Cisco AIR-CB21AG-W-K9 Configuration Guide - Page 81

Configuring PEAP-GTC Settings in the User Credentials Tab

Page 81 highlights

Chapter 3 Configuring EAP Types Configuring PEAP-GTC Table 3-5 PEAP-GTC Connection Settings (continued) PEAP-GTC Connection Settings Description Trusted Root Certificate Authority (CA) Select one of more Trusted Root CA certificates from the list of certificates that are installed on the system. Only trusted CA certificates that are installed on the host system are displayed in the drop-down list, so you must make sure that the desired trusted root CA certificate is installed. To view details about the selected Trusted Root CA certificate, double-click the certificate name. Double-clicking the certificate name opens the Windows certificate property screen, where certificate details are available. Default: None Do not prompt user to authorize new servers or trusted certificate authorities. Check this box if you do not want the user to be prompted to authorize a connection when the server name does not match or the server certificate is not signed by one of the Trusted Root CA certiticates that was selected. If this box is checked and the server certificate is not trusted, the authentication fails. Default: Off Enable fast reconnect Check this box to allow session resumption. The PEAP-GTC module supports fast reconnect (also called session resumption). When you enable fast reconnect, you can roam without re-entering your credentials. Fast reconnect can be used across different network access servers. Default: On Note If you switch profiles, log off, or reboot, fast reconnect is not attempted. You must be reauthenticated. Configuring PEAP-GTC Settings in the User Credentials Tab The PEAP-GTC module supports OTP and a username and password as user credentials for authentication. The user provides one of the following types of username and password: • One-time password (OTP)-The user must manually enter a OTP. New PIN mode and next token mode for OTP are supported. • Windows username and password-The Windows username and password are used as network access credentials. The user is always prompted to enter a password unless PEAP-GTC is configured to use single sign-on (SSO) or the password is cached. • Prompted user credentials-The user is prompted during authentication for credentials. These credentials are credentials that are separate from the Windows username and password, such as Lightweight Directory Access Protocol (LDAP) credentials. • Saved user credentials-These are user credentials that are entered as part of the PEAP-GTC configuration. The user is not prompted for credentials during authentication unless the saved credentials fail or have expired. New credentials that the user enters after successful authentication are saved automatically in the configuration. The user does not have to return to the configuration screen to change the old saved credentials. Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista OL-16534-01 3-27

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170

3-27
Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista
OL-16534-01
Chapter 3
Configuring EAP Types
Configuring PEAP-GTC
Configuring PEAP-GTC Settings in the User Credentials Tab
The PEAP-GTC module supports OTP and a username and password as user credentials for
authentication.
The user provides one of the following types of username and password:
One-time password (OTP)—The user must manually enter a OTP. New PIN mode and next token
mode for OTP are supported.
Windows username and password—The Windows username and password are used as network
access credentials. The user is always prompted to enter a password unless PEAP-GTC is configured
to use single sign-on (SSO) or the password is cached.
Prompted user credentials—The user is prompted during authentication for credentials. These
credentials are credentials that are separate from the Windows username and password, such as
Lightweight Directory Access Protocol (LDAP) credentials.
Saved user credentials—These are user credentials that are entered as part of the PEAP-GTC
configuration. The user is not prompted for credentials during authentication unless the saved
credentials fail or have expired. New credentials that the user enters after successful authentication
are saved automatically in the configuration. The user does not have to return to the configuration
screen to change the old saved credentials.
Trusted Root Certificate
Authority (CA)
Select one of more Trusted Root CA certificates from the list of
certificates that are installed on the system. Only trusted CA
certificates that are installed on the host system are displayed in the
drop-down list, so you must make sure that the desired trusted root
CA certificate is installed.
To view details about the selected Trusted Root CA certificate,
double-click the certificate name. Double-clicking the certificate
name opens the Windows certificate property screen, where
certificate details are available.
Default:
None
Do not prompt user to authorize
new servers or trusted
certificate authorities.
Check this box if you do not want the user to be prompted to authorize
a connection when the server name does not match or the server
certificate is not signed by one of the Trusted Root CA certiticates
that was selected. If this box is checked and the server certificate is
not trusted, the authentication fails.
Default:
Off
Enable fast reconnect
Check this box to allow session resumption.
The PEAP-GTC module supports fast reconnect (also called session
resumption). When you enable fast reconnect, you can roam without
re-entering your credentials. Fast reconnect can be used across
different network access servers.
Default:
On
Note
If you switch profiles, log off, or reboot, fast reconnect is not
attempted. You must be reauthenticated.
Table 3-5
PEAP-GTC Connection Settings (continued)
PEAP-GTC Connection Settings
Description