(PAC) box and the Validate Server Certificate box at the same time.

Chapter 3 Configuring EAP Types

Configuring EAP-FAST

Table 3-1

Connection Settings (continued)

 

 

Connection Settings

Description

 

 

Validate server certificate

Check this box to use an authenticated server certificate to establish

 

 

a tunnel. You can check both the Use Protected Access Credentials

 

 

(PAC) box and the Validate Server Certificate box at the same time.

 

 

If both are checked, you can select one or more Trusted Root CA

 

 

certificates from the list of trusted Certificate Authority certificates

 

 

that are installed on the host system.

 

 

The EAP-FAST module always tries to use the PAC first if both check

 

 

boxes are checked. The module uses the server certifcate if the PAC

 

 

is missing or rejected by the server.

 

 

If both check boxes are unchecked, EAP-FAST functions as PEAP

 

 

does without validating server certificate. We do not recommend

 

 

leaving both boxes unchecked because the module bypasses

 

 

fundamental trust validation.

 

 

Default: Off

 

 

Connect to only these servers

Check this box to enter an optional server name that must match the

 

 

server certificate that is presented by the server. You can enter

 

 

multiple server names; separate multiple server names with

 

 

semicolons. The EAP-FAST module only allows connections to

 

 

continue without prompting if the subject field (CN) in the server

 

 

certificate matches the server names that you enter in this field.

 

 

Default: Off

 

 

Note You can use an asterisk (*) as a wildcard character in server

 

 

names only if the asterisk appears before the first period (.) in

 

 

the name.domain.com format. For example, “*.cisco.com”

 

 

matches any server name that ends with “.cisco.com.” If you

 

 

put an asterisk anywhere else in the server name, it is not

 

 

treated as a wildcard character.

 

 

Trusted Root CA

Select one of more Trusted Root CA certificates from the list of

 

 

certificates that are installed on the system. Only trusted CA

 

 

certificates that are installed on the host system are displayed in the

 

 

drop-down list.

 

 

To view details about the selected Trusted Root CA certificate,

 

 

double-click the certificate name. Double-clicking the certificate

 

 

name opens the Windows certificate property screen, where

 

 

certificate details are available.

 

 

Default: None

 

 

Do not prompt user to authorize

Check this box if you do not want the user to be prompted to authorize

new servers or trusted

a connection when the server name does not match or the server

certificate authorities.

certificate is not signed by one of the Trusted Root CA certiticates

 

 

that was selected. If this box is checked, the authentication fails.

 

 

Default: Off

 

 

 

Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and PI21AG) Installation and Configuration Guide for Windows Vista

3-8

OL-16534-01

 

 

Page 62
Image 62
Cisco Systems PI21AG, CB21AG PAC box and the Validate Server Certificate box at the same time, Default Off, Default None