CATEGORII DOCUMENTE |
Asp | Autocad | C | Dot net | Excel | Fox pro | Html | Java |
Linux | Mathcad | Photoshop | Php | Sql | Visual studio | Windows | Xml |
DOCUMENTE SIMILARE |
|||
|
|||
In the set of instructions that follow, these assumptions are made:
The
computer functioning as your IAS/RADIUS server has Windows Server 2003
with SP1 installed, and the EnableWPSCompatibility
registry key is enabled according to the instructions in "Configuring IAS for
Client computers are running Windows XP Home Edition with SP2; Windows XP Professional with SP2; or Windows XP Tablet PC Edition with SP2.
All of your hardware, including the VLAN-aware
gateway device and VLAN-aware wireless access points, meet all of the technical
requirements stated in "Components
of
You have already deployed a computer running SQL Server 2000 or a third-party database program on your network. For information about SQL Server 2000, see SQL Server at https://go.microsoft.com/fwlink/?LinkId=20014.
You have SQL Server 2000 or third-party relational database development experience and you understand how to use SQL Server 2000 or a third-party database program to create, modify, administer, and manage your databases.
You have experience deploying an Internet
Information Services (IIS) or third-party Web server with HTTPS. If you are
deploying IIS, you understand how to use Active Server Pages (ASP), and you can
develop applications using Microsoft .
You have software development experience that allows you to create your custom Web application that will be installed and run on the provisioning server.
You have software development experience that allows you to create an IAS extension DLL.
Note The instructions that
follow use four servers upon which various programs and services are
installed. If you deploy |
To deploy
Configure the domain controller and IAS server
Configure the DHCP server
Install and configure your VLAN-aware gateway device
Install and configure your wireless access points
Configure RADIUS clients in IAS
Create your Web application
Configure the provisioning server
Configure XML master and subfiles
Configure the database on the SQL server
Configure the Windows XP-based client computer
Configure certificates in a test lab environment (optional)
Install Windows Server 2003, Standard Edition with SP1; Windows Server 2003, Enterprise Edition with SP1; or Windows Server 2003, Datacenter Edition with SP1 on a computer that meets or exceeds the minimum hardware requirements for the respective operating system. After the operating system is installed, you can perform General configuration, Active Directory configuration, IAS configuration, and IAS extension DLL & URL PEAP-TLV configuration.
Assign
the server a static IP address. Determine the IP address range for the WISP
Install a server certificate obtained from a public trusted root certification authority, such as a certificate from Verisign.
For more information, see "Obtaining and Installing a VeriSign WLAN Server Certificate for PEAP-MS-CHAP v2 Wireless Authentication" at https://go.microsoft.com/fwlink/?LinkId=33675.
When you obtain the certificate, it must conform to the minimum server certificate requirements described earlier in this paper.
For more information, see "Network access authentication
and certificates" in Help and
Note If you are deploying |
Install Active Directory and DNS. To install Active Directory, open Command Prompt, type dcpromo, and then follow the instructions provided in the wizard, entering your network configuration information in the wizard as you progress.
Design and create your security groups. When
users sign up and create an account, your Web application adds the new user
account as the member of a security group that you create in this step. The Web
application chooses group membership based on the value of the security group
field in the promotion code database on your SQL Server, so you need to match
the security group you create to the security group field in the SQL server
database. If you have the need for multiple security groups, you can assign
permissions to each group individually. For more information, see "To create a new group" in Help and
Important The security groups you create in Active Directory are named and used in the SQL Server database and in IAS remote access policy. |
Enable the Guest account in Active Directory. If guest access is not enabled in Active Directory, new customers cannot access your provisioning server by authenticating as guest. To enable the Guest account, open the Active Directory Users and Computers snap-in, and then double-click Users. Right-click the account named Guest, and then click Enable Account.
To perform the next procedure, you must be a member of either the Domain Admins group in the domain for which you want to raise functionality or the Enterprise Admins group in Active Directory; or you must have been delegated the appropriate authority.
Raise the domain functional level to either Windows 2000 native or Windows Server 2003 by doing the following:
Open the Active Directory Domains and Trusts snap-in. Click Start, click Control Panel, double-click Administrative Tools, and then double-click Active Directory Domains and Trusts.
In the console tree, right-click the domain for which you want to raise functionality, and then click Raise Domain Functional Level.
