Solved

Restrict RDP clients

Posted on 2012-03-28
3
764 Views
Last Modified: 2012-04-01
I know that remote desktop services supports SSL and allows clients to authenticate the server identity using SSL certificates.  Is it also possible to restrict what clients can connect to the server through the use of certificates?  That is can I require the client to also provide a certificate to authenticate (in addition to the username and password)?
0
Comment
Question by:scotru
3 Comments
 
LVL 36

Accepted Solution

by:
Jian An Lim earned 150 total points
ID: 37785566
http://www.petri.co.il/securing_rdp_communications.htm
http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/50363d8a-ced2-46e9-9459-8a8aaf9ccd5f/


this is not 2 way certificate.

you might want to look at Remote Desktop Gateway can do for you as well to control tighter on your security.
0
 
LVL 42

Assisted Solution

by:kevinhsieh
kevinhsieh earned 150 total points
ID: 37789060
You can do two factor authentication. PhoneFactor works with RD Gateway, and you can use it for free for up to 25 users. phonefactor.com .

You might be able to use certificates with RD Gateway, just like you would use with IIS, since RD Gateway is build on IIS. That said, I have never used client certificates. I do use PhoneFactor.
0
 

Author Comment

by:scotru
ID: 37794136
Doesn't look like it's possible with just RDP client--maybe through web interface :-(  PhoneFactor looks interesting though.  Thanks for the tip!
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
Know what services you can and cannot, should and should not combine on your server.
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question