Meeting CJIS Advanced Authentication



Similar documents
Step-by-Step Guide for Setting Up VPN-based Remote Access in a

Technical Certificates Overview

Configuring Global Protect SSL VPN with a user-defined port

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

Configure your firewall for administrative access via RADIUS authentication

YubiKey PIV Deployment Guide

Certificate Management

Configuring WPA-Enterprise/WPA2 with Microsoft RADIUS Authentication

How To Configure Windows Server 2008 as a RADIUS Server with MS-CHAP v2 Authentication

Step-by-Step Guide for Setting Up VPN-based Remote Access in a Test Lab

Eduroam wireless network Windows Vista

Use 802.1x EAP-TLS or PEAP-MS-CHAP v2 with Microsoft Windows Server 2003 to Make a Secure Network

INFORMATION SYSTEMS SERVICE NETWORKS AND TELECOMMUNICATIONS SECTOR

Wireless Network Configuration Guide

Module 6. Configuring and Troubleshooting Routing and Remote Access. Contents:

Defender EAP Agent Installation and Configuration Guide

How to connect to the diamonds wireless network with Vista.

Automatic Setup... 1 Manual Setup... 2 Installing the Wireless Certificates... 18

NetMotion Mobility XE

Internet Authentication Service (IAS) Operations Guide

CruzNet Secure Set-Up Instructions for Windows Vista

Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

Joining. Domain. Windows XP Pro

HOTPin Integration Guide: DirectAccess

NetMotion + YubiRADIUS Quick Start Guide

Network Services One Washington Square, San Jose, CA

AVG Business SSO Connecting to Active Directory

Connec ng to Northwest s WIFI with Windows 7

AeroLab Wireless Network Code of Conduct. Connecting to the AeroLab Wireless Network

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows Vista

Application Note. Onsight Device Certificate Management

Edith Cowan University Information Technology Services Centre

Note that if at any time during the setup process you are asked to login, click either Cancel or Work Offline depending upon the prompt.

Basic Exchange Setup Guide

Shellfire L2TP-IPSec Setup Windows XP

Extension Wireless Access (EWA) v2.0

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows 7

Creating and Installing a Self Signed Certificate for PEAP/EAP-TLS Authentication

How to connect to VUWiFi

Configuring Wired 802.1x Authentication on Windows Server 2012

Configuring Windows 7 to Use Encrypted (WPA-E) Wireless Services a...

Securing Remote Desktop Services in Windows Server 2008

For paid computer support call

SafeWord Domain Login Agent Step-by-Step Guide

Microsoft OCS with IPC-R: SIP (M)TLS Trunking. directpacket Product Supplement

Patriots Outlook Configuration

Exchange 2010 PKI Configuration Guide

Check Point FDE integration with Digipass Key devices

SCADA Security. Enabling Integrated Windows Authentication For CitectSCADA Web Client. Applies To: CitectSCADA 6.xx and 7.xx VijeoCitect 6.xx and 7.

Instructions for connecting to the FDIBA Wireless Network. (Windows XP)

AD CS.

Windows Clients and GoPrint Print Queues

Using LifeSize Systems with Microsoft Office Communications Server 2007

Windows 8 & RT Wireless Configuration For NCC Student Owned Laptops

Using etoken for Securing s Using Outlook and Outlook Express

Knights Outlook 2013 Configuration

How to Access Coast Wi-Fi

vwlan External RADIUS 802.1x Authentication

Instructions: Configuring Outlook 2003 with Exchange 2010 on the FIUMail

Securing Administrator Access to Internal Windows Servers

Certificate Management

How to connect to NAU s WPA2 Enterprise implementation in a Residence Hall:

WIRELESS SETUP GUIDES FOR WINDOWS 8

Erado Archiving & Setup Instruction Microsoft Exchange 2010 Push Journaling

7.1. Remote Access Connection

ICT DEPARTMENT. Windows 7. Wireless Authentication Procedures for Windows 7 & 8 Users For Linux and windows XP users visit ICT office

How to set up Outlook Anywhere on your home system

Create, Link, or Edit a GPO with Active Directory Users and Computers

Using LifeSize systems with Microsoft Office Communications Server Server Setup

Windows Firewall Configuration with Group Policy for SyAM System Client Installation

Using RADIUS Agent for Transparent User Identification

Deployment of IEEE 802.1X for Wired Networks Using Microsoft Windows

Outlook Express. Make Changes in Red: Open up Outlook Express. From the Menu Bar. Tools to Accounts - Click on Mail Tab.

