Re: VPN Security, locking out non domain members
- From: "bagins" <dejan /at\ levaja /.\ com>
- Date: Thu, 20 Jul 2006 11:11:06 +0200
You are right, but imho it is a lot better to have computer certificate
authentication (+ user auth, of course), instead of trusting a simple client
side script (w2k3 quarantine control...).
--
************************
Best regards
Bagins
************************
"S. Pidgorny <MVP>" <slavickp@xxxxxxxxx> wrote in message
news:Ok%2379Q9qGHA.5108@xxxxxxxxxxxxxxxxxxxxxxx
If the computer is subsequently joins another domain, the certificate is
still in place. But we can argue that the computer account still has to be
in the right group in the AD to connect. Well, I can modify that system
(or its clone), do whatever - and the account is still in the group
because the system wasn't administratively deleted from the domain.
So the original goal of "domain members only" is suddenly replaced with
"systems based on the legitimate domain members". Which brings up the
whole problem of endpoint security.
I also believe that RAS has to authenticate users, not computers.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
"bagins" <dejan /at\ levaja /.\ com> wrote in message
news:%23OqdBjyqGHA.4032@xxxxxxxxxxxxxxxxxxxxxxx
It does. If you set permissions on cert template only for domain
computers.
--
************************
Best regards
Bagins
************************
"S. Pidgorny <MVP>" <slavickp@xxxxxxxxx> wrote in message
news:%23Tsq7kxqGHA.3248@xxxxxxxxxxxxxxxxxxxxxxx
That doesn't make sure that the computers are members of the domain...
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
"bagins" <dejan /at\ levaja /.\ com> wrote in message
news:Owqr3QrqGHA.1796@xxxxxxxxxxxxxxxxxxxxxxx
You can issue computer certificates to your clients, and use them for
authentication.
.
- References:
- Re: VPN Security, locking out non domain members
- From: bagins
- Re: VPN Security, locking out non domain members
- From: bagins
- Re: VPN Security, locking out non domain members
- Prev by Date: Re: Program White List
- Next by Date: Re: Emailing source code?
- Previous by thread: Re: VPN Security, locking out non domain members
- Next by thread: Re: Open source in the national interest
- Index(es):
Relevant Pages
|