ÓÉÓÚÖ¤Êé¿ÉÌṩ¶ÔÓû§ºÍ¼ÆËã»ú½øÐÐÉí·ÝÑéÖ¤µÄÇ¿´ó°²È«ÐÔ¶øÇÒ¿ÉÏû³ý¶Ô»ùÓÚÃÜÂëµÄ²»Ì«°²È«µÄÉí·ÝÑéÖ¤·½·¨µÄÐèÒª£¬Òò´ËÓÃÓÚÍøÂç·ÃÎÊÉí·ÝÑéÖ¤¡£
ʹÓûùÓÚÖ¤ÊéµÄÉí·ÝÑéÖ¤ÀàÐÍÅäÖõÄÁ½ÖÖÉí·ÝÑéÖ¤·½·¨¾ùʹÓÃÒÔÏÂÖ¤Ê飺EAP ºÍ PEAP¡£Ê¹Óà EAP£¬¿ÉÒÔÅäÖÃÉí·ÝÑéÖ¤ÀàÐÍ TLS (EAP-TLS)£¬¶øÊ¹Óà PEAP£¬¿ÉÒÔÅäÖÃÉí·ÝÑéÖ¤ÀàÐÍ TLS (PEAP-TLS) ºÍ MS-CHAP v2 (PEAP-MS-CHAP v2)¡£ÕâЩÉí·ÝÑéÖ¤·½·¨Ê¼ÖÕʹÓÃÖ¤Êé½øÐзþÎñÆ÷Éí·ÝÑéÖ¤¡£¸ù¾ÝʹÓÃÉí·ÝÑéÖ¤·½·¨ÅäÖõÄÉí·ÝÑéÖ¤ÀàÐÍ£¬Ö¤Ê黹¿ÉÓÃÓÚÓû§Éí·ÝÑéÖ¤ºÍ¿Í»§¶Ë¼ÆËã»úÉí·ÝÑéÖ¤¡£
±¸×¢ ʹÓÃÖ¤Êé¶Ô VPN Á¬½Ó½øÐÐÉí·ÝÑéÖ¤ÊÇ Windows Server? 2008 ÖÐ×îÇ¿´óµÄ¿ÉÓÃÉí·ÝÑéÖ¤ÐÎʽ¡£±ØÐë¸ù¾Ý²ÉÓà Internet ÐÒ鰲ȫµÄµÚ¶þ²ãËíµÀÐÒé (L2TP/IPsec) ¶Ô VPN Á¬½ÓʹÓûùÓÚÖ¤ÊéµÄÉí·ÝÑéÖ¤¡£Ê¹Óà EAP-TLS ×÷ΪÉí·ÝÑéÖ¤·½·¨Ê±£¬ËäÈ»Äú¿ÉÒÔ½« PPTP Á¬½ÓÅäÖÃΪʹÓÃÖ¤Êé½øÐмÆËã»úÉí·ÝÑéÖ¤£¬µ«µã¶ÔµãËíµÀÐÒé (PPTP) Á¬½Ó²»ÐèÒªÖ¤Êé¡£¶ÔÓÚÎÞÏ߿ͻ§¶Ë£¬´ø EAP-TLS ÒÔ¼°ÖÇÄÜ¿¨»òÖ¤ÊéµÄ PEAP Êǽ¨ÒéµÄÉí·ÝÑéÖ¤·½·¨¡£ ͨ¹ý°²×°ºÍÅäÖà Active Directory Ö¤Êé·þÎñ·þÎñÆ÷½ÇÉ«£¬¿ÉÒÔ²¿ÊðÓë NPS һͬʹÓõÄÖ¤Êé¡£ÓйØÏêϸÐÅÏ¢£¬Çë²ÎÔÄ AD CS Îĵµ¡£
Ö¤ÊéÀàÐÍ
ʹÓûùÓÚÖ¤ÊéµÄÉí·ÝÑéÖ¤·½·¨Ê±£¬Á˽âÒÔÏÂÀàÐ͵ÄÖ¤Êé¼°ÆäʹÓ÷½Ê½·Ç³£ÖØÒª¡£
?