How to configure MAC authentication on a ProCurve switch

Erado Archiving & Setup Instruction Microsoft Exchange 2007 Push Journaling

Massey University Wireless Network Client Configuration Windows 7

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Knights Outlook Configuration

How To Set Up Hopkins Wireless On Windows 7 On A Pc Or Mac Or Ipad (For A Laptop) On A Network Card (For Windows 7) On Your Computer Or Ipa (For Mac Or Mac) On An Ipa Or

Configuring a Windows 2003 Server for IAS

Application Notes for Microsoft Office Communicator Clients with Avaya Communication Manager Phones - Issue 1.1

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Deploying Remote Desktop Connection Broker with High Availability Step-by-Step Guide

Windows Vista and Windows 7 Wireless Configuration For NCC Faculty and Staff Owned Laptops

Quality Center LDAP Guide

Using Windows NPS as RADIUS in eduroam

Installing Samsung SDS CellWe EMM cloud connectors and administrator consoles

Setting up SJUMobile (Wireless Internet Access for personal devices)

Step-by-Step Guide for Creating and Testing Connection Manager Profiles in a Test Lab

Windows Wireless Network Connection Instructions

How to Setup PPTP VPN Between a Windows PPTP Client and the DIR-130.

Integration with Active Directory

Microsoft IAS Configuration for RADIUS Authorization

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

Using TLS Encryption with Microsoft Outlook 2007

ILTA HAND 6B. Upgrading and Deploying. Windows Server In the Legal Environment

Seamless and Secure Access (SSA) Manual Configuration Guide for Windows Mobile 6.1

ThinManager and Active Directory

Internet Access: Wireless WVU.Encrypted Network Connecting a Windows 7 Device

Transcription:

Meeting CJIS Advanced Authentication using User Certificate and Strong Key Protection Presented by: Carlos Leon, Network Manager City of Palm Beach Gardens

Meeting CJIS Requirements CJIS security policy calls for the use of advanced authentication methods authentication based on additional factors beyond simple user name/password authentication. NetMotion Mobility XE supports industry standard infrastructure: RADIUS servers as the front-end for Microsoft's Active Directory Authentication and PKI (public key infrastructure) for provisioning and exchange of digital certificates. Other RADIUS / PKI solutions are supported if they are compatible with X.509v3 user certificates, standard Microsoft CAPI enabled access to those certificates, and the RADIUS EAP TLS or EAP TLS inside the PEAP protocol. In addition to strong authentication, CJIS security policy mandates the use of FIPS 140 2 validated encryption. NetMotion Mobility XE s use of validated/certified cryptographic libraries (NIST certificate numbers 237, 441 and 493) meets this requirement.

Strong Key Protection: Overview This process utilizes a user-based public key infrastructure (PKI) certificates X.509v3 secured by Microsoft Strong Key Protection which is stored on the user s hard drive. The certificate is then used by NetMotion VPN in a PEAP wrapper for EAP-TLS user authentication. VPN will request the certificate: Each time the employee reboots the computer After a time interval (13 hours is recommended) If employees bypasses NetMotion then connects If air card disconnects (drops), then reconnects, the password for the certificate will be not requested again.

Employee Logon Process Steps through the process for authentication and access to the network: Officers logon: Windows Network username & password to follow CJIS policy 5.6.2.1 Officers VPN client (NetMotion) calls the PKI which forces the user to type an individual password to access the individual certificate following CJIS policy 5.6.2.2 The VPN awaits the verification from the RADIUS server to allow for connection to the network. Officer will be prompted for certificate password every 13 hours.

Software Requirements for Solution Microsoft Windows Server 2008 R2 Enterprise or Datacenter: Microsoft Active Directory Certificate Services (AD CS) Microsoft Network Policy and Access Services (NPAS) Microsoft Active Directory Infrastructure NetMotion Mobility XE 9.21 Server NetMotion Mobility XE 9.x Client(s)

Today's Installation & Configuration Objectives Install and Configure simple deployment of Microsoft Certificate Services Install and Configure Network Policy and Access Services (RADIUS) NetMotion Mobility XE Server Configuration NetMotion XE Client Configuration Validating Client Connection

Installation & Configuration

Install Certificate Services Open Server Manager on the Windows 2008 R2 Server where you plan to install Certificate Services Click on Roles Click on Add Roles

Install Certificate Services Click Next Select Active Directory Certificate Services Click on Next

Install Certificate Services Click Next until you Complete the Wizard accepting all defaults as displayed NOTE: The values displayed for Common name for this CA: and Distinguished name suffix will be specific to your environment.