In Select an available domain functional level, do one of the following:
To raise the domain functional level to Windows 2000 native, click Windows 2000 native, and then click Raise.
To raise domain functional level to Windows Server 2003, click Windows Server 2003, and then click Raise.
Important If you have or will have any domain controllers running Windows NT 4.0 and earlier, then do not raise the domain functional level to Windows 2000 native. After the domain functional level is set to Windows 2000 native, it cannot be changed back to Windows 2000 mixed. Likewise, if you have or will have any domain controllers running Windows NT 4.0 and earlier or Windows 2000, then do not raise the domain functional level to Windows Server 2003. After the domain functional level is set to Windows Server 2003, it cannot be changed back to Windows 2000 mixed or Windows 2000 native. |
The current domain functional level is displayed under Current domain functional level in the Raise Domain Functional Level dialog box.
For more information, see "Domain and forest functionality"
in Help and
For information about configuring Active Directory replication, see "Active Directory replication" in this paper.
For IAS, the three configuration stages are General configuration, Remote access policy configuration, and Connection request policy configuration. (RADIUS client configuration occurs later in the overall WISP deployment process.)
Install Internet Authentication Service.
For more information, see "To install IAS" in Help and
Register IAS in Active Directory. In order for IAS to have permission to read user accounts in Active Directory, IAS must be registered in Active Directory.
For more information, see "To enable the IAS server to
read user accounts in Active Directory" in Help and
Delete the default remote access policies. To delete the policies, open the IAS console, and then click Remote Access Policies. Select each existing policy, right-click the policy, and then click Delete.
Create your IAS extension DLL. For more information, see "How to create an IAS extension DLL and a URL PEAP-TLV" in this paper.
Install the DLL on your IAS server and configure DLL registry keys according to your needs.
To install your DLL, do the following:
Open Command Prompt and change directories to the folder that contains your DLL.
Type the following: regsvr32 DLL_name.dll, where DLL_name.dll is the name of your DLL file.
There are two remote access policies configured for
Note If you have a variety of account types that you offer to customers and these accounts have different properties (such as membership to different security groups), you might find it necessary to create more than two remote access policies on your IAS server. If this is the case, you can use the remote access policies described below to extrapolate how to create additional policies. |
To configure the Guest access policy
Open the Internet Authentication Service console and, if necessary, double-click Internet Authentication Service.
In the console tree, right-click Remote Access Policies, and then click New Remote Access Policy.
Use the New Remote Access Policy Wizard to create a policy. For the WISP guest access policy, you can choose the following:
a. For How do you want to set up this policy? select Use the wizard to set up a typical policy for a common scenario
For Policy name, type Guest access (or type another name for your policy that you prefer).
For Select the method of access for which you want to create a policy, click Wireless.
For Grant access based on the following, click User.
In Select the EAP type for this policy, select Protected EAP (PEAP), and then click Configure.
In Certificate issued, select the certificate that you want the IAS server to use to verify its identity to client computers. Also select the Enable Fast Reconnect check box.
After you have completed creating the policy and have closed the wizard by clicking Finish, you need to perform additional policy configuration.
In the IAS console, click Remote Access Policies, and then double-click the policy you just created. Make the following configuration changes to the policy:
In the policy Properties dialog box, for Policy conditions, click Add.
In Attribute Types, click Day-And-Time-Restrictions, and then click Add. In Time of day restraints, select Permitted, configure the days and times that access is permitted, and then click OK.
In the policy Properties dialog box, click Grant remote access permission.
Click Edit Profile. On the Authentication tab, in Unauthenticated access, click Allow clients to connect without negotiating an authentication method.
To configure the Valid Users access policy
Open the Internet Authentication Service snap-in and, if necessary, double-click Internet Authentication Service.
In the console tree, right-click Remote Access Policies, and then click New Remote Access Policy.
Use the New Remote Access Policy Wizard to create a policy. For the WISP Valid users access policy, you can choose the following:
a. For How do you want to set up this policy? verify that Use the wizard to set up a typical policy for a common scenario is selected.
For Policy name, type Valid Users (or type another name for your policy that you prefer).
For Select the method of access for which you want to create a policy, click Wireless.
For Grant access based on the following, click Group, and then click Add. In Enter the object name to select, type the name of a security group that you defined when configuring Active Directory. For example, if you created a group named Valid Users, type Valid Users, and then click OK.