CA Ö¤Êé
Èç¹ûÖ¤ÊéλÓÚ¿Í»§¶ËºÍ·þÎñÆ÷¼ÆËã»úÉÏ£¬ÔòÏò¿Í»§¶Ë»ò·þÎñÆ÷±íÃ÷Ëü¿ÉÒÔÐÅÈÎÆäËûÖ¤Ê飬ÈçÓÃÓÚ¿Í»§¶Ë»ò·þÎñÆ÷Éí·ÝÑéÖ¤µÄÖ¤Ê飨ÓÉ´Ë CA °ä·¢£©¡£´ËÖ¤ÊéÊÇ»ùÓÚÖ¤ÊéµÄÉí·ÝÑéÖ¤·½·¨µÄËùÓв¿ÊðËù±ØÐèµÄ¡£
?
¿Í»§¶Ë¼ÆËã»úÖ¤Êé
ÓÉ CA °ä·¢¸ø¿Í»§¶Ë¼ÆËã»úÇÒÔÚ¿Í»§¶Ë¼ÆËã»úÔÚÉí·ÝÑéÖ¤¹ý³ÌÖÐÐèÒªÏòÔËÐÐ NPS µÄ·þÎñÆ÷Ö¤Ã÷ÆäÉí·ÝʱʹÓá£
?
·þÎñÆ÷Ö¤Êé
ÓÉ CA °ä·¢¸ø NPS ·þÎñÆ÷ÇÒÔÚ NPS ·þÎñÆ÷ÔÚÉí·ÝÑéÖ¤¹ý³ÌÖÐÐèÒªÏò¿Í»§¶Ë¼ÆËã»úÖ¤Ã÷ÆäÉí·ÝʱʹÓá£
?
Óû§Ö¤Êé
ÓÉ CA °ä·¢¸ø¸öÈËÇÒͨ³£×÷ΪÖÇÄÜ¿¨ÖÐǶÈëµÄÖ¤Êé½øÐзַ¢¡£µ±¸öÈËÔÚÉí·ÝÑéÖ¤¹ý³ÌÖÐÐèÒªÏò NPS ·þÎñÆ÷Ö¤Ã÷ÆäÉí·Ýʱ£¬»á½«ÖÇÄÜ¿¨ÉϵÄÖ¤ÊéÓëÁ¬½Óµ½¿Í»§¶Ë¼ÆËã»úµÄÖÇÄÜ¿¨¶Á¿¨Æ÷һͬʹÓá£
»ùÓÚÖ¤ÊéµÄÉí·ÝÑéÖ¤·½·¨
ʹÓÃÇ¿ EAP ÀàÐ굀 EAP£¨Èç´øÓÐÖÇÄÜ¿¨»òÖ¤ÊéµÄ TLS£©Ê±£¬¿Í»§¶ËºÍ·þÎñÆ÷¶¼Ê¹ÓÃÖ¤ÊéÏ໥½øÐÐÉí·ÝÑéÖ¤¡£´Ë¹ý³Ì³ÆÎªÏ໥Éí·ÝÑéÖ¤¡£Ö¤Ê鱨ÐëÂú×ãijЩҪÇ󣬲ÅÔÊÐí·þÎñÆ÷ºÍ¿Í»§¶ËʹÓÃËüÃǽøÐÐÏ໥Éí·ÝÑéÖ¤¡£
ÕâÀàÒªÇóÖ®Ò»¾ÍÊÇ£¬Ö¤ÊéÊÇʹÓÃÓëÖ¤ÊéʹÓùØÁªµÄ EKU À©Õ¹ÖеÄÒ»¸ö»ò¶à¸öÄ¿µÄÀ´ÅäÖõġ£ÀýÈ磬¿Í»§¶Ë¶Ô·þÎñÆ÷½øÐÐÉí·ÝÑé֤ʱËùʹÓõÄÖ¤Ê鱨ÐëÊÇʹÓá°¿Í»§¶ËÉí·ÝÑéÖ¤¡±Ä¿µÄÀ´ÅäÖõġ£Í¬Ñù£¬ÓÃÓÚ·þÎñÆ÷Éí·ÝÑéÖ¤µÄÖ¤Ê鱨ÐëÊÇʹÓá°·þÎñÆ÷Éí·ÝÑéÖ¤¡±Ä¿µÄÀ´ÅäÖõġ£Ê¹ÓÃÖ¤Êé½øÐÐÉí·ÝÑé֤ʱ£¬Éí·ÝÑéÖ¤Æ÷½«¼ì²é¿Í»§¶ËÖ¤Ê飬ÒÔÔÚ EKU À©Õ¹ÖÐѰÕÒÕýÈ·Ä¿µÄµÄ¶ÔÏó±êʶ·û¡£ÀýÈ磬ÓÃÓÚ¿Í»§¶ËÉí·ÝÑé֤ĿµÄµÄ¶ÔÏó±êʶ·ûΪ 1.3.6.1.5.5.7.3.2¡£Ê¹ÓÃÖ¤Êé½øÐпͻ§¶Ë¼ÆËã»úÉí·ÝÑé֤ʱ£¬´Ë¶ÔÏó±êʶ·û±ØÐë´æÔÚÓÚÖ¤ÊéµÄ EKU À©Õ¹ÖУ¬·ñÔòÉí·ÝÑéÖ¤½«»áʧ°Ü¡£
