Re: Guide for Secure communication between client and TS

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Worried about secure communication between the server and the clients. Want
to avoid DoS attacks, dictionary password cracking as well as man in the
middle scenarios.

MITM attacks can only be prevented by the SSL/TLS mode. Native RDP encryption modes are vulnerable to MITM.

As it stands the Encryption level (in RDP-TCP properties) is set to “Client
Compatible”.
Will setting the encryption level to high be enough to be safe? It is 128
bit encryption.

You need to set "High" or "FIPS". But i'm not sure if Mac clients support FIPS.

(I am aware of the SSL cert setup but trying to avoid this since the clients
are all outsiders and applying the cert to each computer is a killer.)

Actually, SSL/TLS is the safest mode.

--
Sincerely,
Eugene Sukhodolin
CTO, TSFactory Inc.
http://www.tsfactory.com

.



Relevant Pages

  • Re: IPSec to encrypt SMB traffic?
    ... of our clients are within our own Domain. ... Removed all entries under Key Exchange Security Method except for: ... default lists intact) - this new list is the Selected one ... Encryption and Integrity Security Method. ...
    (microsoft.public.windows.server.security)
  • Re: IPSec to encrypt SMB traffic?
    ... of our clients are within our own Domain. ... Removed all entries under Key Exchange Security Method except for: ... default lists intact) - this new list is the Selected one ... Encryption and Integrity Security Method. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Looking for Subversion server-side SSH key manager
    ... Many good clients, such as ... How would you like to store Subversion password? ... since "encryption with publicly known key" is no ...
    (comp.os.linux.security)
  • Re: How to encrypt/decrypt a file
    ... I think the OP simply wants to encrypt the xml file to prevent the clients ... server. ... doing the encryption with the public key and the server decrypts with the ...
    (microsoft.public.dotnet.security)
  • [VulnWatch] defeating Lotus Sametime "encryption"
    ... clients use RC2 to encrypt the password, ... the key along with the login packet allowing an attacker to decrypt the ... For example, Lotus Sametime provides encryption, logging, ... 00 -- length of opaque for auth data ...
    (VulnWatch)