Important The following three items must match: the name of the security group in Active Directory, the value of the security group field in the SQL Server database, and the name of the security group configured in the Valid Users access policy in IAS. The Web application uses the value of the SQL Server database security group field to determine group membership for new accounts. |
In Select the EAP type for this policy, select Protected EAP (PEAP), and then click Configure.
In Certificate issued, select the certificate that you want the IAS server to use to verify its identity to client computers. Also check the Enable Fast Reconnect check box.
After you have completed creating the policy and have closed the wizard by clicking Finish, you need to perform additional policy configuration.
In the IAS console, click Remote Access Policies, and then double-click the policy you just created. Make the following configuration changes to the policy:
In the policy Properties dialog box, for Policy conditions, click Add.
In Attribute Types, click Day-And-Time-Restrictions, and then click Add. In Time of day restraints, select Permitted, configure the days and times that access is permitted, and then click OK.
In the policy Properties dialog box, click Grant remote access permission.
Click Edit
Profile, and then click the Advanced
tab. By default, the Service-Type
attribute appears in Attributes with
a value of Framed. To specify
additional connection attributes required for
Framed-Protocol. Value:
Tunnel-Medium-Type. Value: 802 (Includes all 802 media plus Ethernet canonical format)
Tunnel-Pvt-Group-ID. Value: Enter the integer that represents the VLAN number for the Internet VLAN. For example, if your access controller's Internet VLAN is VLAN 4, type
Tunnel-Type. Value: Virtual LANs (VLAN)
Tunnel-Tag. Value: Obtain this value from your hardware documentation
Important IAS evaluates remote access policies in the order in which they appear in the IAS console under Remote Access Policies. The Valid Users access policy must be the first policy in the list of remote access policies or valid user authentication will fail. Because IAS places newly created policies in the first position and the Valid Users access policy was the last policy created, the Valid Users access policy should now appear first in the IAS console, with the Guest access policy appearing second. If this is not the case, move the Valid Users access policy into first position. |
By default, there is one connection request policy
predefined in the IAS console, called Use Windows
authentication for all users. This policy can be used for
In the IAS console, double-click Connection Request Processing, click Connection Request Policies, and then double-click the policy Use Windows authentication for all users.
Click Edit Profile. The Edit Profile dialog box opens.
On the Authentication tab, click Authenticate requests on this server, and then check the Protected EAP check box.
Click Configure Certificate. Select the certificate you want IAS to use to authenticate to clients, and then click OK three times to close all dialog boxes and return to the IAS console.
Note If you access the profile of a connection request policy
in the IAS console and you cannot see the Protected EAP check box or the Configure Certificate button, you must first configure IAS for
compatibility with |
On a computer running Windows Server 2003:
Install DHCP.
For more information, see "To
install a DHCP server" in Help and
In the DHCP console, run New
Scope Wizard twice. Create two VLAN scopes from which IP addresses will
be leased to wireless clients connected to the VLANs. Each scope must define a
different IP address range using either a private address range or a public IP
address range. If you are using network address translation (
For more information, see "To
create a new scope" in Help and
While running New Scope Wizard, create an exclusion range for the IP addresses you will be assigning statically. For example, if you need to statically assign 10 IP addresses from the address range 10.1.1.1 through 10.1.1.254, your exclusion range is defined as 10.1.1.1 through 10.1.1.10.
While running New Scope Wizard, assign scope options. On the Configure DHCP Options page, select Yes, I want to configure these options now. Scope options are applied only to leases of addresses from within the IP address range that the scope defines, which provides flexibility as your network grows. Define the DNS server and Domain name options, as well as any other options that are appropriate for your network configuration.
While running New Scope Wizard, activate the scope. The option to activate the scope while running the wizard is available only if you have chosen to configure DHCP scope options in the previous steps.
For more information, see "To
activate a scope" in Help and
Authorize the DHCP server in Active Directory.
For more information, see "To
authorize a DHCP server in Active Directory" in Help and
The DHCP server is now online and able to provide IP address
leases to client computers. In some cases you might want to examine the types
and durations of accounts you offer your customers and adjust the DHCP lease
duration accordingly. In most cases when deploying
In this example, you are creating two VLANs and two scopes, one scope for each VLAN.