Ö¤ÊéÄ£°åÊÇÒ»¸ö Microsoft ¹ÜÀí¿ØÖÆÌ¨ (MMC) ¹ÜÀíµ¥Ôª£¬¿ÉÓÃÓÚ¶Ô AD CS °ä·¢µÄÖ¤Êé½øÐÐ×Ô¶¨Òå¡£×Ô¶¨Òå¿ÉÄÜÐÔ°üÀ¨ÈçºÎ°ä·¢Ö¤ÊéÒÔ¼°Ö¤Êé°üº¬ÄÄЩÄÚÈÝ£¨°üÀ¨ÆäÄ¿µÄ£©¡£ÔÚÖ¤ÊéÄ£°åÖУ¬¿ÉÒÔʹÓÃĬÈÏÄ£°å£¨Èç¼ÆËã»úÄ£°å£©À´¶¨Òå CA Ϊ¼ÆËã»ú·ÖÅäÖ¤ÊéʱËùʹÓõÄÄ£°å¡£Äú»¹¿ÉÒÔ´´½¨Ö¤ÊéÄ£°å£¬²¢ÎªÖ¤Êé·ÖÅä EKU À©Õ¹ÖеÄÄ¿µÄ¡£Ä¬ÈÏÇé¿öÏ£¬¼ÆËã»úÄ£°å°üÀ¨ EKU À©Õ¹Öеġ°¿Í»§¶ËÉí·ÝÑéÖ¤¡±Ä¿µÄºÍ¡°·þÎñÆ÷Éí·ÝÑéÖ¤¡±Ä¿µÄ¡£
´´½¨µÄÖ¤ÊéÄ£°å¿ÉÒÔ°üÀ¨½«Ö¤ÊéÓÃÓÚµÄÈκÎÄ¿µÄ¡£ÀýÈ磬Èç¹ûʹÓÃÖÇÄÜ¿¨½øÐÐÉí·ÝÑéÖ¤£¬Ôò³ýÁË¡°¿Í»§¶ËÉí·ÝÑéÖ¤¡±Ä¿µÄÒÔÍ⣬»¹¿ÉÒÔ°üÀ¨¡°ÖÇÄÜ¿¨µÇ¼¡±Ä¿µÄ¡£Äú¿ÉÒÔ½« NPS ÅäÖÃΪÔÚÊÚÓèÍøÂçȨÏÞ֮ǰ¶ÔÖ¤ÊéÄ¿µÄ½øÐмì²é¡£NPS ¿ÉÒÔ¼ì²éÆäËûµÄ EKU ºÍ°ä·¢²ßÂÔÄ¿µÄ£¨Ò²³ÆÎªÖ¤Êé²ßÂÔ£©¡£
±¸×¢ ÓÐЩ·Ç Microsoft CA Èí¼þ¿ÉÄܰüº¬ËùνµÄ¡°È«²¿¡±Ä¿µÄ£¬±íʾËùÓпÉÄܵÄÄ¿µÄ¡£ÕâÓÉÒ»¸ö¿Õ°×µÄ£¨»ò¿Õ£©EKU À©Õ¹±íʾ¡£¾¡¹Ü¡°È«²¿¡±Ö¼ÔÚ±íʾ¡°ËùÓпÉÄܵÄÄ¿µÄ¡±£¬µ«²»Äܽ«¡°È«²¿¡±Ä¿µÄÌæ»»Îª¡°¿Í»§¶ËÉí·ÝÑéÖ¤¡±Ä¿µÄ¡¢¡°·þÎñÆ÷Éí·ÝÑéÖ¤¡±Ä¿µÄ£¬»òÓëÍøÂç·ÃÎÊÉí·ÝÑéÖ¤ÓйصÄÈÎºÎÆäËûÄ¿µÄ¡£ Á˽âʹÓÃÖ¤ÊéµÄÉí·ÝÑéÖ¤
