Terminal Services + IPsec using certificates?

From: Mike (mike_at_nomail.se)
Date: 09/07/04


Date: Tue, 07 Sep 2004 12:11:26 GMT

Hi,
I need to access a few stand alone Win 2000 Servers for admin purposes using
Terminal Services. For security reasons I want to use IPsec to wrap a layer
of security around the servers. I want to do something similar to
http://www.windowsitpro.com/Article/ArticleID/20288/20288.html but instead
of using preshared keys I want to use certificates as authentication option.

I have four servers (Win 2000 Server) I need to be able to connect to using
two different clients (WinXP at home and at work). Using preshared keys this
would be pretty straightforward, but Im not sure exactly how certificates
work in this. Do I generate one certificate for each server and each client,
or how do I go about this?

Since, in the example in the link above, the client sets a rule for all TS
traffic I gather I can only have one certificate per client to be used for
TS traffic? If so, how can I access different TS servers in this way? Is it
possible at all?

I donīt know much about certificates as you see, maybe someone can point me
in the right direction? Any help/input/link is highly appreciated.



Relevant Pages

  • Unable to install certificates and unable to patch
    ... We have three terminal servers that we are not able to install MS ... Timestamping CA" certificates. ... When specify it to put them into the Trusted Root Certificate store I get ...
    (microsoft.public.windows.server.general)
  • Terminal servers missing required certificates
    ... We have three terminal servers that we are not able to install MS ... Timestamping CA" certificates. ... When specify it to put them into the Trusted Root Certificate store I get ...
    (microsoft.public.security)
  • Terminal Services + IPsec using certificates?
    ... I need to access a few stand alone Win 2000 Servers for admin purposes using ... For security reasons I want to use IPsec to wrap a layer ... of using preshared keys I want to use certificates as authentication option. ... Since, in the example in the link above, the client sets a rule for all TS ...
    (microsoft.public.win2000.security)
  • Re: Multiple web hosts and SSL
    ... It is possible to create a "wildcard" cert using the name *.domain.com ... though there may be some limitations on which browsers [or servers?] can use ... packs had problems with wildcard certs, until service pack 1 or later was ... The price is not the same as non-wildcard certificates... ...
    (microsoft.public.inetserver.iis.security)
  • Re: Terminal Services + IPsec using certificates?
    ... protect any data exchanged between client and server. ... have to manually set Encryption level to high. ... If you decide to use certificates for IPSec each computer would get it's own ... > of security around the servers. ...
    (microsoft.public.win2000.security)