Chapter 4: Configuration
Wi-Fi Config: Configure
103
Psion VH10 Vehicle-Mount Computer User Manual
4.27.2.4 EAP
This menu allows you to choose the
EAP
(Extensible Authentication Protocol) type used for 802.1x authen-
tication to an access point.
The following EAP types are supported by
Wi-Fi Config
:
•
TLS:
Provides strong security by the use of client certificates for user authentication.
•
PEAPv0-MSCHAPv2:
Provides secure user authentication by using a TLS tunnel to encrypt EAP traf-
fic.
MSCHAPv2
is used as the inner authentication method. This is appropriate for use against Windows
Active Directory and domains.
•
PEAPv1-GTC:
PEAP authentication using GTC as the inner method which utilizes one time passwords
(OTPs) for authentication against OTP data bases such as SecureID.
•
LEAP:
Is an authentication method for use with Cisco WLAN access points. LEAP does not require the
use of server or client certificates. LEAP supports Windows Active Directory and domains but requires
the use of strong passwords to avoid vulnerability to off-line dictionary attacks.
•
FAST-MSCHAPv2:
Is a successor to LEAP and does not require strong passwords to protect against
off-line dictionary attacks. Like LEAP, EAP-FAST does not require the use of server or client certificates
and supports Windows Active Directory and domains.
•
Complete the fields in the
Configure Profile
screen. If you’re uncertain about some of the options,
your system administrator will be able to provide the correct information for your wireless network.
•
Once you’ve completed the necessary fields, tap on
OK
.
4.27.2.5 Verify Server Certificate
When the
Verify Server Certificate
box is checked, the VH10 will verify the certificate provided by the au-
thentication server during the authentication process. This requires that an appropriate certificate be man-
ually installed on the VH10 for the verification.
4.27.2.6 Enable OPMK
When used with compatible wireless infrastructure, Opportunistic Key Caching (OPMK) reduces the
number of full authentications required when roaming. Only available with WPA2-Enterprise (EAP)
authentication mode.