Deploying Virtual Private Networks with Microsoft Windows Server 2003 (Technical Reference)

You can use third-party CAs to issue certificates for EAP-TLS authentication as long as the certificates installed can be validated and have the appropriate properties.

Certificates on the Authenticating Servers

For the computer certificates installed on the authenticating servers (either the VPN servers or the Internet Authentication Service [IAS] servers), the following must be true:

Additionally, the root CA certificates of the CAs that issued the VPN client user certificates must be installed in the Certificates (Local Computer)\Trusted Root Certification Authorities certificate store of the authenticating servers.

Certificates on VPN Client Computers

For the user certificates installed on VPN client computers, the following must be true:

Additionally, the root CA certificates of the CAs that issued the IAS server computer certificates must be installed in the Certificates (Local Computer)/Trusted Root Certification Authorities store of the VPN client computers.

Категории