802.1x client authentication fails when you connect to a Windows Server 2003-based computer that is running IAS (838502)
The information in this article applies to:
- Microsoft Windows XP Professional
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Server 2003, Enterprise Edition
SYMPTOMSWhen you configure a client computer to use IEEE 802.1x authentication, you may find that you cannot connect to a Microsoft Windows Server 2003-based computer that is running Internet Authentication Services (IAS). You may receive an error message in the application event log on the Windows Server 2003-based computer that is similar to the following: Event Type: Warning
Event Source: IAS
Event ID: 2
Authentication-Type = PEAP
Reason-Code = 262
Reason = The supplied message is incomplete. The signature was not verified.
CAUSEThe issue that is described in the "Symptoms" section may occur if both of the following conditions are true: - IAS is installed on the Windows Server 2003-based computer.
- The Trusted Root CA certificate is not installed on the client computer.
RESOLUTIONTo resolve this issue, follow the appropriate method: Method 1: Disable certificate validation on the client computerTo do this, follow these steps: - Click Start, and then click Control Panel.
- Double-click Network Connections.
- Right-click the connection that you use to connect to the Windows Server 2003-based computer, and then click Properties.
- On the Authentication tab, click Properties.
- Click to clear the Validate server certificate check box.
Method 2: Install the trusted root certification authority on the client computer- Start Microsoft Internet Explorer.
- In the Address box, type the following address:
http://ServerName/certsrv Note Replace ServerName with the name of the server where the certification authority (CA) is stored. - Click Download a CA certificate, certificate chain, or CRL.
- Under CA Certificate, click the CA that you want to install, and then click Download CA Certificate.
- On the File Download page, click Open.
- Click Install certificate.
- Click Next.
- Click Automatically select the certificate store based on the type of certificate, and then click Next.
- Click Finish.
Modification Type: | Major | Last Reviewed: | 8/24/2006 |
---|
Keywords: | kbSecurityServices kbnetwork kbwinservnetwork kbprb KB838502 kbAudITPRO |
---|
|