VLAN 2 is the Network Resource VLAN that provides access to network resources (such as the IAS server and DHCP server) for wireless computers connecting as guest. VLAN 2 blocks access to the Internet, however. The DHCP scope for VLAN 2 is defined with the following example parameters:
Address range:
192.168.1.1 through 192.168.1.254. This is a private IP address range. If you
are using
Exclusion range: 192.168.1.1 through 192.168.1.10. By using this exclusion range, the available address pool for clients is 192.168.1.11 through 192.168.1.254. Ten IP addresses are excluded so that you can statically assign these addresses to computers and devices on your network. For example, the router IP address must be statically assigned on the router.
DHCP scope option 003, Router: 192.168.1.1. The router IP address must be an address that falls within the exclusion range so that the DHCP server does not lease the router IP address to a wireless client computer, thereby creating an address conflict.
DHCP scope option 006, DNS
server: the IP address of the Active Directory and DNS server on the
WISP
Note that DHCP scope option 003, Router, provides client computers with the IP address of their default gateway IP address. In this case, the default gateway for wireless clients is the VLAN-aware gateway device, whether it is an access controller, a VLAN-aware router, a VLAN-aware switch, or another compatible device. When you configure your VLAN-aware gateway device, you can specify the IP address that the device uses for each VLAN.
In this example, you must configure the VLAN-aware gateway device so that it uses the IP address 192.168.1.1 on VLAN 2.
For your
VLAN 4 is the Internet VLAN that provides access to the Internet. Users who have successfully created an account are switched to this VLAN after completing the provisioning and sign-up process. The DHCP scope for VLAN 4 is defined with the following example parameters:
Address range: 192.168.2.1 through 192.168.2.254
Exclusion range: 192.168.2.1 through 192.168.2.10
DHCP scope option 003, Router: 192.168.2.1. The router IP address must be an address that falls within the exclusion range so that the DHCP server does not lease the router IP address to a wireless client computer, thereby creating an address conflict.
DHCP
scope option 006, DNS server: the IP address of the Active Directory and
DNS server on the WISP
For VLAN 4 in this example, you must configure the VLAN-aware gateway device so that it uses the IP address 192.168.2.1 on VLAN 4.
Configure two VLANs on the gateway device: a Network
Resource VLAN that provides access to the WISP
The remote access policies you create in IAS determine which VLAN your customers can access:
The Guest access policy places users on the Network Resource VLAN so that they can create and pay for a valid user account.
The Valid Users access policy in IAS places customers on the Internet VLAN.
Each VLAN has a different IP address range. When configuring your DHCP server, you created a scope for each VLAN, and you defined DHCP scope option 003, Router. This is the IP address commonly referred to as the "default gateway."
You must configure the VLAN-aware gateway device as the default gateway for each VLAN, using an IP address from the IP address range that you defined on your DHCP server.
Your VLAN-aware gateway device is the default gateway for both VLANs and is configured with a different IP address for each VLAN.
After you define an IP address range for a VLAN on your DHCP server, you can use any IP address from that range as the IP address for the default gateway. To prevent an IP address conflict, however, exclude some IP addresses from the range for use by devices that you want to configure with a static IP address. When you create an exclusion range for an IP address range, the DHCP server does not lease IP addresses from the exclusion range to DHCP clients.
Note IP address conflicts occur when two devices or computers on the same subnet have the same IP address. This situation can occur if you configure a device or computer with a static IP address that is also an address that the DHCP server can lease to DHCP clients. |
Thus ensure that you assign an IP address from the exclusion range as the IP address for the default gateway. The address you use does not need to be the first address in the exclusion range, but it must be an address contained within the exclusion range.
In accordance with the example provided in the DHCP configuration section of this paper, configure the VLAN-aware gateway device so that it uses an IP address from the exclusion range 192.168.1.1 through 192.168.1.10 for VLAN 2. For example, you can configure the VLAN-aware gateway device so that it uses the IP address 192.168.1.1 on VLAN 2.
