPv2 - mobile devices and certificates

I'm looking to secure our wireless infrastructure and CHAPv2 seems to be what we need but I have a couple of concerns.
Our external domain is company.net but our internal domain where the NPS server would sit is domain.company.local
We have a lot of mobile devices - some are on the domain, some are not. 
I'm happy to use an internal certificate or a 3rd party certificate, but given the different domain suffixes, is this going to be possible?  If I use a certificate with subject name domain clients won't trust it.  If I use subject name of company.net,
no clients will trust the NPS server.
How do I get all domain PCs and domain/non-domain mobile devices to trust and connect to the NPS server?

Hi,
When you deploy 802.1X authenticated wireless access that uses PEAP-MS-CHAP v2, RADIUS servers must have digital certificates in order to perform mutual authentication. To issue certificates to your NPS servers you have the option of deploying
a private CA on your network, or purchasing a server certificate from a third party certification authority.
During PEAP-MS-CHAP v2 authentication, the IAS or RADIUS server supplies a certificate to validate its identity to the client. Client computer and user authentication is accomplished with passwords, which eliminates some of the difficulty of deploying certificates
to wireless client computers.
Since user authentication is performed with password-based credentials, not certificates, the certificate which is issued to NPS use the internal domain suffix. But non-domain member computers must have the private CA certificate manually
installed in the Trusted Root Certification Authorities certificate store for them to trust certificates, such as NPS server certificates, that are issued by the private CA.
Besides, are all users in the internal domain? If users are in two domains, you have two options,
Create a two-way forest trust for both sides of the trust.
Install a new NPS server in external domain.
For detailed information, please refer to the link below,
Create a two-way, forest trust for both sides of the trust
http://technet.microsoft.com/en-us/library/cc778851(v=WS.10).aspx
Certificates and NPS
http://technet.microsoft.com/en-us/library/cc772401(v=WS.10).aspx
PEAP-MS-CHAP v2-based Authenticated Wireless Access Design
http://technet.microsoft.com/en-us/library/dd348500(v=WS.10).aspx
Hope this helps.
Steven Lee
TechNet Community Support

Similar Messages

  • HT1369 Ipod touch not being recognized by itunes (but is registering as an external drive by the computer itself) have updated and reinstalled itunes, stopped/started apple mobile device and removed and mobile programs associated with my non apple cellpho

    Ipod touch not being recognized by itunes (but is registering as an external drive by the computer itself) have updated and reinstalled itunes, stopped/started apple mobile device and removed any mobile programs associated with my non apple cellphone. This seems to have started happening after the last Itunes update I did as I was able to put music on my ipod touch a month or so ago. Is there some way to go back to an older version of itunes? I really have no idea what else to do since I followed every step on the trouble shooting page for windows 8.

    I had this problem too and my roommate solved it!
    Go to 'Settings'
    'Music'
    Scroll to the bottom and enter your password to log onto your home sharing
    Then connect to iTunes and sync!

  • HT1688 What is "Apple Mobile Device" and how do I get it on my iphone 5? My iphone is not syncing when plugged in. The message says I have not started the device.

    What is "Apple Mobile Device" and is it loaded/activated on the iphone 5?

    I suspect you mean that you are getting the iTunes error message that the Apple Mobile Device Service is not started, in which case you need to follow the steps show in item #4 at the bottom of this article to restart it: http://support.apple.com/kb/TS1538.

  • I go to start the "Apple Mobile Device" and it says the side-by-side configuration is incorrect. (Error 14001)  How do I fix this?

    I go to start the "Apple Mobile Device" and it says the side-by-side configuration is incorrect. (Error 14001)  How do I fix this?

    Delete them and then download them from the desired Apple ID. This may require repurchasing paid applications.
    (95675)

  • ITunes Match; a waste of time for mobile devices and the impatient

    I recently subscribed to itunes match, aside from being able to upgrade a portion of my lower bitrate files, I am extremely dissapointed (as are many others I've read about having the same issues.) 
    First, getting all of my music on the server was a nightmare.  I spent way more time then I'd like to admit tricking iTunes into accepting my data.  Quite a bit of my library is in fact available for purchase in the itunes store, but only portions of most of the albums actually matched - the remaining portions had to upload. Fine, I'm okay with that aside from not being able to upgrade albums in their entirety, now I have some tracks at 256, others in the same album at 128 or whatever - I decided to selectively chose alums/tracks that I really cared about or didn't feel like re importing from disc in a few cases.  Fine.. annoying, but not a total deal breaker.
    I was finally able to figure out how (without apples help btw.. they didn't know this procedure when I spent an hour or so on the chat, screen sharing with a "specialisdt")  to trick itunes into uploadeing all "waiting" tracks by doing the AAC conversion myself manually and then replacing the compressed data locally with apple lossless files (both m4a files) while retainging the compressed data on the cloud.  fine.. I enjoy trouble shooting and problem solving, I was actually psyched to figure it out and be able to retain my high quality files locally without having doubles or redundant data in an archive elsewhere not within the iTunes data base.  Fine. apple lossless is no wav, aiff, but I can compramise also in order to imbed meta data which wav is not able to do.
    What I want is access to my entire library and to be able to either stream songs over wifi or 4g and/or download locally for when I'm off network in the boonies, etc.  *side note: don't anyone tell me this isn't a streaming service and that it only downloads to the device because it in fact does... it's just intollerably slow more often than not.  Now I can deal with that, that is either my cellular provider throttling me, or it's Apple's servers.  I will assume a bit of both.  also, don't tell me that matched content downloads faster then uploaded content.. that's BS, I've run the tests on multiple devices and there is no consitacy to it.. it all depends on the traffic on iCloud servers, wireless towers and size of the file/leanght of track, etc.  Fine.
    I've run the speed test, I've rebooted divices.  I've reset/confirmed/adjusted network setting.. I've done most of what I could do on my end as a user.  I can't seemlessly stream data on my unlimmited data plan from at&t from apple.. fine.. I get it.. regarless of my slow streaming issues - it's a first world problem.. whatever, I can deal. 
    My biggest gripe is that when I download either matched songs or uploaded content, it's is painfully slow to do so.. it's a waste of time.. manging the library on mobile devices takes forward thought and plenty of patience.. I might as well do this at home tethered to my desktop - convert to 128 to save space and accept my choices and deal with what I have loacally for the time when I'm out and about.   Now whren I buy something from apple over the 4g network or even the edge network,... &*^% downloads lickity split.. *** apple .. fine, it's big business.. I get it.. I for one would have paid 100 bucks a year if this service worked as advertised.. maybe more.,.. it's awesome in  theory, but is not realy for the limelight even still 2 years after the release.. hopefully it'll get better soon...
    Now this works great in my home over laptop, apple tv, but over ipad and iphone.. not so much.. actually working fine right now as long as I don't change the track abruptly... figures after this long rant.... once I continue on my day I'm sure it'll go back to being a pain.
    I'm going to use it at home, maybe on the run very ocasionally.. I guess that's what Apple thought we'd want, but they have been so misleading with this, and so abscent with trouble shooting an technical support that I've given up.. if I wasn't so in love with thier UI's and hardware (for the most part) I'd walk in time since steve jobs is now gone.
    unless you want to wrestle with it for hours and hours, or just want to upgrade your low quality files and bounce.. don't waste your time people.. ^$^$ all that noise
    It's too bad Samsung assinated Steve Jobs.. he'd never let this service be released uptil it was ready.   in the future I may have to go to the dark side and get a galaxy tab and smart phone, a Dell.. window vista.. naaaa just kidding.  *** apple.. p,lease sort your ^$%&7 out.
    Done and done. 
    please fix this Apple, I want to love iTunes match, I really do.

    Firstly, this is a user-to-user forum: you're not talking to Apple here.
    Just saying it 'doesn't work' doesn't make it possible to offer any cogent suggestion - one would need a lot more detail on what you've tried and what the result have been - including your operating system details. However if the thing is actually faulty - this is rare, it works fine for most people, but it can happen - then plainly you need to contact the people you bought it from, or take it into an Apple Store if you can, and ask for a replacement or repair.

  • The newest version of iTunes is awful when it comes to Cloud syncing-file management. I'm constantly frustrated with what iTunes 'chooses to eliminate from my mobile device and settings aren't fine-grained enough to allow for real user control.

    I'm endlessly frustrated with iTunes Cloud syncing, something that was supposed to make lenjoying my music easier. I routinely find that, though itunes and podcasts have been split, iTunes arbitrairily removes music files or in progress podcast in favor of 'new' podcasts. The settings are just not fine-grained enough to allow true user control and so we are instead subjected to 'Apple knows best' protocols. I understand and appreciate the level of exacting control Apple excercises over their ecosystem, however, more and more often I see them tightening control over things that should be user control while dropping the ball on aesthetic desisions made in producing their own software (see the hideous pull down tab for iTunes to access Podcast, TV shows, Music, etc.
    I would like to see features like those in Mail and the Podcasting apps implemented in iTunes afor the management of content on mobile devices, for instance it would be great to swipe to delete files that you know longer want on your device, at both the album and song level. Another issues is the new pushiness of iRadio and iTunes Store, the app now seems to default to the iRadio page (versus the last page Albums, songs, etc. that the user was navigating, or in the instance of the iTunes Store push, if I doon't have all the tracks of an album i own on my mobile device 'complete my album' takes you to iTunes store rather than showing the 'cloud' download icon next to missing tracks. These are the tactics I expect from Google, not Apple (pushing commerce over quality user experience).
    Fix these things Apple, please.

