Receive new posts as email.
RSS 0.91 | RSS 2.0
RDF | Atom
Podcast only feed (RSS 2.0 format)
Get an RSS reader
Get a Podcast receiver
| Sun | Mon | Tues | Wed | Thurs | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 | 31 |
This site operates as an independent editorial operation. Advertising, sponsorships, and other non-editorial materials represent the opinions and messages of their respective origins, and not of the site operator or JiWire, Inc.
Entire site and all contents except otherwise noted © Copyright 2001-2006 by Glenn Fleishman. Some images ©2006 Jupiterimages Corporation. All rights reserved. Please contact us for reprint rights. Linking is, of course, free and encouraged.
Powered by
Movable Type
« Bluetooth Headset Woes Show Limits | Main | The Noisy Cabin: Picocells in Planes »
University of Tennessee switches to 802.1X, but leaves gateway-controlled segment for older systems: The university first tried a proprietary method of authentication in 2002 that left behind users of the latest operating systems (XP and OS X). The latest incarnation uses 802.1X, which is well supported in Windows XP (Service Pack 1 with wireless rollout for best results) and Mac OS X 10.3 (PEAP, EAP-TTLS, EAP-TLS, and other flavors).
Because the university opted for TTLS (the reasoning isn’t explained), it’s not noted but they would have had to install a third-party client on Windows systems. However, TTLS is supported by Funk and Meetinghouse for a wide variety of Windows platforms as well as Solaris and certain Linux flavors.
The non-802.1X segment requires a gateway login and is locked by MAC. The staff use tools to monitor MAC addresses to ensure that legitimate authenticated sessions aren’t being hijacked. It’s clearly a transition stage for them, too, as they can’t have a complete .1X switchover, but they’ll gradually have less reason to run a gatewayed system.
Their current system doesn’t offer session-to-session authentication, but requires re-entering credentials each time a laptop is awoken from sleep. But given the state of .1X clients, this should still be simpler (clicking a button in most cases) than a repeated gateway login.
Posted by Glennf at April 7, 2004 6:27 PM
Categories: Security
TrackBack URL for this entry:
https://db.isbn.nu/mt3/mt-tb.pl/1782
Listed below are links to weblogs that reference University Switches to 802.1X:
» wireless at University of Tennessee from Liudvikas Bukys
Network Computing: University of Tennessee Implements 802.11i (and MAC registration to support legacy machines). [via Wi-Fi Networking News]... [Read More]
Tracked on April 8, 2004 7:26 AM