Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

3
Adding corporate TLS certificate to Azure VMSS for RDP
Post Flair (click to view more posts with a particular flair)
Post Body

Just had a third party pen-test report against our VMSS that we use for RDP. They report that the top certificate is self-signed, and we should use a corporate one. From here: https://learn.microsoft.com/en-us/azure/virtual-desktop/network-connectivity#connection-security - "By default, the certificate used for RDP encryption is self-generated by the OS during the deployment. If desired, customers may deploy centrally managed certificates issued by the enterprise certification authority."

Their rationale is to protect against man-in-the-middle attacks. I'm happy to defer to them on this issue. I've discovered we already have a paid-for cert that is, apparently, *.our.domain.com, although it expires in August. Q1 - how to validate this? Q2 - come August, how to renew this?

I've also discovered what appears to be a decent guide: https://intranetssl.net/securing-rdp-connections-with-trusted-ssl-tls-certificates/ however,

Q3 - it starts out saying "Suppose, that a corporate Microsoft Certificate Authority is already deployed in your domain..." - What if I can't suppose this? The first part of this guide sounds like I'm duplicating the Computer certificate. Shouldn't I be using the paid-for one?

Q4 - Does anyone know of a better guide(s) for our scenario?

Please note, I may be in a different time-zone to you so might be a while in responding, apologies!

Author
Account Strength
100%
Account Age
9 years
Verified Email
Yes
Verified Flair
No
Total Karma
11,077
Link Karma
161
Comment Karma
10,764
Profile updated: 4 days ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
8 months ago