View Full Version : Question for any WPA experts here
frankeleyn
05-01-2006, 04:50 AM
I've installed the "wireless security update" on my TX and now want to connect to our 802.1x WPA network. When I try and connect I get a message from the TX saying it has "problems verifying the server certificate".
The instructions for setting up a Windows XP machine with this network say that you shoul "Deselect Validate server certificate" on one of the set-up screens.
I can't see where one does that on the TX - does anybody know? I'd be grateful for any help.
with the update there is also an applications for windows - profiler , where you can setup your connections one by one also with certificates - it create a .pdb file which you just put in your palm :)
frankeleyn
05-02-2006, 06:46 AM
met,
thanks yes - but the profiler will not let you set up a PEAP without a server certificate whereas windows networking allows connection to such a network without server verification.
In fact I have found the certificate and installed it thus getting round the problem.
MegaManXcalibur
05-03-2006, 12:10 AM
Actually the way PEAP and all other 802.1x security protocols work is that they require the client have a certificate that they server provides (by provides I mean you must get it from the server not that the server sends it out when you try to connect).
Without the proper certificate you can not connect to an 802.1x wireless network. Also aside from the client certificate you need another certificate from a certificate authority which is used to verify that they client certificate is from who it says it's from. The idea that Windows allows you to bypass that is really gut wrenching actually, and most devices and operating systems won't let you get around it.
So what you'll need it a client certificate and a certificate from the certificate authority and install them onto the T|X and then add your settings to your PDA.
frankeleyn
05-03-2006, 04:15 AM
MegaMan,
Thanks, and as I said above I found the certificate and installed it.
Nevertheless, I suspect you may be wrong: the instructions for users to connect an XP machine to this network are not to bother to install the certificate but to check a box that says don't verify the servers certificate. Presumably this can be an option. It just means the user can not be certain they are on the "right" network.
MegaManXcalibur
05-03-2006, 11:08 PM
MegaMan,
Thanks, and as I said above I found the certificate and installed it.
Nevertheless, I suspect you may be wrong: the instructions for users to connect an XP machine to this network are not to bother to install the certificate but to check a box that says don't verify the servers certificate. Presumably this can be an option. It just means the user can not be certain they are on the "right" network.
Right it can be done but it shouldn't be allowed for the fact that it goes against the WPA standard and is a security risk to what is suppose to be a security standard.
vBulletin v3.0.3, Copyright ©2000-2012, Jelsoft Enterprises Ltd.