Cisco AIR-CB21AG-W-K9 Configuration Guide - Page 62

Use Protected Access Credentials, Validate Server Certificate, Default

Page 62 highlights

Configuring EAP-FAST Chapter 3 Configuring EAP Types Table 3-1 Connection Settings (continued) Connection Settings Description Validate server certificate Check this box to use an authenticated server certificate to establish a tunnel. You can check both the Use Protected Access Credentials (PAC) box and the Validate Server Certificate box at the same time. If both are checked, you can select one or more Trusted Root CA certificates from the list of trusted Certificate Authority certificates that are installed on the host system. The EAP-FAST module always tries to use the PAC first if both check boxes are checked. The module uses the server certifcate if the PAC is missing or rejected by the server. If both check boxes are unchecked, EAP-FAST functions as PEAP does without validating server certificate. We do not recommend leaving both boxes unchecked because the module bypasses fundamental trust validation. Default: Off Connect to only these servers Check this box to enter an optional server name that must match the server certificate that is presented by the server. You can enter multiple server names; separate multiple server names with semicolons. The EAP-FAST module only allows connections to continue without prompting if the subject field (CN) in the server certificate matches the server names that you enter in this field. Default: Off Note You can use an asterisk (*) as a wildcard character in server names only if the asterisk appears before the first period (.) in the name.domain.com format. For example, "*.cisco.com" matches any server name that ends with ".cisco.com." If you put an asterisk anywhere else in the server name, it is not treated as a wildcard character. Trusted Root CA Select one of more Trusted Root CA certificates from the list of certificates that are installed on the system. Only trusted CA certificates that are installed on the host system are displayed in the drop-down list. To view details about the selected Trusted Root CA certificate, double-click the certificate name. Double-clicking the certificate name opens the Windows certificate property screen, where certificate details are available. Default: None Do not prompt user to authorize new servers or trusted certificate authorities. Check this box if you do not want the user to be prompted to authorize a connection when the server name does not match or the server certificate is not signed by one of the Trusted Root CA certiticates that was selected. If this box is checked, the authentication fails. Default: Off Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista 3-8 OL-16534-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

3-8
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista
OL-16534-01
Chapter 3
Configuring EAP Types
Configuring EAP-FAST
Validate server certificate
Check this box to use an authenticated server certificate to establish
a tunnel. You can check both the
Use Protected Access Credentials
(PAC)
box and the
Validate Server Certificate
box at the same time.
If both are checked, you can select one or more Trusted Root CA
certificates from the list of trusted Certificate Authority certificates
that are installed on the host system.
The EAP-FAST module always tries to use the PAC first if both check
boxes are checked. The module uses the server certifcate if the PAC
is missing or rejected by the server.
If both check boxes are unchecked, EAP-FAST functions as PEAP
does without validating server certificate. We do not recommend
leaving both boxes unchecked because the module bypasses
fundamental trust validation.
Default:
Off
Connect to only these servers
Check this box to enter an optional server name that must match the
server certificate that is presented by the server. You can enter
multiple server names; separate multiple server names with
semicolons. The EAP-FAST module only allows connections to
continue without prompting if the subject field (CN) in the server
certificate matches the server names that you enter in this field.
Default:
Off
Note
You can use an asterisk (*) as a wildcard character in server
names only if the asterisk appears before the first period (.) in
the name.domain.com format. For example, “*.cisco.com”
matches any server name that ends with “.cisco.com.” If you
put an asterisk anywhere else in the server name, it is not
treated as a wildcard character.
Trusted Root CA
Select one of more Trusted Root CA certificates from the list of
certificates that are installed on the system. Only trusted CA
certificates that are installed on the host system are displayed in the
drop-down list.
To view details about the selected Trusted Root CA certificate,
double-click the certificate name. Double-clicking the certificate
name opens the Windows certificate property screen, where
certificate details are available.
Default:
None
Do not prompt user to authorize
new servers or trusted
certificate authorities.
Check this box if you do not want the user to be prompted to authorize
a connection when the server name does not match or the server
certificate is not signed by one of the Trusted Root CA certiticates
that was selected. If this box is checked, the authentication fails.
Default:
Off
Table 3-1
Connection Settings (continued)
Connection Settings
Description