Wireless username/password being cached?

jlazzaro

Golden Member
May 6, 2004
1,743
0
0
We have wireless setup here (actually, im testing it)...WPA with AES encryption, PEAP with MSCHAP v2 going through a radius server. My boss didnt want for a client to authenticate using there current credentials, he wanted them to type in their username/password/domain everytime they want to authenticate through the wireless.

I have "Authenticate as computer when computer info is avaliable" under Wireless Authentication and "Automatically use my Windows logon name and password" in MSCHAPv2 properties both UNCHECKED. When I go to authenticate at first, it asks for my username/password/domain fine and I authenticate and connect to the AP.

If I disconnect and reconnect, it doesnt ask me for my credentials and uses the ones I typed in previously. If i log off and log back on and attempt to connect again, it still uses the credentials I did the first time I authenticated. Is there a way to force this issue and make it not use the username/password I did he first time? This is an obvious security issue as someone can logon to an domain account that isnt theirs without entering any credentials. TIA!
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
Originally posted by: jlazzaro
This is an obvious security issue as someone can logon to an domain account that isnt theirs without entering any credentials. TIA!

No it's not an obvious issue. You have to logon as a domain account...which requires knowledge of an ID and password.

If you change the domain password, then disconnect, then log on again and try to connect, it should prompt you at that point, since the connection should have failed.

What I think would work best would be to turn ON the checkbox for "Automatically use my Windows Logon...". That way the second user won't use the WLAN credentials that the first user put in. (assuming you're sharing clients). However, the user won't be prompted when accessing the WLAN, just when they log on to Windows.

How are they going to log on to the machine for the first time? Will it be wired at that point?

Why is there a requirement to re-authenticate the user when they connect to the WLAN? Do you not trust Windows Auth? (wait...you're using that for the WLAN back end). Is the WLAN providing access to a more restrictive set of resources?

Just trying to understand the concerns that management has, so we can help you allay those fears.

IME, people want the network access thing to be completely seamless, and almost invisible to the majority of end-users.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |