Click to See Complete Forum and Search --> : Can we specify EAP(802.1x) method with Shared Authentication


Manpreet
08-04-2005, 01:47 AM
Hi All,

Is it a valid case to specify an EAP(802.1x) method with the following combination:-

1) Authentication type : Shared
Encryption type : WEP

PS: This option is available in the Windows Zero Configuration GUI on Windows XP OS.
WZC provides an option to specify EAP(802.1x) Method( PEAP and smartcard) with above combination.

Is the above case as per the specification, If not still is it a valid/possible one.

Any inputs on this issue will be highly appreciated.

Thanks & Regards,
Manpreet

sdandeker
08-10-2005, 07:23 AM
Why do you want to implement shared authentication? Shared Authentication is alot less secure that open authentication since a hacker can easily determine the WEP key due to the way shared authentication uses the WEP key. With Open authentication there is NO authentication (which sound less secure!) but since the WEP comes in afterwards only to encrypt the traffic and it not used to authenticate at the start, it is more secure. So in answer to your question, yes you can do it but It is not a good idea.