Windows 7 machines are capable of auto-enrolling from a Windows Server 2003 Enterprise (i.e. AD integrated) CA. The server doesn't "push" out the certs - you can use a GPO to have the client auto-enrol the cert from the issuing CA.
Also, are you using a different WLAN management tool to the built-in Windows client? If using the native Windows WLAN manager then a user changing their Windows password shouldn't lock-out their account... Cheers Ken From: [email protected] [mailto:[email protected]] On Behalf Of Scott Schneider Sent: Friday, 12 September 2014 11:53 PM To: [email protected] Subject: [NTSysADM] AD 2003 certificates We are still stuck on AD 2003. I am attempting to use certificate authentication for Windows 7 laptops, iPhones and iPads over our internal WAP's. Radius is setup to our DC's. I am trying to do away with pre-shared keys or authentication through domain username and password. Users end up locking themselves out each time they change their windows password and don't change their wireless credentials. I would like clients to connect automatically to the WAP's if their device has a valid cert issued. As far as I know (correct me if I am wrong) Windows 2003 does not natively support pushing certs to Windows 7 clients. Has anyone successfully used 2003 certs for authentication with Windows 7 laptops? Any other suggestions how it might be accomplished? Care to share how you did it? Cheers Scott Schneider Network and Systems Admin ___________________________________ inscape smart workspaces T 905 952 4001 www.inscapesolutions.com<http://www.inscapesolutions.com/>

