Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

RRAS and Computer Certificates for L2TP VPN

Status
Not open for further replies.

beatdown

Technical User
Feb 27, 2005
85
US
I've researched this to death, and have tried every solution I can think of, but still can't figure it out...so hopefully one of you can help me!

We're using RRAS on Windows 2003 Server Standard edition, for remote users to access the network via VPN. Remotes users currently connect using the VPN connection settings built into Windows XP, using the PPTP protocol.

We want to stop using PPTP and start using L2TP. In order to use L2TP, you need to install a computer certificate on the client PC, which is issued by our Enterprise Root Certificate Authority server (also a 2003 Standard server). I've tested this out using a laptop thats part of our domain, and it works great.

The problem, is that our remote users PC's are not part of our domain. So I need to figure out how to install the computer certificate on these remote PC's.

I've tried connecting to the \\server\certsrv page, and going through the motions to request a certificate, but there is no option for Computer Certificates.

I have read that you can request an "Offline VPN certificate"....but this only is an option if your Certificate Authority Server is running the Enterprise Version of Server 2003.

I tried connecting the clients via PPTP VPN, and then using the Certificates MMC console to request a Computer Certificate, but it comes back with an error saying it can't communicate with a CA Server....I assume this is because the PC is not part of the domain. I tried this with a non-domain member laptop here on the office LAN, and got the same results.

Does anyone know if there is a way to make this work, or am I out of luck?

Thanks!
 
Access the CA using IE and then request an Advanced Certificate (I think?), then in the advanced options select to store the certificate in the Computer Store as opposed to the (default) User store.
I have set this up before using non-domain PC's and it works.

HTH

Andy
 
I tried this before and it didn't work for me, but I'll give it another try.

What type of certificate did you request? I know there are a handful of certificate type options in the little drop down window, which are you choosing?

Thanks for your help!
 
I tried this before and it didn't work for me, but I'll give it another try.

What type of certificate did you request? I know there are a handful of certificate type options in the little drop down window, which are you choosing?

Thanks for your help!

I just requested a User Certificate. I seem to recall I also had to copy the CA certificate into the Computer "Trusted Root Certificate Authorities" as well - From the Certificates MMC snap-in (open MMC, add Snap-In and select Certifcates for User and then add it again and select the Local Computer). Open User "Trusted Root Certificate Authorities" and copy your CA certificate into the "Trusted Root Certificate Authorities" on the Computer store.

I don't have access to a remote XP PC at the moment so I can't confirm exactly what I did.....

Andy
 
Andy,

You rock! Thanks for your help on this, it's working perfectly now.

The one step I was missing was that you have to copy the CA Certificate from the User store into the Computer store.

Thanks again!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top