  • Different Text Size for different mobile devices and Tabbed View Application

    Hi,
    I am developing an sample mobile application to target all mobile devices (IPhone/IPad/IPod and Android).
    I am facing an Issue that i am using default text size for the TextInput, TextArea and label but text size look so small for some devices, i discuss this with some(unkown) person(he is an IPhone developer).
    He told me that in Iphone development for different devices they use different text size.
    So how would I do the same at our Flex Mobile application ?
    Please provide me help regarding this
    There is one more problem in the application. I have tabbed view application, and i assign the firstview of the tab after 10 or more seconds of interval so that data will load in the application properly.
    But issue is that my first tab is not show anything at first go. When we switch the tab then it loads the screen and application work fine.
    Please provide me any help so that i can see the first Tab Screen.
    Thanks

    Hi there. For your font issue you need to set up a variable call it var fontSize or something. Then have an if statement that reads something like if (stage.stageWidth <= 320) fontSize=8 else if (stage.stageWidth > 320 || stage.stageWidth <= 640) fontSize = 12.
    Then instead of giving your font a size give it the size of fontSize variable and it will check for stage width or whatever you base it on and apply that size to your text field.
    I had done this for an app I did for Kellogg Garden Products but if you notice when you go from portrait to landscape mode the font size increases using this technique.
    http://itunes.apple.com/us/app/kellogg-garden-products-soil/id440522636?mt=8

  • Interactive form on mobile devices and other PDF viewers

    Hello! I made an interactive PDF, which i first made in InDesign. It's basically built up like this: There are fields with a picture and text which go to transparency 0% when i go over them with the mouse and then you can see the background. I dind't have problems in Acrobat Pro and the Reader on PC and MAC, but when i open the PDF on a mobile device, even Adobe Reader, i can't use these effects. When i tap just short on the screen it marks the field for like a second and when i leave my finger longer on the touchscreen it shows me some options like making a signature and so on.. Is there any way to get this interactive effect going on mobile devices? And could it be that the interactive form only works with Adobe software? because I tried it with a preinstalled version of a Windows 8 PDF Viewer and the only thing that worked were the links i set to some websites.

    hi Vidyadhar,
    The Adobe Reader was installed in handheld. It can open standalone (offline) pdf document. But it would appear error when display dynamic generated adobe form in browser.
    Thanks.
    Regards,
    Weng

  • VERY URGENT!!transferring a midlet to a mobile device and other questions

    PLEASE HELP!!
    hi
    i would like to know the following details regarding
    J2ME:
    1. What is the size of a KVM(Kilobyte Virtual Machine)?
    2. What would be approximately the memory size
    of a mobile phone?
    3. How do i transfer my midlet application developed
    with the help of a J2ME tool kit to a mobile device?
    4. Should the device to which i am transferring
    be MIDP compliant alone i.e as of now
    i can transfer my midlet application only
    to an MIDP compliant mobile device?Or rather
    what are the in-built features/softwares/specification
    a mobile device should have before i transfer
    a midlet to a mobile device??
    5.Suppose i have written midlets...and put them
    in .jad and .jar files(midlet suite has been created).
    Now suppose i have to download it to my
    mobile phone,how do i do it?
    And if other people have to download it to
    thier mobile device...i need to put it on the web-site
    right?How do actually put my midlet to a web-site?
    Are there any steps involved for all that?
    6.Will the mobile device have ENOUGH MEMORY
    for executing the midlet which i have created
    considering the memory constraints of a mobile
    device.Also the fact that the KVM also
    would take up a lot of space though it is measured
    in kilobytes

    1 and 2 i do not know right now.
    You can transfer MIDlets to J2ME compatible devices only ,atleast for now. To do this , you must use a serial cable and download it directly to your cell phone or pager.
    The CLDC has been designed to suit applications that run low on memory ( from 160 kb to 512 kb)
    good luck

  • I went into services to fix my Apple mobile device and "Start" didn't come what do i do?

    Itunes said "This iPod cannot be used because the Apple Mobile Device service is not started." So then I did what apple support said to and I went into Services and I clicked on "Apple Mobile Device" but the "Sart" or "Restart" didn't come up like it should. Basicaly how do I get it back?

    First see:
    How to restart the Apple Mobile Device Service (AMDS) on Windows
    The try the AMDS topic of
    iOS: Device not recognized in iTunes for Windows

  • Youtube videos says not set for mobile devices and this is on my laptop.

