Peap-Ms-Chap-V2 Security; About Keys And Certificates - 3Com 3CRWX120695A, 3CRWX440095A Configuration Manual

Wireless lan switch and controller
Table of Contents

Advertisement

256
C
12: M
HAPTER
PEAP-MS-CHAP-V2
Security
About Keys and
Certificates
K
C
ANAGING
EYS AND
ERTIFICATES
TLS allows the client to authenticate the WX switch (and optionally allows
the WX switch to authenticate the client) through the use of digital
signatures. Digital signatures require a public-private key pair. The
signature is created with a private key and verified with a public key. TLS
enables secure key exchange.
PEAP performs a TLS exchange for server authentication and allows a
secondary authentication to be performed inside the resulting secure
channel for client authentication. For example, the Microsoft Challenge
Handshake Authentication Protocol version 2 (MS-CHAP-V2) performs
mutual MS-CHAP-V2 authentication inside an encrypted TLS channel
established by PEAP.
1 To form the encrypted TLS channel, the WX switch must have a digital
certificate and must send that certificate to the wireless client.
2 Inside the WX switch's digital certificate is the WX switch's public key,
which the wireless client uses to encrypt a pre-master secret key.
3 The wireless client then sends the key back to the WX switch so that both
the WX and the client can derive a key from this pre-master secret for
secure authentication and wireless session encryption.
Clients authenticated by PEAP need a certificate in the WX switch only
when the switch performs PEAP locally, not when EAP processing takes
place on a RADIUS server. (For details about authentication options, see
Chapter 13, "Configuring AAA for Network Users," on page 277.)
Public-private key pairs and digital signatures and certificates allow keys
to be generated dynamically so that data can be securely encrypted and
delivered. You generate the key pairs and certificates on the WX switch
or install them on the switch after enrolling with a certificate authority
(CA). The WX switch can generate key pairs, self-signed certificates, and
Certificate Signing Requests (CSRs), and can install key pairs, server
certificates, and certificates generated by a CA.
The WX switch uses separate server certificates for Admin, EAP (802.1X),
and WebAAA authentication. Where applicable, the manuals refer to
these server certificates as Admin, EAP (or 802.1X), or WebAAA
certificates respectively.

Advertisement

Table of Contents
loading

Table of Contents