RE: Secure / Encrypt Terminal Services

From: David Vincent (david.vincent@mightyoaks.com)
Date: 11/26/02

  • Next message: Miguel Duarte: "RE: Exchange in the DMZ"
    From: David Vincent <david.vincent@mightyoaks.com>
    To: "'ohnonono@hushmail.com'" <ohnonono@hushmail.com>, focus-ms@securityfocus.com
    Date: Mon, 25 Nov 2002 20:03:48 -0800
    
    

    it has built-in encryption configurable up to 128bit both ways. only issue
    i've encountered is at the 128bit or "high" encryption level is then my
    pocket pc clients cannot connect - they only support 40bit or "medium"
    encryption.

    check the "terminal services configuration" snap-in when you put "mmc" in a
    "run:" dialog from the "start" menu.

    i suppose you could use ipsec policies from active-directory and get l2tp
    going, or you could also go grab openssh for windows at
    http://www.networksimplicity.com/openssh/, or even Zebedee available here:
    http://www.winton.org.uk/zebedee/.

    -d

    -----Original Message-----
    From: ohnonono@hushmail.com [mailto:ohnonono@hushmail.com]
    Sent: Thursday, November 21, 2002 6:22 AM
    To: focus-ms@securityfocus.com
    Subject: Secure / Encrypt Terminal Services

    -----BEGIN PGP SIGNED MESSAGE-----

    Does the community have an opinion on which is the best way to do this? Can
    it be done via IP-Sec? Basically we have a machine (tripwire manager) that
    will have access to all our networks. Due to politics (gotta love security
    made insecure by politics) it must be remotely managed. The CIO (god bless
    CIO's) has decided that we will use terminal services. Is there a way to
    encrypt the traffic so it is not flying around the network in clear text?
    Would IP-Sec be the recomended solution?

    Suggestions or links (or gentle shoves) to the information would be great.

    Thanks

    -----BEGIN PGP SIGNATURE-----
    Version: Hush 2.2 (Java)
    Note: This signature can be verified at https://www.hushtools.com/verify

    wl0EARECAB0FAj3c67gWHG9obm9ub25vQGh1c2htYWlsLmNvbQAKCRAuXN+1lPsfqYk9
    AJ4ndm/CgplNAjJHfTV5oSgPLfoYYwCfYUHT6Cta9Or1jTiu4KGfYokrjYg=
    =2bx1
    -----END PGP SIGNATURE-----

    Get your free encrypted email at https://www.hushmail.com



    Relevant Pages

    • RE: Secure / Encrypt Terminal Services
      ... Basically we have a machine (tripwire manager) that ... will have access to all our networks. ... made insecure by politics) it must be remotely managed. ... Would IP-Sec be the recomended solution? ...
      (Focus-Microsoft)
    • Re: WiFi connections and management - Hotspots and Home LANs
      ... networks you connect to use DHCP. ... network without encryption, try to open any web page and the browser is "hijacked" and directed to a login page Then your MAC address is recorded and granted access for whatever time period you purchase. ... As far as being structured words, they can be if you stick to words comprised of only the letters A thru E! ...
      (microsoft.public.pocketpc)
    • Re: WiFi connections and management - Hotspots and Home LANs
      ... networks you connect to use DHCP. ... Setting encryption must ... the passphrase for the encryption system. ...
      (microsoft.public.pocketpc)
    • Re: Legality & security of wireless networks
      ... Umm, you do need to enable WPA on *both* ends of the link, the list of available networks shows the status of the router/access point, not your local wireless card in the machine you're using. ... When the router has encryption set, then it will tell you it's encrypted and the type of encryption in use, clicking on the network you're trying to connect to should bring up a pas word/encryption key request if you've not entered the key before or you've disconnected from the router manually. ...
      (uk.telecom.broadband)
    • [opensuse] Configuring WiFi on ThinkPad R31 & SUSE 10.2
      ... I am trying to configure the WiFi interface, using KWiFiManager in SUSE ... networks, but not my home network, which is encrypted, even though ... encryption and keys are specified in KWiFiManager. ... encryption in Yast, I can connect to my home network, but no longer ...
      (SuSE)