Important In each scope you configure on the DHCP server, the value you enter for DHCP scope option 003, Router, must match the IP address you assign to the VLAN-aware gateway device for use on each VLAN. For example, if you configure a scope on the DHCP server for VLAN 2 with the IP address range 192.168.1.1 through 192.168.1.254, and you assign the DHCP scope option 003, Router, with the value 192.168.1.1, you must configure the VLAN-aware gateway device to use the IP address 192.168.1.1 on VLAN 2. |
Similarly, as described in "Configure the DHCP server" in this paper, configure the VLAN-aware gateway device so that it uses an IP address from the exclusion range 192.168.2.1 through 192.168.2.10 for VLAN 4. For example, you can configure the VLAN-aware gateway device so that it uses the IP address 192.168.2.1 on VLAN 4.
In some circumstances you might prefer to use your VLAN-aware gateway device as the DHCP server for each VLAN. If this is the case, you must define IP address ranges and exclusion ranges on the VLAN-aware gateway device rather than on a DHCP server.
See the product documentation for your VLAN-aware gateway device for information about configuring your hardware.
Important The Internet VLAN integer must match the value you configure for the Tunnel-Pvt-Group-ID attribute in the Valid Users access policy on your IAS server. For example, if VLAN 4 leads to the Internet, the value of the Tunnel-Pvt-Group-ID attribute in the profile of the Valid Users access policy must be 4. |
Following is an example of how to configure your wireless
access points for use with
The Cisco access point used in this example provides a Web-based interface for access point configuration. To use this interface for access point configuration, you must physically connect the access point to the network, log on to a computer that has network connectivity to the access point, and then open a Web browser, such as Microsoft Internet Explorer.
Type the IP address for your 802.1X-compatible access point in the Web browser address bar, and then press ENTER. The access point configuration page appears in the Web browser.
To configure your wireless access point
On the configuration page, click the Setup tab, and then click Express Setup.
In the Radio Service Set ID (SSID) field, type an SSID for the access point, and then click OK.
Under Services, click Security, and then click Radio Data Encryption (WEP).
On the AP Radio Data Encryption page, select the Open check boxes for the Accept Authentication Type and the Require EAP options, and then clear all other check boxes.
In the Encryption Key box, type a 32-digit WEP key. In the Key Size list, select 128 bit, and then, to update the page, click Apply.
In the Use of Data Encryption by Station is list, select Full Encryption, and then click OK.
On the Security Setup page, click Authentication Server. The following table shows the values to set on the Authenticator Configuration page.
Item |
Value |
802.1X Protocol Version (for EAP Authentication) |
Draft 10 |
Server Name/IP |
IAS server IP address |
Server Type |
RADIUS |
Port |
1812 |
Shared Secret |
Type the shared secret you want to use for RADIUS clients |
Timeout (in seconds) |
20 |
User server for |
EAP Authentication |
When you have completed the configuration of the authentication server, click OK.
If you are using an access point (AP) other than Cisco, follow the directions in your access point documentation using the following guidelines:
Authentication or RADIUS server: Specify your IAS server by IP address or FQDN, depending on the requirements of the AP.
SSID: Specify a Secure Set Identifier (SSID), which is an alphanumeric string that serves as the network name. This name is broadcast by APs to wireless clients and is visible to users at your Wi-Fi hotspots.
RADIUS settings: Use RADIUS authentication on User Datagram Protocol (UDP) port 1812 and use RADIUS accounting on UDP port 1813.
Secret or shared secret: Use a strong shared secret and configure the IAS server with the same shared secret.
EAP: Configure the AP to require EAP from wireless clients.
802.1X and WEP: Enable IEEE 802.1X authentication and WEP.
Note Make sure that you use a strong
shared secret. For more information about how to create a strong shared
secret, see 'Shared secrets' in Windows Server 2003 Help and |
In the IAS console, add each access point
on your network as a RADIUS client. In addition, configure the shared secret
used between the access points and the IAS server. For more information, see "To
add RADIUS clients" in Help and
If your IAS server is running Windows Server 2003, Enterprise Edition, or Windows Server 2003, Datacenter Edition, you can configure RADIUS clients by IP address range. This is a useful feature when you have a large number of access points to deploy; if you deploy your access points on the same subnet or VLAN within the same IP address range, configuration of RADIUS clients in IAS is simplified. Instead of individually configuring each access point as a RADIUS client in IAS, you can configure all access points at once using the IP address range of the subnet or VLAN upon which the APs reside. In this circumstance, use the same shared secret for all access points, and make sure that the shared secret is strong.
