Microsoft Windows XP/7

Contents

Get CA Certificate

In order for the server to "trust" certificates generated through pkIRISGrid they must have the Certificate Authority (CA) root certificate installed.

Download the file IRISGridCA.der from Microsoft Internet Explorer and click on “Abrir”.

image01

Click on “Instalar certificado ...”.

image02

Click on “Siguiente”.

image04

Select "Colocar todos los certificados en el siguiente almacén:" option and click on "Examinar".

image05

Click on “Siguiente”.

image06

Click on “Finalizar”.

image07

Click on “”.

image08

Finally, click on “Finalizar”.

image09

Configuring Windows XP supplicant

Go to "Inicio -> Conectar a -> Mostrar todas las conexiones".

image10

Right-click on the “Conexiones de red inalámbricas” and choose “Propiedades”.

image11

Go to "Redes inalámbricas" tab, check "Usar Windows para establecer mi configuración de red inalámbrica", and click on “Agregar”.

image12

Enter "eduroam" for the “Nombre de la red (SSID)”, select “WPA2” for the “Autenticación de red”, select “AES” for “Cifrado de Datos”.

image18j

In the “Autenticación” tab, check “Habilitar la autenticación IEEE 802.1X en esta red” for this network, choose  “EAP protegido (PEAP)” for “Tipo de EAP”, and click on “Propiedades”.

image14

In the “Propiedades protegidas de EAP” window, select “Validar un certificado de servidor”, check  “IRISGridCA” for “Entidades emisoras raíz de confianza”, and choose “Contraseña segura (EAP-MSCHAP v2)” for “Seleccione el método de autenticación”. Then click on “Configurar”.

image15

Finally, in the “Propiedades de EAP MSCHAPv2” window, unselect “Usar automáticamente el nombre de inicio de sesión y la contraseña de Windows (y dominio, si existe alguno).

image17

Configuring Windows 7 supplicant

Go to "Control Panel -> All Control Panel Items -> Network and Sharing Center" and choose "Set up a new connection or network".

image18

Choose "Manually connect to a wireless network" and click on "Next".

image19

Enter "eduroam" for “Network Name” and click on “Next”.

image25

Click on “Change connection settings”.

image26

In the “Security” tab, select “WPA2-Enterprise” for the “Security type”, select “AES” for “Encryption type”,  choose  “EAP protegido (PEAP)” for “Tipo de EAP” and click on “Settings”.

image22

In the “Protected EAP Properties” window, select “Validate server certificate”, check  “IRISGridCA” for “Trusted Root Certification Authorities”, and choose “Secured password (EAP-MSCHAP v2)” for “Select Authentication Method”. Then click on “Configure”.

image23

Finally, in the “EAP MSCHAPv2 Properties” window, unselect “Automatically use my Windows logon name and password (and domain if any).

image24