Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Windows AD client machine certificate authentication?

This thread has been viewed 2 times
  • 1.  Windows AD client machine certificate authentication?

    Posted Oct 10, 2014 04:15 PM

    I've inherited a wireless network (WPA-TKIP) that has an active directory setup with NPS configured.  The machines that are apart of the domain have the CA cert pushed to them via GPO as well the wireless network so they connect automatically using their AD credentials and already accept the internal CA signed server cert.

     

    Unfortunately with this setup anyone can bring in any wiress device and login to the network assuming they have valid AD credentials.  Non-corporate devices won't have the internal CA trusted but it's bypassed by just accepting the cert.

     

    What I've been tasked to do is REQUIRE the machine cert (AFAIK) to be signed by the internal CA for successful authentication to the wireless network. My colleague who asked me to research if this is possible thinks we can't do this because we only have Windows 2008 R2 Standard, (Running at Windows 2003 level if that matters) we can't issue machine certs without Windows 2008 Server Enterpise.  We can't upgrade at the moment to 2012 because we still have some Windows 2003 servers lurking. 

     

    So the questions I have unasnwered are:

     

    1) Is it possible to setup client machine certification authentication with Windows 2008 R2 Standard?

    2) Are there security wholes with this plan?  Do we still need authentication of AD credentials in addition to authentication the client certificate to prevent outside devices from connecting.

     

    Thanks

     

     



  • 2.  RE: Windows AD client machine certificate authentication?

    EMPLOYEE
    Posted Oct 10, 2014 05:54 PM

    1) Yes. In your connection request policy, remove the Protected EAP option leaving only the "Smartcard or other certificate" option.

     

    2) If you're only allowing certificate based authentication from corporate assets, there's nothing else you need to do. From a security standpoint, you should configure the 802.1X settings via Group Policy so end users can't change them.



  • 3.  RE: Windows AD client machine certificate authentication?

    Posted Oct 10, 2014 08:27 PM
    Doesn't the server need to verify that the client cert is signed by the internal CA? Maybe I'm not grasping the idea of the machine cert. I'm not really a Windows Admin. AD isn't my strong suit.


  • 4.  RE: Windows AD client machine certificate authentication?

    EMPLOYEE
    Posted Oct 10, 2014 08:28 PM

    Yes, you would need to issue machine certificates from your ADCS. This can happen automagically via Group Policy.



  • 5.  RE: Windows AD client machine certificate authentication?

    Posted Oct 15, 2014 01:54 PM

    Can this be done without an Enterprise CA though?



  • 6.  RE: Windows AD client machine certificate authentication?

    EMPLOYEE
    Posted Oct 15, 2014 01:55 PM

    Yes, but it would be a manual, painful process.



  • 7.  RE: Windows AD client machine certificate authentication?

    Posted Oct 15, 2014 01:56 PM

    Is there a login script that someone has made to automate this?  We just don't have Windows Server 2008 Enterprise and I doubt we'll get it soon. 

     

     

     



  • 8.  RE: Windows AD client machine certificate authentication?

    EMPLOYEE
    Posted Oct 15, 2014 02:13 PM

    Not that I know of. Maybe someone else has some ideas.



  • 9.  RE: Windows AD client machine certificate authentication?

    Posted Oct 15, 2014 05:04 PM

    A coworker is telling me we can't build an Enterprise CA since we just have Windows Server 2008 R2 Standard.  I'm not finding confirmation of that fact. Can anyone confirm?

     

    Thanks



  • 10.  RE: Windows AD client machine certificate authentication?



  • 11.  RE: Windows AD client machine certificate authentication?

    EMPLOYEE
    Posted Oct 11, 2014 10:56 PM


  • 12.  RE: Windows AD client machine certificate authentication?

    Posted Oct 15, 2014 01:54 PM

    All I see is a blank post, cjoseph.