By contrast, you can configure IAS in Windows Server 2003, Standard Edition, with a maximum of 50 RADIUS clients. You can define a RADIUS client using a fully qualified domain name or an IP address, but you cannot define groups of RADIUS clients by specifying an IP address range. With Windows Server 2003, Standard Edition, if the fully qualified domain name of a RADIUS client resolves to multiple IP addresses, the IAS server uses the first IP address returned in the DNS query. With IAS in Windows Server 2003, Enterprise Edition, and Windows Server 2003, Datacenter Edition, you can configure an unlimited number of RADIUS clients.
Your Web application must be capable of performing the following functions:
Communicating with Wireless Provisioning Services using HTTPS.
Uploading XML master file and subfiles that are stored on the provisioning server to client computers that request the files.
Accepting and processing XML documents from client computers that contain customer data, such as promotion code, customer name, customer address, and other information.
Accepting and processing XML documents from client computers that contain credit card information. This includes verifying the credit card and charging the customer account.
Reading the promotion code database records to validate promotion codes.
Reading the promotion code database records to determine the domain in which to create a new user account.
Reading the promotion code database records to determine the security group membership for a new user account.
Writing a user name to the user name field in the promotion code database.
Dynamically creating new accounts in Active Directory (or a third-party LDAP-compliant database) using data provided by customers as well as parameters from the promotion code database.
It is recommended that the design of your Web application provides customers with knowledge of their user name and password. Customers can either be allowed to designate their own user name and password or this information can be provided to them upon completion of the sign-up wizard. Following are some circumstances where customers need to know their password-based credentials:
For a variety of reasons, user authentication might fail. For example, cached credentials might get corrupted or network connectivity issues might prevent wireless client computers from successfully authenticating.
The user account expires and the customer wants to renew their account. In this circumstance, IAS sends a URL PEAP-TLV to the wireless client that contains the renewal action parameter and the URL of the provisioning server. After the wireless client is directed to your account renewal application, the customer must have their password-based credentials to renew their account.
If your customers know their user name and password, they can attempt to connect to your network until they are successful. If they do not have this information, they cannot fix the problem without calling your help desk.
You can create your Web application with the Microsoft .
Microsoft .
If you have already installed Microsoft Visual Studio .
You can get .
Windows Server 2003
Microsoft Windows 2000 (Service Pack 2 is recommended)
Windows XP Professional or Windows XP
Home Edition (Windows XP Professional is required to run ASP.
For the provisioning server, if you are using Internet Information Services (IIS), do the following:
Install
Internet Information Services and ASP.
For more information, see "To install Internet
Information Services (IIS) 6.0" in Help and
Verify that you have .
a.
If Microsoft .
%WINDIR%Microsoft.
If
Microsoft .
Create two folders in the Web server root location %systemroot%Inetpubwwwroot. You can use one folder to hold your custom Web application and one folder to hold the XML master and subfiles that you will be creating in later steps. For example, you can create a folder named wpsdeploy (%systemroot%Inetpubwwwrootwpsdeploy) to contain your Web application, and you can create a folder named wpsfiles (%systemroot%Inetpubwwwrootwpsfiles) to contain your XML files.
Install your Web application into the folder you created for the Web application files.
Set user permissions for the Web application. Open Windows Explorer and browse to the location where you installed your Web application. For example, if you named your folder wpsdeploy, browse to %systemroot%Inetpubwwwrootwpsdeploy. Right-click the wpsdeploy folder, and then click Sharing and Security. On the Security tab, click Add. In Enter the object names to select, type Everyone, and then click OK. In Permissions for Everyone, enable Write permissions by checking the Allow check box.
Enable HTTPS. You must configure IIS to use a certificate for secure Web communications between the provisioning server and clients. To enable HTTPS you must install a server certificate obtained from a public trusted root certification authority, such as a certificate from Verisign or Thawte. When you obtain the certificate, it must conform to the minimum server certificate requirements described in this paper.
For more information, see "Network access authentication
and certificates" in Help and
To enable Secure Sockets Layer (SSL) and HTTPS, complete the following procedures.
Note If you are deploying a certification authority in a test lab environment, you must install and configure the CA before completing the following procedures. |
To obtain a new server certificate using Web Server Certificate Wizard
In IIS Manager, expand the local computer, and then expand the Web Sites folder.
Right-click the Web site or file that you want, and then click Properties.
On the Directory Security or File Security tab, under Secure communications, click Server Certificate.
