Community discussions

MikroTik App
 
marting
Member Candidate
Member Candidate
Topic Author
Posts: 172
Joined: Thu Aug 21, 2014 2:07 pm

IKEv2 with Windows: Required to import user cert to local computer (instead of user cert store)?

Fri Aug 25, 2017 3:07 pm

Hi,
I tried the "quite" new IKEv2 feature in ROS. I followed this guide https://wiki.mikrotik.com/wiki/Manual:I ... 2_RSA_auth and it works great if I import the genereated pfx cert to local computers cert store. It does not work (windows claims it cannot find IKE computer cert during connect) if I store it to users store.
I know this problem is not MikroTik related, but I wonder what´s best practice for this.
After importing it to local computer, every user of the computer can use it to authorize to the VPN server. In windows VPN client I can select "Use machine certificates" but not "Use user certificates".
I guess usually you would do two way auth with EAP (cert and userlogin data) but as mentioned in the wiki, EAP is not implemtened at the moment (although there is EAP Radius in the peer config).
So what do you suggest how to use it best way?
Best Regards
Martin
 
krwi
just joined
Posts: 9
Joined: Mon Aug 21, 2017 3:49 pm

Re: IKEv2 with Windows: Required to import user cert to local computer (instead of user cert store)?

Fri Aug 25, 2017 6:18 pm

EAP with radius is implemented and working only with cert installed in User Store (in this mode Windows searching for certificate only in user store).