LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking > Linux - Wireless Networking
User Name
Password
Linux - Wireless Networking This forum is for the discussion of wireless networking in Linux.

Notices


Reply
  Search this Thread
Old 11-13-2007, 09:31 AM   #1
njpruess
LQ Newbie
 
Registered: Nov 2007
Posts: 3

Rep: Reputation: 0
wireless authentication prior to ldap logon


we have about 15-20 laptops that dual boot into xp and ubuntu 7.04. on the XP side they are joined to a domain and part of active directory. ubuntu uses ldap to authenticate. we have figured out a way to get wireless authentication prior to logon on xp but need a way to do this on the linux side as well. the xp side authenticates the computer for wireless rather than a user prior to logon so they are able to log on to the active directory domain through a wireless connection. The problem is all our wireless authentication has to occur with an active directory account and the linux side isn't connected to that. is there a way to get linux to use active directory to authenticate wireless prior to logon then use ldap as the actual logon? or even if we could join the linux side to the active directory domain instead of ldap, is there a way to get it to authenticate prior to logon?
 
Old 11-14-2007, 02:02 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
Could you provide more details on the wireless authentication process. What protocol is used? Active directory may be used to look up certificates for a radius server. You may be able to use xsupplicant on the clients to authenticate.

google for "8021X-HOWTO". The FAQ states the free-radius can use Active Directory. It is the Free Radius <-> client interaction that I think you want to work with.

One of these resources might help:
Quote:
9. Useful Resources
Only IEEE standards older than 12 months are available to the public in general (through the "Get IEEE 802 Program"). So the new 802.11i and 802.1X-2004 standards documents are not available. You must be a IEEE participant to get hold of any drafts/work in progress papers (which actually isn't that hard - just join a mailing list and say you are interested).
FreeRADIUS Server Project http://www.freeradius.org/
Open1x: Open Source implementation of IEEE 802.1X (Xsupplicant) http://www.open1x.org/
The Open1x User's Guide http://sourceforge.net/docman/displa...group_id=60236
Port-Based Network Access Control (802.1X-2001) http://standards.ieee.org/getieee802...02.1X-2001.pdf
RFC2246: The TLS Protocol Version 1.0 http://www.ietf.org/rfc/rfc2246.txt
RFC2459: Internet X.509 Public Key Infrastructure - Certificate and CRL Profile http://www.ietf.org/rfc/rfc2459.txt
RFC2548: Microsoft Vendor-specific RADIUS Attributes http://www.ietf.org/rfc/rfc2548.txt
RFC2716: PPP EAP TLS Authentication Protocol http://www.ietf.org/rfc/rfc2716.txt
RFC2865: Remote Authentication Dial-In User Service (RADIUS) http://www.ietf.org/rfc/rfc2865.txt
RFC3079: Deriving Keys for use with Microsoft Point-to-Point Encryption (MPPE) http://www.ietf.org/rfc/rfc3079.txt
RFC3579: RADIUS Support For EAP http://www.ietf.org/rfc/rfc3579.txt
RFC3580: IEEE 802.1X RADIUS Usage Guidelines http://www.ietf.org/rfc/rfc3580.txt
RFC3588: Diameter Base Protocol http://www.ietf.org/rfc/rfc3588.txt
RFC3610: Counter with CBC-MAC (CCM) http://www.ietf.org/rfc/rfc3610.txt
RFC3748: Extensible Authentication Protocol (EAP) http://www.ietf.org/rfc/rfc3748.txt
Linux Wireless Access Point HOWTO http://oob.freeshell.org/nzwireless/LWAP-HOWTO.html
SSL Certificates HOWTO http://www.tldp.org/HOWTO/SSL-Certificates-HOWTO/
OpenSSL: x509(1) http://www.openssl.org/docs/apps/x509.html
Be forewarned that Microsoft's "Embrace, Expand, Destroy" policy may be cause for numerous non-standard issues. Such as what they did to non-standardize kerberos, ldap, eap and you are dealing with virtually all of them at once.

Last edited by jschiwal; 11-14-2007 at 02:19 AM.
 
Old 11-29-2007, 02:55 PM   #3
njpruess
LQ Newbie
 
Registered: Nov 2007
Posts: 3

Original Poster
Rep: Reputation: 0
I work for a "subdivision" of the main IT department which means I don't directly have control over how our wireless network operates. Actually, I think the department we support might be the only one on campus that has linux users so I doubt anything is going to get changed for the 30 or so computers we are trying to get to authenticate. As far as I know, we use WPA security. I'm not exactly sure how it all works yet since I'm new here but the signal is broadcast such that all a user has to do when they want to connect is type in their AD credentials and domain name and it authenticates (this is on the windows side). I have been informed recently that these laptops can't connect to our wireless network at all on the linux side, so getting that problem solved first would be more beneficial than figuring out how to get the wireless connection enabled prior to logon. I don't recall hearing anything about a radius server being used here and I imagine it would be difficult to get the higher-ups to go along with that. I hope this helps a little bit but if you need more info let me know and i'll try to squeeze it out of someone.
 
Old 11-30-2007, 09:29 AM   #4
njpruess
LQ Newbie
 
Registered: Nov 2007
Posts: 3

Original Poster
Rep: Reputation: 0
scratch that. i found a nice guide with several configs and we were able to get it to work. http://ubuntuforums.org/showthread.p...light=wpa+peap
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
help in LDAP authentication chickenjoy Linux - Server 3 06-14-2007 05:28 AM
LDAP howto? simple setup up? linux logon? sirmonkey Linux - Networking 1 04-07-2006 09:00 AM
Samba share authentication using logon username and password mikepengelly Linux - Software 0 08-31-2004 03:47 AM
Authentication Error [gnome logon RH9] carmoda Linux - General 0 12-17-2003 12:32 AM
How to make linux take the logon authentication from my winnt server funmaya Linux - Networking 5 01-11-2002 03:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking > Linux - Wireless Networking

All times are GMT -5. The time now is 06:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration