Cisco AIR-CB21AG-W-K9 Configuration Guide - Page 63

Overview of the User Credentials Tab, Client Certificates, Usernames and Passwords

Page 63 highlights

Chapter 3 Configuring EAP Types Configuring EAP-FAST Overview of the User Credentials Tab The EAP-FAST module supports the use of both a client certificate and a username and password as user credentials for authentication and provisioning. Client Certificates If a client certificate is used, the EAP-FAST module automatically obtains the client certificate from the Windows certificate store of the current user. The EAP-FAST module finds the user certificate that matches the username of the user who is logged on. The certificate cannot be expired. If multiple user certificates are available, the EAP-FAST module prompts the user to select one, and that selection is saved to the profile. By default, the user certificate is sent securely through TLS renegotiation or through the EAP-TLS inner method in the protected TLS tunnel. If the EAP-FAST server does not start TLS renegotiation to request the client certificate after the tunnel is established, then the EAP-FAST module sends the certificate through the EAP-TLS inner method. The EAP-FAST module administrator can configure the EAP-FAST module XML schema to send the user certificate without using these security measures. Usernames and Passwords If a username and password are used, the user provide one of the following types of username and password: • Windows username and password-The Windows username and password are used as network access credentials. The user is not prompted to enter the username and password unless the password is invalid or must be changed. • Prompted user credentials-The user is prompted during authentication for credentials. These credentials are credentials that are separate from the Windows username and password, such as Lightweight Directory Access Protocol (LDAP) credentials. • Saved user credentials-These are user credentials that are entered as part of the EAP-FAST configuration. The user is not prompted for credentials during authentication unless the saved credentials fail or have expired. New credentials that the user enters after successful authentication are saved automatically in the configuration. The user does not have to return to the configuration screen to change the old saved credentials. • One-time password (OTP)-The user must manually enter a OTP. New PIN mode and next token mode for OTP are supported. Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista OL-16534-01 3-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

3-9
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista
OL-16534-01
Chapter 3
Configuring EAP Types
Configuring EAP-FAST
Overview of the User Credentials Tab
The EAP-FAST module supports the use of both a client certificate and a username and password as user
credentials for authentication and provisioning.
Client Certificates
If a client certificate is used, the EAP-FAST module automatically obtains the client certificate from the
Windows certificate store of the current user. The EAP-FAST module finds the user certificate that
matches the username of the user who is logged on. The certificate cannot be expired.
If multiple user certificates are available, the EAP-FAST module prompts the user to select one, and that
selection is saved to the profile. By default, the user certificate is sent securely through TLS
renegotiation or through the EAP-TLS inner method in the protected TLS tunnel. If the EAP-FAST
server does not start TLS renegotiation to request the client certificate after the tunnel is established, then
the EAP-FAST module sends the certificate through the EAP-TLS inner method.
The EAP-FAST module administrator can configure the EAP-FAST module XML schema to send the
user certificate without using these security measures.
Usernames and Passwords
If a username and password are used, the user provide one of the following types of username and
password:
Windows username and password—The Windows username and password are used as network
access credentials. The user is not prompted to enter the username and password unless the password
is invalid or must be changed.
Prompted user credentials—The user is prompted during authentication for credentials. These
credentials are credentials that are separate from the Windows username and password, such as
Lightweight Directory Access Protocol (LDAP) credentials.
Saved user credentials—These are user credentials that are entered as part of the EAP-FAST
configuration. The user is not prompted for credentials during authentication unless the saved
credentials fail or have expired. New credentials that the user enters after successful authentication
are saved automatically in the configuration. The user does not have to return to the configuration
screen to change the old saved credentials.
One-time password (OTP)—The user must manually enter a OTP. New PIN mode and next token
mode for OTP are supported.