Go Back   Wireless and Wifi Forums > Other Networking > Security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-15-2008, 12:42 PM
Junior Member
 
Join Date: Jan 2008
Posts: 2
Default Problem trying to force password change through PEAP

Hi,
I recently setup a wireless network for a client, but left with one issue that I cannot seem to resolve.
Hardware is a Cisco 2100 WCS controller with several compatible Cisco AP's.
Hardware configured for PEAP / WPA / WPA2 / TKIP / AES combinations.
They authenticate through Windows IAS and authenticate against Active Directory (2003).
IAS is configured to authenticate only wireless clients, and only specifiy AD groups.
Clients are configured using PEAP / MSChapv2. Not configured to validate server certificates. All use Windows wireless Zero configuration utility.
The problem is that the client gives their users a standard password which they are expected to change at first login. In other words, the user's account in AD is set to force a password change the first time they log into the wireless network.
Now I know this works, because it works in my lab without issue....as long as you configure PEAP to allow the client to change their password.
But in production, it only works sometimes. The problem occurs accross different laptop brands....in other words, I can't pin it down to either an IBM or Dell, or any specific kind of client wireless hardware.
When it does't work, users are prompted 3 times for their change their password, but it doesn't work and then their authentication attempt start sover from the beginning.
Note that when this policy is not enbaled (force passwor change), then all notebooks authenticate without issue....it's only when we try to force a password change through the client's AD account.
I tried applying several microsoft patches (to help with 3rd party radius timing issues) to the clients, but so far no luck.
Any advice would be appreciated.
Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 02:36 PM
Junior Member
 
Join Date: Jan 2008
Posts: 2
Default Definitely a hardware issue

Just to update my own question, after much testing, it looks like certain wireless cards / drivers have incompatibility issues with the Cisco wireless hardware we are currently using. I was able to find a couple combination of wirless pc cards an laptops brands that can change their password over PEAP / wireless connection, so it doesn't look like a windows or radius congifuration issue.
Reply With Quote
  #3 (permalink)  
Old 01-30-2008, 08:36 AM
Junior Member
 
Join Date: Dec 2007
Posts: 20
Default

Hi Max,

Yes as you said it looks like the issue with the client drivers. Also when the user has been prompted with change in password for 3 times as you said, check for relevant logs from windows event viewer and see if we can intrepret the logs. Adding to your setup, i have been trying to setup EAP-TLS and TTLS for clients location. Though i dont use cisco, but my infrastructure is same as urs. Controller and thin APs deployed across the site. When i use TLS, i need to know whether we need to transfer the cert to the client and select Smartcard/cert for authentication or is there anyother steps which i'm missing? I have deployed PEAP. But need to know how to deploy certs in TLS and TTLS. One thing i know in theory is for TTLS, we need server and client side certs. What does this mean? How do we go about deploying? If you have any docs or links to configure, Please send it across. Will be more helpful.
Thanks.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Wow Apple and Google Force Verzion to Change Network Policy CozmicDebris alt.cellular.attws 3 11-29-2007 06:06 AM
shoes leather=33$ <www.netfashion2008.cn> cheapestsell uk.telecom.mobile 0 11-16-2007 08:42 AM
Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Lieberm Radium alt.internet.wireless 13 07-23-2007 09:58 PM
Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Liebermann! Jeff Lieberm Radium alt.cellular.verizon 10 07-23-2007 09:58 PM
Password Problem Drew alt.cellular.nokia 11 11-27-2006 08:11 PM


All times are GMT. The time now is 02:11 PM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC4

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43