Configuring Certificate Services Open Server Manager on Certificate Services Server Expand out Roles Active Directory Certificate Services Servername Right click Certificate Templates and select Manage

Configuring Certificate Services Right Click the USER CERIFICATE A Duplicate Template dialog box may appear asking if this Certificate is for Windows Server 2003 Enterprise or Windows Server 2008 Enterprise Select Windows 2008 Enterprise and click OK

Configuring Certificate Services Change the Template display name: In the screen shot we specified CJIS-NetMotion Click the Security tab and Select the Active Directory Group you wish to use

Configuring Certificate Services Set Extensions Application Polices Remove all but Client Authentication Certificate is only used by User Authentication Set Request Handing Prompt every time the certificate is used.

Configuring Certificate Services Now you need to issue the template Return to Server Manager Right click on Certificate Templates Select New Certificate Template to Issue

Configuring Certificate Services The template you just duplicated should now be listed under Certificate Templates

Configuring Active Directory

Configuring Active Directory to use Use Group Policies to enforce: Strong Key Policy Strong Key Protection User must enter a password each time they use a key 19

Configuring Active Directory to Deploy Certificates Open Group Policy Management Snap-In Note: This snap-in exists on the Domain Controller Right click on the Default Domain Policy Select Edit to open the Group Policy Management Editor 20

Configuring Active Directory Apply to officer laptops Organizational Unit or at Domain level Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\

Configuring Network Policy and Access Services (NPAS)

Configuring Network and Access Policy Services There are 3 things that should be defined in Network Policy and Access Services 1. Create the RADIUS Client 2. Create a Connection Request Policy 3. Create a Network Policy If you have more than one Mobility XE server in your pool you will need to create a RADIUS Client for each NetMotion Mobility XE server

Install and Configure Network Policy and Access Services

Install Network Policy & Access Services (NPS) Open Server Manager on the Windows 2008 R2 Server where you plan to install NPS Click on Roles Click on Add Roles

Install Network Policy & Access Services Select Network Policy and Access Services Click Next Select Network Policy Server Click Install to begin installation Click Close to complete the install 26

NPAS Create the RADIUS Client Open Server Manager where NPAS was installed Expand out Roles Network Policy and Access Services NPS RADIUS Clients and Servers RADIUS Clients Right click RADIUS Clients and select New

NPAS Create a Connection Request Policy Open Server Manager where NPAS was installed Expand out Roles Network Policy and Access Services NPAS Policies Connection Request Policies Right click Connection Request Policies and select New

NPAS - Connection Request Policy Set Specified Condition as NAS Identifier NetMotion

NPAS - Create a Network Policy Open Server Manager where NPAS was installed Expand out Roles Network Policy and Access Services NPS Policies Network Policies Right click Network Policies and select New

NPAS - Create a Network Policy Conditions»Windows Group form Active Directory»NAS Identifier to be used in Netmotion settings

NPAS - Create a Network Policy Constraints: Select Microsoft: Smart Card or other certificate and click OK NOTE: Selecting this option does NOT mean you must have Smart Cards

XE Server Installing NetMotion

Mobility XE Server install Note: Retain Password

Configuration NetMotion XE Server

Mobility XE Server Configuration Configure Mobility XE for RADIUS EAP and EAP-TLS Global Server Setting

Mobility XE Server Configuration Configure RADIUS Server List Global Server Setting NOTE: NAS ID: same as the NAS Identifier in NPAS

Mobility XE Server Configuration Configure User Logon Re-authentication Interval Global Client Setting

Installing User Certificate

Client Configuration Requirement: Laptop joined to domain NetMotion Client in bypass User must have local network access WIFI or Ethernet

Installing User Certificate User opens Certificate Console (Windows 7) Certmgr.msc

Installing User Certificate Start the process Expand Personal Right Click Certificates Click on Request New Certificate

Installing User Certificate Pick correct certificate Named CJIS- Netmotion during the Certificate install Type password that will be used to access certificate. Enforced by strong key protection and requirement on certificate. Password follows Domain password policy Finish

NetMotion XE Client configuration

NetMotion Client configuration Must configure client to use local personal user certificate Right Click Properties Status Configuration -> Client Certificate

Netmotion XE Client Connection

Client Connection First time XE client will ask for which certificate from the store to use:

Client Connection User asked to type in Password to access certificate which allows for connection

Renewing user Certificate

Renewing user Certificate Requirement: Laptop joined to domain User must have network access WIFI or Ethernet access NetMotion Connected or bypassed

Renewing user Certificate Open certificate store

Renewing user Certificate NOTE: User will need to know old password

Lost Password

Recover Certificate lost password Process to create a new certificate if user does NOT know the password for the certificate. Requirement: Laptop joined to domain NetMotion Client in bypass User must have network access WIFI or Ethernet access

Recover Certificate lost password User must delete old certificate and request new

QUESTIONS: Meeting CJIS Advanced Authentication using User Certificate and Strong Key Protection Presented by: Carlos Leon, Network Manager City of Palm Beach Gardens cleon@pbgfl.com 561-248-7373