Juniper SSL VPN and third party certificates


hello,

i working juniper technicians setting juniper ssl vpn use third party smart card certificates logon vpn. had setup certificate server authentication piece validating certificate presented juniper device. had setup secondary authentication method check active directory account (extracted san field in certificate). found out ad check checking existence of account , not checking whether locked or disabled.

we inserted logic checks following based on user principle name - useraccountcontrol = 512 or 262656 , ms-ds-user-account-control-computed = 0. checking see if account normal account (512) or normal account requires smartcard interactive logon (262656) and check ensure account not locked.

we prefer have full kerberos logon vpn juniper technician not sure how achieve because of hybrid nature of certificates using.

does have ideas of how better authenticate juniper ssl vpn using third party certificates?

thank time , consideration.

vpn authentication in scenario typically done through radius.

if set juniper device use nps server, have radius server base authentication attempt on current state of account.

this require adding third party ca ntauth store in active directory (done through pkiview.msc console)

brian



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...