½«Ö¤Êé×÷ΪÉí·ÝÖ¤Ã÷Ìṩ¸ø¿Í»§¶Ë»ò·þÎñÆ÷¼ÆËã»úʱ£¬Éí·ÝÑéÖ¤Æ÷±ØÐë¼ì²é¸ÃÖ¤ÊéÒÔÈ·¶¨ÆäÓÐЧÐÔ£¨ÎÞÂÛ³öÓÚºÎÖÖÄ¿µÄ½øÐÐÅäÖã©£¬²¢Á˽âÖ¤ÊéÊÇ·ñÓÉÉí·ÝÑéÖ¤Æ÷ËùÐÅÈ뵀 CA °ä·¢¡£
¼ÙÉèÖ¤ÊéµÄÅäÖÃÕýÈ·ÇÒÓÐЧ£¬Éí·ÝÑéÖ¤¹ý³Ì×îÖØÒªµÄ·½Ãæ¾ÍÊÇͨ¹ýÉí·ÝÑéÖ¤Æ÷¼ì²éËüÊÇ·ñÐÅÈΰ䷢֤ÊéµÄ CA¡£ Èç¹ûÉí·ÝÑéÖ¤Æ÷ÐÅÈÎ CA£¬¶øÇÒÖ¤ÊéÓÐЧÇÒ°´ÕÕ×îµÍµÄ¿Í»§¶ËºÍ·þÎñÆ÷Ö¤ÊéÒªÇóÕýÈ·½øÐÐÁËÅäÖã¬ÔòÉí·ÝÑéÖ¤½«³É¹¦¡£Èç¹ûÉí·ÝÑéÖ¤Æ÷²»ÐÅÈÎ CA£¬ÔòÉí·ÝÑéÖ¤½«Ê§°Ü¡£
ÈçºÎ½¨Á¢ÐÅÈÎ
»ùÓÚ Windows µÄ¼ÆËã»ú½«Ö¤Êé±£ÁôÔÚ±¾µØ¼ÆËã»úÉϵÄÖ¤Êé´æ´¢ÇøÖС£´æÔÚרÃÅΪ±¾µØ¼ÆËã»ú¡¢µ±Ç°Óû§ºÍ¸÷¸ö·þÎñ£¨ÈçÍøÂçÁ¬½Ó¡¢×Ô¶¯¸üкͼÆËã»úä¯ÀÀÆ÷£©ÉèÖõÄÖ¤Êé´æ´¢Çø¡£ÔÚÿ¸öÖ¤Êé´æ´¢ÇøÖж¼ÓÐÃûΪ¡°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±µÄÎļþ¼Ð£¬ÆäÖаüº¬À´×ÔÊÜÐÅÈεÄÿ¸ö CA µÄÖ¤Ê飬ÎÞÂÛËüÃÇÊǹ«¹²µÄ»¹ÊÇרÓÃµÄ CA¡£
ΪÁËÈ·¶¨ÐÅÈΣ¬Éí·ÝÑéÖ¤Æ÷½«Õë¶Ôµ±Ç°Óû§»ò±¾µØ¼ÆËã»ú¼ì²é¡°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢Çø¡£
Èç¹û°ä·¢ÓÃÓÚÉí·ÝÑéÖ¤µÄ¿Í»§¶Ë¡¢Óû§»ò·þÎñÆ÷Ö¤ÊéµÄ CA ÔÚ±¾µØ¼ÆËã»úÉϵġ°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖоßÓÐÖ¤Ê飬ÔòÉí·ÝÑéÖ¤Æ÷½«ÐÅÈÎÖ¤Êé¡£Èç¹û°ä·¢Ö¤ÊéµÄ CA ÔÚ±¾µØ¼ÆËã»úÉϵġ°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖÐûÓÐ CA Ö¤Ê飬ÔòÉí·ÝÑéÖ¤Æ÷²»ÐÅÈÎÖ¤Êé¡£
