So, I'm finally going through the process of provisioning my Windows Server 2016 station (its going to be a VM host, and I'd like to be able to do remote admin stuff) for hardware-based 2FA. My plan is to use a YubiKey as a virtual smartcard (i.e. auth via PIV)
-
Show this thread
-
I figured I'd document the whole process here because hey twitter is great for live-tweet writeups (tweetups?). anyway this will be a several-day thing for sure.
1 reply 0 retweets 6 likesShow this thread -
First thing was verifying that the yubikey even works, and that I could provision it using their GUI tool. Did this on my Arch laptop, and grabbed: https://www.yubico.com/products/services-software/download/yubikey-neo-manager/ … from the AUR. 1 service I forgot to launch later, and yubikey is confirmed functioing.
1 reply 0 retweets 5 likesShow this thread -
Next step is getting windows server 2016 set up for using an alternative authentication method. eventually, I'd like it to be that all RDP logins need my 2FA, but in case of emergency theres a local RDP-disabled admin that only needs 1FA.
1 reply 0 retweets 6 likesShow this thread -
Found this, which seems pretty useful. Documents the setup process for provisioning and verifying a smartcard on windows, I'll probably spin up a separate dummy account on the server for testing this starting tomorrow: https://blogs.msdn.microsoft.com/edutech/certificate-services/configure-server-2012-ca-for-smartcard-authentication/ …
1 reply 0 retweets 6 likesShow this thread -
So, turns out that before I can set up PIV auth, I need to make a Cert Authority. As such, to be 100% safe and careful before fucking with that, I'm provisioning via LetsEncrypt. Turns out windows server has a great tool for doing this: https://github.com/ebekker/ACMESharp/wiki/Quick-Start …
3 replies 0 retweets 4 likesShow this thread
I'm confused. Let's Encrypt gives certificates, not CAs. I assume you need a CA to sign PIV certs, how does LE help you there? Or is this just for unrelated encryption of some network transport?
-
-
Replying to @marcan42
Separate, just want to make sure I don't wind up with weird windows bullshit collisions or w/e that make it hard to set up later. This is my first time doing this specific piece, so I'm trying to be careful and not get myself locked into a corner.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.