    Yesterday the YouTube video page displayed differently. I clicked on a video and get a message that says cannot play on a mobile device. This is what I don't understand because it is on my laptop. I was using it watching videos earlier in the day. The YouTube does display and work well in Chrome.

    Seems to have corrected itself.

  • Can you download adobe flash to mobile devices, and if so, which ones? Thanks!  l

    Can you download adobe flash to any kindles or ipads? I like my facebook game and I can't load it on my new kindle fire hdx. Very dissapointed. Can you download flash on ipads?? If so which ones? Thanks for the help

    iPads, which operate on Mac iOS, are specifically incompatible with Flash Player, per Apple design, going back to iOS 1 in 2006. That... will never change... according to Apple.
    Kindles and Samsung tablets operate on Android which WAS compatible with Flash Player prior to version 4.0. After that, Android dropped all support for Flash Player (June 2012).
    The reasoning for both of these decisions (as Apple stated in 2006) was that playing Flash content is extremely processor consumptive, and it kills batteries, as well as shortening battery life, in mobile devices. It just took Android a little longer to come to the decision to drop support.
    Windows phones, 7 and 8 are compatible, and 8 even has Flash Player embedded by Microsoft, like Windows 8 for desktops.
    You can find info about "Dolphin" for Android at: https://play.google.com/store/apps/details?id=mobi.mgeek.TunnyBrowser It seems to be the browser of choice to play Flash content on an Android device. Also, check the Android forums to see what their "gurus" recommend.
    For the iPad, check out SkyFire. It seems to be the preferred iOS browser for Flash content.

  • Apple Mobile devices and Itunes is taking up 100% of my CPU and I can not get to the Itunes music store on 10.5

    I have installed the 10.5 version of the Apple Itunes app.  Now when I bring it up it takes up one whole CPU and my other CPU is used up by Apple Mobile devices.   I am using Windows XP Service Pack 2.    I have tried uninstalling all Apple products and reinstalling them but with no luck.  Please if anyone has any advice I am all ears...

    Thanks, Andrew for your help.  Not sure if you will see this, but I did the above and it said the HD was okay.  Rebooted it and still won't go past login page.  Tried it again and this time typed in the line /sbin/fsck -fy and then it came up and said HD was okay, but said something about being modified.  I once more rebooted, but it still won't get past the login screen.  Besides taking long to reboot, as before, I am able to enter my password, but then it hangs up with the rainbow icon rotating continuously.  Does this mean that the disk is corrupt or partially so, and if so, can you advise how I should proceed?  TIA again.

  • How do deauthorise a mobile device, and move the license to new mobile device?

    For work reasons, I change my mobile device a couple of times a month and need to migrate my Overdrive media files which has Adobe Digital Edition DRM to a new mobile device. I have encountered a limit of 3 devices, and can now no longer install my content on any further devices. Is there a means of deauthorising  devices within Adobe Digital Edition DRM, so i can migrate to a new device?
    Cheers 

    Sorry Claudio, I was in the wrong forum. Thanks for bringing it to my attention.
    Jimmy

  • HT1923 I had to reinstall Itunes due to "runtime error" and the instructions said to run as administrator.  I did that but I'm getting a message about administrator rights to my mobile device and it won't load.  What do I do now?

    Having issues reinstalling ITunes.  I ran as administrator but getting message that I do not have administrator rights for mobile device.  Any suggestions.

    See this User Tip by turingtest2
    https://discussions.apple.com/docs/DOC-6562

Maybe you are looking for

  • Price Difference account when Creating Goods Return

    Hello experts, I got below case: 1) Create a GRPO 2) Created Landed Cost document 3) Create a Goods Return (realized the lot number entered on the GRPO) was incorrect. When I create the latter document, this impacts the Price Difference account for t

  • Cable for importing to new MacBook Pro

    Could you please tell me what kind of cable connection (DV interface cable?) I should purchase for importing movies from my Panasonic (PV-GS83) to my brand new MacBook Pro? The one I have for my iBook G4 no longer works because the MacBook Pro doesn'

  • How do I change the number of rings on messages?

    How do I change the number of rings on messages. At the moment it rings twice and I miss it. Could do with being quite a few rings more.

  • SAP PS Budget Profile & Availability Check

    Hi All We have a requirement to control  Purchase Order amount , so that it should not exceed the allocated Budget , currently the Error message is coming when we are doing FG delivery /PGI  & we are converting PR generated from PS into PO Please tel

  • I need to find and upload a hidden file for an app service issue

    I need to locate a hidden file, filename.plist which is on a networked drive, and upload it to the company;s wed=biste for the to support the app. Obviously 'filename' is just a word. there is a long and complex filename. Finder spins its wheels usel