cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
524
Views
0
Helpful
4
Replies

machine-authentication with digital certificate

hstf_techy
Level 1
Level 1

https://kb.meraki.com/knowledge_base/radius-configuring-peap-mschapv2---machine-authentication

RADIUS: Obtain a digital certificate for a Windows domain member system

I am reading the above article and I am wondering do I need to obtain a certificate manually for each computer?

1 Accepted Solution

Accepted Solutions

there should not be, unless you are doing a CRL and checking your CA for updates.  So long as your the client trusts the AAA server certificate you should be fine.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

View solution in original post

4 Replies 4

Stephen Rodriguez
Cisco Employee
Cisco Employee

no, you do not need to do it manually. 

http://technet.microsoft.com/en-us/library/cc731242.aspx

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Thanks.

Let say if they are enroll automatically, is there any affect with the authentication process if the PKI server is down?

there should not be, unless you are doing a CRL and checking your CA for updates.  So long as your the client trusts the AAA server certificate you should be fine.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Abhishek Abhishek
Cisco Employee
Cisco Employee

Hello,

As per your query i can suggest  you the following solution-

No, there is no need to obtain a certificate manually for each computer.

Hope this will help you.

Review Cisco Networking for a $25 gift card