ÖØÒªÊÂÏî CA Ö¤Ê鱨Ðë´æÔÚÓÚ±¾µØ¼ÆËã»ú£¨ÎÞÂÛ¼ÆËã»úΪ¿Í»§¶Ë»¹ÊÇ·þÎñÆ÷£©Éϵġ°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖУ¬ÓÉ CA °ä·¢µÄÆäËûÖ¤Êé²Å»áµÃµ½ÐÅÈΡ£ ¹«¹² CA
ĬÈÏÇé¿öÏ£¬Ä³Ð©ÊÜÐÅÈεĸù CA Ö¤Ê飨Óɹ«¹²µÄÊÜÐÅÈθùÖ¤Êé°ä·¢»ú¹¹°ä·¢£©°üÀ¨ÔÚ Windows µÄËùÓа²×°ÖУ»ËüÃǰüÀ¨ÔÚ²úÆ·°²×°¹âÅÌÖлò´æÔÚÓÚÓÉÌṩ°²×°ÁË Windows µÄ¼ÆËã»úµÄÔʼÉè±¸ÖÆÔìÉÌ (OEM) ³öÊ۵ļÆËã»úÖС£ ÀýÈ磬λÓÚÔËÐÐ Windows XP µÄ¼ÆËã»úÉϵÄÖ¤Êé´æ´¢ÇøÖеġ°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Îļþ¼ÐÖУ¬´æÔÚÀ´×Ô Verisign Trust Network CA¡¢Thawte Premium Server CA ºÍ Microsoft ¸ùÖ¤Êé°ä·¢»ú¹¹µÄ CA Ö¤Êé¡£Èç¹ûÔËÐÐ Windows XP µÄ¼ÆËã»úÖдæÔÚÓÉÉÏÊöij¸ö CA °ä·¢µÄÖ¤ÊéºÍÕýÈ·ÅäÖÃÇÒÓÐЧµÄÖ¤Ê飬ÔòÔËÐÐ Windows XP µÄ¼ÆËã»úÐÅÈθÃÖ¤Êé¡£
¿ÉÒÔ´ÓÐí¶à¹«Ë¾£¨Èç Verisign ºÍ Thawte£©¹ºÂòÒªÔÚÉí·ÝÑéÖ¤»ù´¡½á¹¹ÖÐʹÓÃµÄÆäËûÖ¤Êé¡£ÀýÈ磬²¿Êð PEAP-MS-CHAP v2 ÇÒÔÚ¿Í»§¶ËÉÏÆôÓá°ÑéÖ¤·þÎñÆ÷Ö¤Ê顱ÉèÖÃʱ£¬¿Í»§¶Ë¼ÆËã»ú½«Ê¹Óà NPS ·þÎñÆ÷Ö¤Êé¶Ô NPS ·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤¡£Èç¹û²»Ï벿ÊðÄú×Ô¼ºµÄ CA ²¢½«Äú×Ô¼ºµÄ·þÎñÆ÷Ö¤Êé°ä·¢¸ø NPS ·þÎñÆ÷£¬Ôò¿ÉÒÔ´ÓÆä CA ÒÑÊܵ½¿Í»§¶Ë¼ÆËã»úÐÅÈεĹ«Ë¾¹ºÂò·þÎñÆ÷Ö¤Êé¡£
רÓà CA
