Loading

Configure EAP-TLS with username authentication

Before you begin

This instruction applies to the [Username from domain; EAP-TLS] authentication method. The authentication method refers to the method you selected on PRISMAsync Print Server.

The instructions below refer to Windows Server 2016. Other systems may need other configuration. See the vendor documentation for complete instructions.

These configurations have been done.

  1. Configure IEEE 802.1X on the authentication server (phase 1)

  2. Configure IEEE 802.1X on the authenticator

  3. Configure IEEE 802.1X on PRISMAsync Print Server

Perform the instructions in the order they are listed.

Instruction 1. On Active Directory, create a group on the domain

  1. In [Server Manager] click [Tools].

    [Server Manager] options
  2. Open the [Active Directory Users and Computers] console.

  3. Right-click the domain name, click [New]. Then click [Group].

  4. Enter a name for the group.

    New group
  5. Select [Global] in the [Group scope] option group.

  6. Select [Security] in the [Group type] option group.

  7. Click [OK].

Instruction 2. Add user account

  1. In [Server Manager], click [Tools].

    [Server Manager] options
  2. Open the [Active Directory Users and Computers] console.

  3. Open the domain entries.

  4. Right-click [Users].

  5. Click [New]. Then click [User].

  6. Enter the username field. Then click [Next].

    The [Subject alternative name 1], [Subject alternative name 2] or [Subject alternative name 3] field of the PRISMAsync Print Server identity certificate contains the username written as UPN name (Internet-style name, such as: username@example.com) or as Fully Qualified Domain Name (FQDN) name, such as: username.example.com. Here you enter the username part of the UPN or FQDN.

    New user
  7. Click [Finish].

    New user
  8. When the user is added, right-click the user. Then click [Properties].

  9. Click the [Member Of] tab and click [Add...] to add the group you created in instruction 1.

    New user
  10. Click the [Dial-in] tab.

    [Dial-in] tab
  11. Select [Control access through NPS Network Policy] in the [Network Access Permission] option group.

  12. Click [OK].

Instruction 3. On authentication server, configure network policy for EAP-TLS with username authentication

  1. In [Server Manager] click [Tools].

    [Server Manager] options
  2. Open the [NPS] console.

  3. Open the [Policies] directory.

  4. Right-click [Network Policies]. Then click [New] to open the [New Network Policy] wizard.

  5. Enter a policy name.

    [Network Policies] options
  6. Ensure [Unspecified] is selected in the [Type of network access server] option.

  7. Click [Next].

  8. On the [Specify Conditions] page, click [Add...] and select [Windows Groups].

    [Network Policies] wizard
  9. Click [Add...] to add and select the group you created in instruction 1.

    [Network Policies] wizard
  10. Click [OK] to close the [Select Group] dialog box.

  11. Click [Next].

    [Network Policies] wizard
  12. On the [Specify Access Permission] page, select [Access granted].

    [Network Policies] wizard
  13. Click [Next].

  14. On the [Configure Authentication Methods] page, click [Add...]].

  15. In the [Add EAP] dialog box, select [Microsoft: Smart Card or other certificate].

  16. Click [OK].

  17. From the [EAP Types] list, select [Microsoft: Smart Card or other certificate]. Then click [Edit].

  18. In the [Smart Card or other Certificate Properties] dialog box, select the Identity certificate of the RADIUS server. This certificate refers to the trusted certificate available on PRISMAsync Print Server.

  19. Click [OK].

  20. Clear the [Less secure authentication methods] check boxes that refer to authentication methods you do not want to use.

  21. Click [Next].

  22. On the [Configure Constraints] page, click [Next].

  23. Click [Next].

  24. On the [Completing New Network Policy ] page, click [Finish].

    [Network Policies] wizard