Windows 7 machines are capable of auto-enrolling from a Windows Server 2003 
Enterprise (i.e. AD integrated) CA. The server doesn't "push" out the certs - 
you can use a GPO to have the client auto-enrol the cert from the issuing CA.

Also, are you using a different WLAN management tool to the built-in Windows 
client? If using the native Windows WLAN manager then a user changing their 
Windows password shouldn't lock-out their account...

Cheers
Ken

From: [email protected] [mailto:[email protected]] On 
Behalf Of Scott Schneider
Sent: Friday, 12 September 2014 11:53 PM
To: [email protected]
Subject: [NTSysADM] AD 2003 certificates

We are still stuck on AD 2003. I am attempting to use certificate 
authentication for Windows 7 laptops, iPhones and iPads over our internal 
WAP's. Radius is setup to our DC's. I am trying to do away with pre-shared keys 
or authentication through domain username and password. Users end up locking 
themselves out each time they change their windows password and don't change 
their wireless credentials. I would like clients to connect automatically to 
the WAP's if their device has a valid cert issued. As far as I know (correct me 
if I am wrong) Windows 2003 does not natively support pushing certs to Windows 
7 clients.
Has anyone successfully used 2003 certs for authentication with Windows 7 
laptops? Any other suggestions how it might be accomplished? Care to share how 
you did it?

Cheers

Scott Schneider
Network and Systems Admin
___________________________________
inscape smart workspaces

T 905 952 4001
www.inscapesolutions.com<http://www.inscapesolutions.com/>


Reply via email to