Discussion:
Authenticate user with third party certificates
(too old to reply)
stocchet
2008-02-18 14:28:18 UTC
Permalink
Hi,
I use IAS to authenticate wireless clients with user certificates issued by
my CA.
Now I'm trying to authenticate users from another CA mapping them to a user
of my AD. I installed its root certificate in the Trusted Certificate
Authorities list and I mapped the trusted certificate to a user in my AD
leaving a check on "use issuer for alternate security identity" and
unchecking "use subject for alternate security identity". This should make
IAS skip the user name of the certificate and accept all the user fro the
trusted issuer. Actually the name is not stripped and the user is denied
access "the specified user account does not exist".

Is there something missing?

Thank you

Saverio
James McIllece [MS]
2008-02-22 20:09:03 UTC
Permalink
Post by stocchet
Hi,
I use IAS to authenticate wireless clients with user certificates
issued by my CA.
Now I'm trying to authenticate users from another CA mapping them to a
user of my AD. I installed its root certificate in the Trusted
Certificate Authorities list and I mapped the trusted certificate to a
user in my AD leaving a check on "use issuer for alternate security
identity" and unchecking "use subject for alternate security
identity". This should make IAS skip the user name of the certificate
and accept all the user fro the trusted issuer. Actually the name is
not stripped and the user is denied access "the specified user account
does not exist".
Is there something missing?
Thank you
Saverio
Hi Saverio --

Not sure what the problem is, but you might want to review the Help topic
"Mapping network authentication and authorization" at
http://technet2.microsoft.com/windowsserver/en/library/08dc81fc-fcb8-44a2-
b1f9-7e97af3442d51033.mspx

It seems that the scenario you're attempting is covered in the section
titled "Mapping with certificate-based authentication," subsection "Many-
to-one mapping."
--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
Loading...