User's Manual
Setting up Profile Security
Authentication Protocol
This parameter specifies the authentication protocol operating over the PEAP tunnel. The protocols are:
MS-CHAP-V2, GTC, and TLS.
Using MS-CHAP-V2 and GTC protocols:
● Use the Windows logon user name and password: If this feature is selected the credentials are
retrieved from the Windows Logon process.
● Prompt for the user name and password: Selecting this feature prompts for user name and
password before you connect to the wireless network. The user name and password must be first
set in the authentication server by the IT administrator.
● For GTC protocol: Select whether you want to use a static password or a one-time
password.
● Use the following user name and password: The user name and password are securely
(encrypted) saved in the profile
● User Name: This user name must match the user name that is set in the authentication
server.
● Password: This password must match the password that is set in the authentication server.
The entered password characters display as asterisks.
● Confirm Password: Re-enter the user password.
● Use a client certificate: You may optionally select a client certificate from the Personal certificate
store of the Windows logged-in user, this certificate is used for client authentication.
● Roaming Identity: When using 802.1x MS RADIUS as an authentication server, the authentication
server authenticates the device by using the "Roaming Identity" username from Intel
PROSet/Wireless and ignores the "Authentication Protocol MS-CHAP-V2" User Name. This feature
is the 802.1x identity supplied to the authenticator. Microsoft IAS RADIUS accepts only a valid
username (dotNet user) for EAP clients. Enter a valid username when using 802.1x MS RADIUS.
For all other servers, this is an optional field, therefore, it is recommended that this field not contain
a true identity, but instead the desired realm (e.g., anonymous@myrealm).
Using TLS protocol:
● Use my smart card or certificate: Select smart card if the certificate resides on a smart card.
Select certificate if the certificate resides on the computer.
● User Name: This user name must match the user name that is set in the authentication server by
the system administrator prior to client's authentication. The user name is case-sensitive. This
name specifies the identity supplied to the authenticator by the authentication protocol operating
over the TLS tunnel. This user’s identity is securely transmitted to the server only after an
encrypted channel has been verified and established.
● Select: Choose a client certificate from the Personal certificate store of the Windows logged-in
user. This certificate is used for client authentication.
file:///C|/CX2%20Muroc%20UG/6-15-04/wepsetup.htm (15 of 19) [6/15/2004 3:40:10 PM]