LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-24-2005, 03:18 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
Radius And W2k


I WAS WONDERING IF I COULD USE MY SUSE LINUX BOX USING RADIUS TO AUTHENTICATE MY WINDOWS 2000 WIRELESS CLIENTS OVER MY NETWORK SO THAT I COULD HAVE SOMEWHAT OF SECURITY ON THE WIRELESS SIDE. HERE IS CURRENT SETUP:


dsl modem
'''
''''
Suse linux Router/Firewall
'''
'''
Dlink 624 wireless router/switch
''
''
2 Wireless PC's (windows 2000)



Here is what I want:

dsl modem
'''
''''
Suse linux Router/Firewall (RADIUS)
'''
'''
Dlink 624 wireless router/switch
''
''
2 Wireless PC's (windows 2000) authenticating to the linux server

To use RADIUS to authenticate my windows 2000 workstation to LINUX and have a secure wireless connection from within my network. Is this possible?

Last edited by metallica1973; 06-24-2005 at 04:07 PM.
 
Old 06-25-2005, 11:10 PM   #2
jspsandhu
Member
 
Registered: Dec 2004
Location: Slough, UK
Distribution: Fedora, FreeBSD, RHEL
Posts: 85

Rep: Reputation: 15
Does ur dlink has radius server support

If yes you can make it secure using freeradius

There are lots of articles on the same

Can see the following link for the same

http://www.tldp.org/HOWTO/8021X-HOWTO/index.html

Will not be sure how to add certificates on WIN 2000

But I am also working on securing Win XP over the wireless network using Radius server

Best of luck

Regards

JAS
 
Old 06-26-2005, 12:18 AM   #3
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
Thanks! At my work we use active directoy and we log into a w2k domain ,But can a windows 2000 machine authenticate to a linux machine using RADIUS. I would imagine so but I need some info.
 
Old 07-05-2005, 04:51 PM   #4
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
how would setup freeRADIUS to authenticate to a windows 2000 machine?
 
Old 07-07-2005, 01:20 PM   #5
Atrocity
Member
 
Registered: Nov 2002
Location: Hell
Distribution: FreeBSD, Slackware
Posts: 308

Rep: Reputation: 30
well if your router supports radius shouldnt your router have a place to fill in the address of where your radius server resides?? and also the selection of authentication by radius rather then the current supported athentication, that way they can talk?
 
Old 07-11-2005, 10:57 AM   #6
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
the part about configuring WPA and specifying my radius server IP address I completely understand. Let me clarify a little better. Lets say for example I have enable WPA on my wireless router and specified the IP address of my Linux RADIUS server. How would my windows 2000 workstation authenticate to my Linux RADIUS server. How does Linux RADIUS server make the wireless Windows 2000 workstaion think that they are logging into a windows network via authenication(active directory) for authenticating via RADIUS? Is there any additional software that I need to configure so that this will work? If I am on one of my wireless windows 2000 workstaion and I attempt to login as in lets say ROOT, can I? I dont think that this will work without some other type of translation software. I know that this setup will work with a windows 2000 server with RADIUS software and my wireless windows 2000 wokstations. All the software if from Microsoft. My question is will RADIUS work mixing LINUX and Microsoft products?

Last edited by metallica1973; 07-11-2005 at 10:59 AM.
 
Old 07-12-2005, 06:38 PM   #7
jspsandhu
Member
 
Registered: Dec 2004
Location: Slough, UK
Distribution: Fedora, FreeBSD, RHEL
Posts: 85

Rep: Reputation: 15
Yeah
you can definately authenticate using linux radius
Its not true that the communication will be different when you use linux as a Radius server
It will be the same as having windows as radius authentication server.
The only differnce that i could see configuring the two was that windows was all graphical but on linux it was command line and hence was fast

I used the following steps

Created a central authority
Created server certificates and signed them with my CA
Created client certificates ( when using EAP-TLS) and signed them too
Created certificates for XP clients

Configured freeradius for EAP-TLS
Shared the secret with my access point
Transfered the certirficates to the wireless client

Was wonderfull computer has to have a WPA supplicant or should be on XP SP2.

Well try searching on the topics cant find my links file so cant give now

Best of Luck
 
Old 07-19-2005, 04:48 PM   #8
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
did you have to create accounts on the linux box and when logging in the xp cpu's , did you use your linux accounts on your xp cpu's?
 
Old 07-20-2005, 03:01 AM   #9
jspsandhu
Member
 
Registered: Dec 2004
Location: Slough, UK
Distribution: Fedora, FreeBSD, RHEL
Posts: 85

Rep: Reputation: 15
Nope not central login from linux.

The certificates for client were used for authentication.

I used EAP-TLS that doesnt require central login but requires client certificates.

If you use PEAP or EAP-TTLS then you require central login but not in EAP-TLS

PEAP, EAP-TTLS is what i am looking forward to for wireless security also.

Thanks

Regards

Jaspreet
 
Old 07-20-2005, 10:52 AM   #10
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
many thanks! jspsandhu!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
RADIUS and Others wwnexc Linux - Networking 4 10-31-2005 01:30 PM
Radius gummimann Linux - Networking 0 02-04-2004 03:43 AM
Radius Help PuNkErX Linux - Networking 1 10-02-2003 11:01 PM
SAMBA bet RH 9 & W2K with Netgear Router - can't see W2K share cevjr Linux - Software 0 07-30-2003 11:44 AM
Installed W2k, then RH 7.3 but grub now can't see W2K ericcarlson Linux - General 5 07-17-2002 05:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration