Windows 10: Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...

Discus and support Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN... in Windows 10 Gaming to solve the problem; We are commencing a rollback of our employees' computer operating systems from Windows 24H2 to 23H2 due to complications with RADIUS Authentication for... Discussion in 'Windows 10 Gaming' started by InfoSec IT-Support, Jan 8, 2025 at 6:47 AM.

  1. Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...


    We are commencing a rollback of our employees' computer operating systems from Windows 24H2 to 23H2 due to complications with RADIUS Authentication for SmartCards and RADIUS VLAN Tagging on Wi-Fi networks in the newest version of Windows.Regarding RADIUS SmartCard authentication, we have observed complete freezes in the user interface, necessitating the termination of the "Credentials UI Host Manager" process. Our investigation indicates that this freezing issue does not manifest on all devices operating on 24H2 when authentication is performed at the Windows login screen or through Wi-Fi sett

    :)
     
    InfoSec IT-Support, Jan 8, 2025 at 6:47 AM
    #1
  2. DimitarEX Win User

    Radius server + WLC and Client Certificate Authentication

    Hello people,

    We have an issue with our radius server.

    I will explain what is our goal and what configuration we have so far:

    Our goal is to authenticate clients in the domain using WLC and Client Certificate Authentication.

    Each client in our domain has a unique personal certificate.

    The idea is when an employee opens his PC automatically connects to the specified by the GPO recommended network by using the certificate and not the username and password.



    Currently, we configured the WLC Cisco controller to receive the client certificate, authenticate it and provide the IP address(of course if the policies are validated).

    Afterward that the WLC controller has to send the request to the radius server. The radius should check if the certificate is valid (not expired) and not included in the revocation list.

    Here our issue came. It seems that the radius cannot access the revocation list and cannot check if the certificate is revoked.

    We validated that by disabling the revocation list check in the Radius server registry settings.

    If we set it to ignore the revocation list check, the authentication succeeds, and the client is authenticated successfully.

    The thing is that this way we lower the security of the connection significantly and we would like to make sure the certificate is validated against the revocation list.

    At the same time, there are no issues in the connection between the RADIUS server and the server where the revocation list is stored/published.



    Could you please let me know if there is any specific configuration that should be made in order for the radius to be able to check the status of the authenticated certificate in the revocation list?

    Is there any configuration guide that we have to follow in order to implement the necessary configuration in the most proper way?
     
  3. wlan + radius authentication

    Hello,

    i dont know what types of radius server your using? what types of security? enabled Proxcy? MS radius server or another party server? AP is configured to support radius server? Does your radius server support your Nokia Phone ?

    so many questions in my mind and everything must be configured in order to be able to connect to radius server.

    for the Better solution contact your Network Administrator he/she can connect you to radius server.

    thanks
     
    downloader---01, Jan 8, 2025 at 6:53 AM
    #3
  4. Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...

    A RADIUS message was received from RADIUS client 192.x.x.x with an invalid authenticator

    Hello Team,

    I am getting "A RADIUS message was received from RADIUS client 192.x.x.x with an invalid authenticator. This is typically caused by mismatched shared secrets. Verify the configuration of the shared secret for the RADIUS client in the Network Policy Server
    snap-in and the configuration of the network access server"

    But I updated the shared key as well but no luck.

    Thanks,

    Shailendra V
     
    Shailendra.Vishwakar, Jan 8, 2025 at 6:53 AM
    #4
Thema:

Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...

Loading...
  1. Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN... - Similar Threads - 24H2 Broken Changes

  2. Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...

    in Windows 10 Software and Apps
    Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...: We are commencing a rollback of our employees' computer operating systems from Windows 24H2 to 23H2 due to complications with RADIUS Authentication for SmartCards and RADIUS VLAN Tagging on Wi-Fi networks in the newest version of Windows.Regarding RADIUS SmartCard...
  3. Windows Endpoint stop sending RADIUS Authentication

    in Windows 10 Gaming
    Windows Endpoint stop sending RADIUS Authentication: Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS Certificate but during Friday Morning, We noticed that many endpoint start failing authentication and try to use MAC Address to...
  4. Windows Endpoint stop sending RADIUS Authentication

    in Windows 10 Software and Apps
    Windows Endpoint stop sending RADIUS Authentication: Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS Certificate but during Friday Morning, We noticed that many endpoint start failing authentication and try to use MAC Address to...
  5. Windows Endpoint stop sending RADIUS Authentication

    in AntiVirus, Firewalls and System Security
    Windows Endpoint stop sending RADIUS Authentication: Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS Certificate but during Friday Morning, We noticed that many endpoint start failing authentication and try to use MAC Address to...
  6. Radius serer + WLC and Client Certificate Authentication

    in Windows 10 Gaming
    Radius serer + WLC and Client Certificate Authentication: Hello people,We have an issue with our radius server.I will explain what is our goal and what configuration we have so far: Our goal is to authenticate clients in the domain using WLC and Client Certificate Authentication. Each client in our domain has a unique personal...
  7. Radius serer + WLC and Client Certificate Authentication

    in Windows 10 Software and Apps
    Radius serer + WLC and Client Certificate Authentication: Hello people,We have an issue with our radius server.I will explain what is our goal and what configuration we have so far: Our goal is to authenticate clients in the domain using WLC and Client Certificate Authentication. Each client in our domain has a unique personal...
  8. Windows 11 22H2 cannot authentication with 802.1x radius authentication server.

    in Windows 10 Gaming
    Windows 11 22H2 cannot authentication with 802.1x radius authentication server.: We try connnect wifi with security 802.1x authentication but it show can't connect this network and as I check the log on Wireless controller show that terminal not respond to radius server after EAP connect. How we can solve this issue because windows 10 can connect normally...
  9. Windows 11 22H2 cannot authentication with 802.1x radius authentication server.

    in Windows 10 Software and Apps
    Windows 11 22H2 cannot authentication with 802.1x radius authentication server.: We try connnect wifi with security 802.1x authentication but it show can't connect this network and as I check the log on Wireless controller show that terminal not respond to radius server after EAP connect. How we can solve this issue because windows 10 can connect normally...
  10. AP unable to authenticate to RADIUS server

    in Windows 10 Network and Sharing
    AP unable to authenticate to RADIUS server: RADIUS is running on NPS Windows 2016 Datacenter AP is Meraki MR33 I have tried just about everything I can think of in this configuration and cannot get a connection. I have looked over some of the other articles in the forum also but no success. If anyone can point out...