Hi all,
I'm testing DA under Windows Server 2012 and have a working configuration using IP-HTTPS for both Kerberos Proxy and Windows 7/Windows 8 hybrid mode scenarios (using client certs). I've now expanded testing to include the OTP capability and followed
the instructions here:
http://technet.microsoft.com/en-us/library/hh831715.aspx
I'm seeing authentication requests being processed correctly and the DA Server authenticating correctly with the selected RADIUS server. In the event log I say a RADIUS Accept message for authentication. On the test Windows 8 client though, when logging
on, from the CTRL-ALT-DEL screen, using the OTP Credentials, I'm getting the following error message:
Authentication Failed due to an Internal Error x80040008. Try again or ask your administrator for help.
On the CA I see a failed request for the (smart card) certificate to be enrolled.
The parameter is incorrect. 0x80070057 (WIN32:87). Denied by Policy Module
I've tried this configuration on a couple of different CAs (Windows 2008 and Windows 2008R2), but the results are the same. The CA is reachable from the DA client as required.
Looking at this article
http://technet.microsoft.com/en-us/library/hh831379.aspx
- It states that if successful, the Remote Access server signs the certificate request using its registration authority certificate, and sends it back to the DirectAccess client computer.This doesn't appear to be working.
1. Anyone have any ideas why the DAOTPLogon certificate is failing during the enrolment process?
2. There's a DAPROBEUSER account I've created which is used to determine the availability of the RADIUS service, but where is the corresponding password specified on the DA Server to be passed to RADIUS? I saw a reference to this registry key ( HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectAccess\OTP\
RadiusProbePass) but the DirectAccess path doesn't exist so I'm assuming it's a Beta thing..
Regards,
Mylo