D-Link DWL-8500AP Product Manual - Page 119

Obtaining a TLS-EAP Certificate for a Client

Page 119 highlights

5. Click Finish. A Wireless Client Settings and RADIUS Server Setup The access point is now displayed as a client of the Authentication Server. Obtaining a TLS-EAP Certificate for a Client If you want to use IEEE 802.1X mode with EAP-TLS certificates for authentication and authorization of clients, you must have an external RADIUS server and a Public Key Authority Infrastructure (PKI), including a Certificate Authority (CA), server configured on your network. It is beyond the scope of this document to describe these configuration of the RADIUS server, PKI, and CA server. Consult the documentation for those products. For information about configuring Microsoft Windows PKI software or installing a CA, see the Microsoft Web site: http://support.microsoft.com/. Wireless clients configured to use either "WPA/WPA2 Enterprise (RADIUS)" or "IEEE 802.1X" security modes with an external RADIUS server that supports TLS-EAP certificates must obtain a TLS certificate from the RADIUS server. This is an initial one-time step that must be completed on each client that uses either of these modes with certificates. This example uses the Microsoft Certificate Server. To obtain a certificate for a client, follow these steps. 1. Enter the following URL in a Web browser: https:///certsrv/ Obtaining a TLS-EAP Certificate for a Client 119

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

Obtaining a TLS-EAP Certificate for a Client
119
A
Wireless Client Settings and RADIUS Server Setup
5.
Click
Finish
.
The access point is now displayed as a client of the Authentication Server.
Obtaining a TLS-EAP Certificate for a Client
If you want to use IEEE 802.1X mode with EAP-TLS certificates for authentication and
authorization of clients, you must have an external RADIUS server and a
Public Key Authority
Infrastructure
(PKI), including a
Certificate Authority
(CA), server configured on your
network. It is beyond the scope of this document to describe these configuration of the
RADIUS server, PKI, and CA server. Consult the documentation for those products.
For information about configuring Microsoft Windows PKI software or installing a CA, see
the Microsoft Web site:
.
Wireless clients configured to use either “WPA/WPA2 Enterprise (RADIUS)” or “IEEE
802.1X” security modes with an external RADIUS server that supports TLS-EAP certificates
must obtain a TLS certificate from the RADIUS server.
This is an initial one-time step that must be completed on each client that uses either of these
modes with certificates. This example uses the Microsoft Certificate Server.
To obtain a certificate for a client, follow these steps.
1.
Enter the following URL in a Web browser:
https://<
IPAddressOfServer>
/certsrv/