Juniper SSL VPN and third party certificates
hello,
i working juniper technicians setting juniper ssl vpn use third party smart card certificates logon vpn. had setup certificate server authentication piece validating certificate presented juniper device. had setup secondary authentication method check active directory account (extracted san field in certificate). found out ad check checking existence of account , not checking whether locked or disabled.
we inserted logic checks following based on user principle name - useraccountcontrol = 512 or 262656 , ms-ds-user-account-control-computed = 0. checking see if account normal account (512) or normal account requires smartcard interactive logon (262656) and check ensure account not locked.
we prefer have full kerberos logon vpn juniper technician not sure how achieve because of hybrid nature of certificates using.
does have ideas of how better authenticate juniper ssl vpn using third party certificates?
thank time , consideration.
vpn authentication in scenario typically done through radius.
if set juniper device use nps server, have radius server base authentication attempt on current state of account.
this require adding third party ca ntauth store in active directory (done through pkiview.msc console)
brian
Windows Server > Security
Comments
Post a Comment