µ±×éÖ¯²¿ÊðÆä¸÷×ԵĹ«Ô¿»ù´¡½á¹¹ (PKI) ²¢°²×°×¨ÓõÄÊÜÐÅÈθù CA ʱ£¬Æä CA »á½«ÆäÖ¤Êé×Ô¶¯·¢Ë͸ø×éÖ¯ÖеÄËùÓÐÓò³ÉÔ±¼ÆËã»ú¡£Óò³ÉÔ±¿Í»§¶ËºÍ·þÎñÆ÷¼ÆËã»ú½« CA Ö¤Êé´æ´¢ÔÚ¡°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖС£³öÏÖÕâÖÖÇé¿öºó£¬Óò³ÉÔ±¼ÆËã»ú½«ÐÅÈÎ×éÖ¯µÄÊÜÐÅÈθù CA °ä·¢µÄÖ¤Êé¡£
ÀýÈ磬Èç¹ûÄú°²×°ÁË AD CS£¬Ôò CA »á½«ÆäÖ¤Êé·¢Ë͸ø×éÖ¯ÖеÄÓò³ÉÔ±¼ÆËã»ú£¬²¢ÇÒËüÃǽ« CA Ö¤Êé´æ´¢ÔÚ±¾µØ¼ÆËã»úÉϵġ°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖС£Èç¹ûÄú»¹Îª NPS ·þÎñÆ÷ÅäÖò¢×Ô¶¯×¢²áÁË·þÎñÆ÷Ö¤Ê飬ȻºóÓÉΪÎÞÏßÁ¬½Ó²¿ÊðÁË PEAP-MS-CHAP v2£¬ÔòËùÓеÄÓò³ÉÔ±ÎÞÏ߿ͻ§¶Ë¼ÆËã»ú¶¼¿ÉÒÔʹÓà NPS ·þÎñÆ÷Ö¤Êé³É¹¦µØ¶Ô NPS ·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤£¬ÒòΪËüÃÇÐÅÈΰ䷢ NPS ·þÎñÆ÷Ö¤ÊéµÄ CA¡£
±¸×¢ ·ÇÓò³ÉÔ±¼ÆËã»ú±ØÐëÔÚ¡°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖÐÊÖ¶¯°²×°×¨ÓÃµÄ CA Ö¤Êé²Å»áÐÅÈÎרÓà CA °ä·¢µÄÖ¤Ê飬Èç NPS ·þÎñÆ÷Ö¤Êé¡£ ËùÐèµÄÖ¤Êé
ϱí±êʶÁ˳ɹ¦²¿ÊðÿÖÖ»ùÓÚÖ¤ÊéµÄÉí·ÝÑéÖ¤·½·¨ËùÐèµÄÖ¤Êé¡£
¶ÔÓÚ EAP-TLS ºÍ PEAP-TLS ¶ÔÓÚ PEAP-MS-CHAP v2 Ö¤Êé ÊÇ·ñÊDZØÐèµÄ£¿ ÊÇ·ñÊDZØÐèµÄ£¿ ÏêϸÐÅÏ¢ ±¾µØ¼ÆËã»úÊÇ¡£ÏµÍ³½«ÎªÓò³ÉÔ±¼ÆËã»ú×Ô¶¯ÊÇ¡£ÏµÍ³½«ÎªÓò³ÉÔ±¼ÆËã»ú×Ô¶ÔÓÚ PEAP-MS-CHAP v2£¬ºÍµ±Ç°Óû§µÄ¡°ÊÜÐÅÈεĸùÖ¤Êé°ä·¢»ú¹¹¡±Ö¤Êé´æ´¢ÇøÖÐµÄ CA Ö¤Êé¡£ ¿Í»§¶ËµÄÖ¤Êé´æ´¢ÇøÖеĿͻ§¶Ë¼ÆËã»úÖ¤Êé¡£ ×¢²á CA Ö¤Êé¡£¶ÔÓÚ·ÇÓò³ÉÔ±¼ÆËã»ú£¬±ØÐ뽫֤ÊéÊÖ¶¯µ¼ÈëÖ¤Êé´æ´¢ÇøÖС£ ¶¯×¢²á´ËÖ¤Êé¡£¶ÔÓÚ·ÇÓò³ÉÔ±¼ÆËã»ú£¬±ØÐ뽫֤ÊéÊÖ¶¯µ¼ÈëÖ¤Êé´æ´¢ÇøÖС£ ´ËÖ¤ÊéÊÇÔÚ¿Í»§¶ËÓë·þÎñÆ÷Ö®¼ä½øÐÐÏ໥Éí·ÝÑéÖ¤Ëù±ØÐèµÄ¡£ ÊÇ¡£¿Í»§¶Ë¼ÆËã»úÖ¤ÊéÊDZØÐèµÄ£¬·ñ¡£Ê¹ÓûùÓÚÃÜÂëµÄƾ¾Ý£¨¶ø³ý·ÇÒÑÔÚÖÇÄÜ¿¨ÉÏ·Ö·¢ÁËÓû§Ö¤Ê顣ϵͳ½«ÎªÓò³ÉÔ±¼ÆËã»ú×Ô¶¯×¢²á¿Í»§¶ËÖ¤Êé¡£¶ÔÓÚ·ÇÓò³ÉÔ±¼ÆËã»ú£¬±ØÐëÊÖ¶¯µ¼Èë¸ÃÖ¤Êé»òʹÓà Web ×¢²á¹¤¾ß»ñÈ¡¸ÃÖ¤Êé¡£ ²»ÊÇÖ¤Ê飩À´Ö´ÐÐÓû§Éí·ÝÑéÖ¤¡£ Èç¹ûÔÚÖÇÄÜ¿¨Éϲ¿ÊðÓû§Ö¤Ê飬Ôò¿Í»§¶Ë¼ÆËã»ú²»ÐèÒª¿Í»§¶ËÖ¤Êé¡£ NPS ·þÎñÆ÷µÄÖ¤Êé´æ´¢ÇøÖеķþÎñÆ÷Ö¤Êé¡£ ÊÇ¡£¿ÉÒÔÅäÖà AD CS£¬ÒÔ±ãΪ Active Directory Óò·þÎñ (AD DS) ÖÐµÄ RAS ºÍ IAS ·þÎñÆ÷×éµÄ³ÉÔ±×Ô¶¯×¢²á·þÎñÆ÷Ö¤Êé¡£ ÊÇ¡£³ýÁ˶ԷþÎñÆ÷Ö¤ÊéʹÓà AD CS ÒÔÍ⣬»¹¿ÉÒÔ´Ó¿Í»§¶Ë¼ÆËã»úÒÑÐÅÈÎµÄÆäËû CA ´¦¹ºÂò·þÎñÆ÷Ö¤Êé¡£ NPS ·þÎñÆ÷»á½«·þÎñÆ÷Ö¤Êé·¢Ë͸ø¿Í»§¶Ë¼ÆËã»ú£»¿Í»§¶Ë¼ÆËã»ú½«Ê¹ÓøÃÖ¤Êé¶Ô NPS ·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤¡£ ÖÇÄÜ¿¨ÉϵÄÓû§Ö¤Êé¡£ ·ñ¡£Ö»Óе±ÄúÑ¡Ôñ²¿ÊðÖÇÄÜ¿¨¶ø²»×Ô¶¯×¢²á¿Í»§¶Ë¼ÆËã»úÖ¤Êéʱ£¬´ËÖ¤Êé²ÅÊDZØÐèµÄ¡£ ·ñ¡£Ê¹ÓûùÓÚÃÜÂëµÄƾ¾Ý£¨¶ø²»ÊÇÖ¤Ê飩À´Ö´ÐÐÓû§Éí·ÝÑéÖ¤¡£ ¶ÔÓÚ EAP-TLS ºÍ PEAP-TLS£¬Èç¹ûÄúûÓÐ×Ô¶¯×¢²á¿Í»§¶Ë¼ÆËã»úÖ¤Ê飬ÔòÖÇÄÜ¿¨ÉϵÄÓû§Ö¤Êé¾ÍÊDZØÐèµÄ¡£ ÖØÒªÊÂÏî IEEE 802.1x Éí·ÝÑéÖ¤¶Ô 802.11 ÎÞÏßÍøÂçºÍÓÐÏßÒÔÌ«ÍøÍøÂçÌṩÁ˾¹ýÑéÖ¤µÄ·ÃÎÊȨÏÞ¡£802.1X ¶Ô°²È«µÄ EAP ÀàÐÍ£¨Èç´øÓÐÖÇÄÜ¿¨»òÖ¤ÊéµÄ TLS£©Ìṩ֧³Ö¡£¿ÉÒÔ²ÉÓöàÖÖ·½Ê½Ê¹Óà EAP-TLS À´ÅäÖà 802.1X¡£Èç¹ûÔÚ¿Í»§¶ËÉÏÅäÖÃÁË¡°ÑéÖ¤·þÎñÆ÷Ö¤Ê顱ѡÏÔò¿Í»§¶Ë½«Ê¹ÓÃÆäÖ¤Êé¶Ô·þÎñÆ÷½øÐÐÉí·ÝÑéÖ¤¡£¿ÉÒÔʹÓÿͻ§¶ËÖ¤Êé´æ´¢»òÖÇÄÜ¿¨ÖеÄÖ¤Ê飨ÌṩÏ໥Éí·ÝÑéÖ¤£©À´Íê³É¿Í»§¶Ë¼ÆËã»úºÍÓû§Éí·ÝÑéÖ¤¡£½èÖúÎÞÏ߿ͻ§¶Ë£¬¿ÉÒÔʹÓà PEAP-MS-CHAP v2 ×÷ΪÉí·ÝÑéÖ¤·½·¨¡£PEAP-MS-CHAP v2 ÊǽáºÏʹÓà TLS ºÍ·þÎñÆ÷Ö¤ÊéµÄ»ùÓÚÃÜÂëµÄÓû§Éí·ÝÑéÖ¤·½·¨¡£ÔÚÖ´ÐÐ PEAP-MS-CHAP v2 Éí·ÝÑéÖ¤ÆÚ¼ä£¬IAS »ò RADIUS ·þÎñÆ÷½«ÌṩÓÃÓÚÏò¿Í»§¶ËÑéÖ¤ÆäÉí·ÝµÄÖ¤Ê飨Èç¹ûÔÚ Windows Vista? ºÍ Windows XP Professional ¿Í»§¶ËÉÏÅäÖÃÁË¡°ÑéÖ¤·þÎñÆ÷Ö¤Ê顱ѡÏ¡£¿Í»§¶Ë¼ÆËã»úºÍÓû§Éí·ÝÑéÖ¤ÊÇʹÓÃÃÜÂëÍê³ÉµÄ£¬ÕâÏû³ýÁËΪÎÞÏ߿ͻ§¶Ë¼ÆËã»ú²¿ÊðÖ¤ÊéʱµÄһЩÀ§ÄÑ¡£ ÏòÓòºÍ·ÇÓò³ÉÔ±¼ÆËã»ú×¢²áÖ¤Êé
ҪΪÆä×¢²áÖ¤ÊéµÄ¼ÆËã»úµÄÓò³ÉÔ±Éí·Ý»áÓ°Ïì¿ÉÒÔÑ¡ÔñµÄÖ¤Êé×¢²á·½·¨¡£¿ÉÒÔ×Ô¶¯×¢²áÓò³ÉÔ±¼ÆËã»úµÄÖ¤Ê飬µ«¹ÜÀíÔ±±ØÐëʹÓà AD CS Web ×¢²á¹¤¾ß»òÈíÅÌ»ò¹âÅÌÀ´Îª·ÇÓò³ÉÔ±¼ÆËã»ú×¢²áÖ¤Êé¡£
Óò³ÉÔ±Ö¤Êé×¢²á
Èç¹ûÄúµÄ VPN ·þÎñÆ÷¡¢NPS ·þÎñÆ÷»òÔËÐÐ Windows 2000¡¢Windows XP »ò Windows Vista µÄ¿Í»§¶ËÊÇÔËÐÐ