In Web Server Certificate Wizard, click Create a new certificate.
Complete Web Server Certificate Wizard, which will guide you through the process of requesting a new server certificate.
To install a server certificate using Web Server Certificate Wizard
In IIS Manager, expand the local computer, and then expand the Web Sites folder.
Right-click the Web site or file that you want, and then click Properties.
On the Directory Security or File Security tab, under Secure communications, click Server Certificate.
In Web Server Certificate Wizard, click Assign an existing certificate.
Complete Web Server Certificate Wizard, which will guide you through the process of installing a server certificate.
Note The Web Server Certificate Wizard always denotes this step as 'assigning' a certificate to a resource (such as a file, directory, or site), not as 'installing." |
There are two methods you can use to create and configure your XML master and subfiles:
Use the
Use the XML schemas provided in this paper to create your files. After you have created these files, you can enter information specific to your network and deployment parameters. For example, where the location of the provisioning server is required, you can provide an HTTPS URL. In another example, you may need to enter your domain name in several places; you can examine the schemas and example files and determine where to insert your domain name.
When your XML files are configured with the information for your organization, you can store them on your provisioning server and configure your Web application so that it can find the files when necessary. If you are using Internet Information Services as your Web server, you can install the files at the location %systemroot%inetpubwwwroot.
On the computer running SQL Server 2000 or a third-party product with similar functionality, create a promotion code database with the following fields, using the appropriate data type for each field:
Promotion code. This field contains promotion codes that you distribute publicly to potential customers. When customers sign up for an account, they provide the promotion code that is matched by the Web application to a value in this field in the database.
User name. This field has no value assigned until a customer creates an account. At this time, the Web application assigns a value to this field.
Domain name. This field contains the domain name where you want the Web application to create the user account when a customer signs up using the promotion code.
Security group. The Web application joins the new user account to the security group defined in this field.
Expiration date. If your promotion lasts for a specific period of time, you can enter the expiration date related to the promotion code in this field. If a user with a promotion code attempts to create an account after the expiration date for the promotion, they cannot do so.
Populate the database with records, providing values for all fields except user name, and enable the data link between your Web application and the SQL server. Also configure security and authentication on the SQL server so that your Web application has permission to access and write to the database. For more information, see SQL Server at https://go.microsoft.com/fwlink/?LinkId=20014.
Important When you configure values for records in the SQL Server database, the following three items must match: the name of the security group in Active Directory, the value of the security group field in the SQL Server database, and the name of the security group configured in the Valid user remote access policy in IAS. The Web application uses the value of the SQL Server database security group field to determine group membership for new accounts. |
On the computer running Windows XP Professional, Windows XP Tablet PC Edition, or Windows XP Home Edition, install SP2. The computer must have a wireless network adapter compatible with IEEE 802.11 and 802.1X.
Note If you are deploying |
If you are deploying
On a computer running Windows Server 2003, install Certificate Services.
For more information, see "To
install an enterprise root certification authority" in Help and
Add a server certificate template to the certification authority and configure the certification authority to allow computers to request a certificate that is based on the template you create.
For
In addition, you must base your certificate on the correct
certificate template for the operating system you are running. If you are
running an enterprise certification authority (CA) on a computer running
Windows Server 2003, Standard Edition, and your IAS server is a domain
member, base your certificate on the Computer certificate template. If you are running an
enterprise certification authority (CA) on a computer running Windows
Server 2003, Enterprise Edition, and your IAS server is a domain member,
base your certificate on the
For more information, see "To
create a certificate template" in Help and
Autoenroll certificates to domain member
computers. Autoenrollment allows domain member computers to automatically
obtain, or enroll, certificates. For
For more information, see "Planning for autoenrollment
deployment" in Help and
Install the enterprise CA certificate in the Trusted Root Certification Authority certificate store on client computers being used for testing purposes. You can request the enterprise root CA certificate by using Web enrollment services, which is installed with Certificate Services, or you can export the server certificate to a floppy disk, and then import the certificate into the Trusted Root Certification Authority certificate store on the client.
For more information, see "To
export a certificate" in Help and
Politica de confidentialitate | Termeni si conditii de utilizare |
Vizualizari: 1179
Importanta:
Termeni si conditii de utilizare | Contact
© SCRIGROUP 2024 . All rights reserved