cancel
Showing results for 
Search instead for 
Did you mean: 

UAC deployment for 802.1x AD users

SOLVED
eng_mahmood48_
Contributor

UAC deployment for 802.1x AD users

i have the below queries about the UAC deployment for AD users:

1- what is the best solution for the L2 802.1x Active directory connected PCs, since they will not have access to the AD server before user login (No IP address), is the Gina or the Machine Auth the best for this scenario?

2- is there limitations for GINA in windows 7?

3- what is the required configuratio for machine auth in the IC itself?

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions
apaul_
Regular Contributor

Re: UAC deployment for 802.1x AD users

Typical machine authentication uses either a statically defined user account or the machine credentials that were created when the machine ID was set up in Active Directory.

In case of certificate machine authentication, users to be authenticated based on attributes contained in client-side certificates. You can use the certificate server alone or in conjunction with another server to authenticate users and map them to roles.

Thanks

View solution in original post

7 REPLIES 7
Stanislas P_
Contributor

Re: UAC deployment for 802.1x AD users

Hello,

If you do not need user authentication to assign different VLAN associated to groups, the best solution is Certificate Machine authentication. the deployement of machine certificates is easy with GPO.

there is no difference between machine and user authentication in IC. but AD does not support LDAP machine authentication.

Regards,

Stanislas

eng_mahmood48_
Contributor

Re: UAC deployment for 802.1x AD users

Hello

i will use the assignment of remediation VLAN from the IC to the users whom didnt pass the policy check.

if the Certificate Machine authentication is the best, then how it works.?

- what about Gina, do you recommend it?

Thanks

apaul_
Regular Contributor

Re: UAC deployment for 802.1x AD users

Hi,

On Windows 7 systems, the capabilities for GINA are provided by Credential Providers.

Feel free to refer the release notes, this should be a good resource for you to understand the known issues and limitations.

http://www.juniper.net/techpubs/en_US/oac5.3/information-products/pathway-pages/oac-series/oac-relea...

Thanks

eng_mahmood48_
Contributor

Re: UAC deployment for 802.1x AD users

is there a difference between the machine authentication and certificate machine authentication?

Thanks

apaul_
Regular Contributor

Re: UAC deployment for 802.1x AD users

Typical machine authentication uses either a statically defined user account or the machine credentials that were created when the machine ID was set up in Active Directory.

In case of certificate machine authentication, users to be authenticated based on attributes contained in client-side certificates. You can use the certificate server alone or in conjunction with another server to authenticate users and map them to roles.

Thanks

yuvarajR_
Occasional Contributor

Re: UAC deployment for 802.1x AD users

Hi,

can i get a step by step procedure for configruing certificate based authentications using local & also conjunction with another server? pls its very urgent.....


@apaul wrote:

Typical machine authentication uses either a statically defined user account or the machine credentials that were created when the machine ID was set up in Active Directory.

In case of certificate machine authentication, users to be authenticated based on attributes contained in client-side certificates. You can use the certificate server alone or in conjunction with another server to authenticate users and map them to roles.

Thanks


apaul_
Regular Contributor

Re: UAC deployment for 802.1x AD users

Hi,

I am not sure whether sure a document like the one that you are looking for is available or not.

However you could open a JTAC case, for technical assistance on your requirement.

Thanks