Jump to content

Recommended Posts

Posted

Morning,

I am pushing direct access through a server with an internal network card and an external address. My question is do I need to bother with an official SSL cert or will the self signed one be ok? Im new to SSL cert however the setup clearly reads the certificate is used for the network location server (so not really looking externally) and the current self signed one reads "directaccess-NLS.school.internal" so I assume this is ok to leave this like that?

I guess my point is it looks for an internal cert rather than an external facing directaccess.schoolname.uk (for example) address so wont require a third party certificate.

 

New to SSL certs and a little confused. If someone out there is in the know, do I need an SSL from a third party?

 

THanks

Posted

For IP-HTTPS it is recommended to get a certificate from a public CA. For the NLS, a certificate from an internal CA is sufficient (although as mentioned below you can also use a wildcard certificate if you already have one of those).

 

SSL certificate for NLS

The first certificate that we need isn't for the DirectAccess server at all, but rather this is just a standard SSL certificate like you would put on any other website, and it gets installed onto the server where you are hosting your Network Location Server (NLS). We'll actually talk a little more shortly about why the NLS website should be hosted externally to your DirectAccess server, but for the purposes of this section, you just need to know that you will have a website in your network, it'll be running on a webserver (most likely IIS), and it must be an HTTPS site, so it requires a valid SSL certificate. The Subject Name of this certificate must match whatever DNS name you chose for the NLS website, and the intended purpose of this certificate must be Server Authentication. Again, this is similar to any other SSL certificate. In most implementations, we issue this certificate from your internal CA server. This is really just to minimize costs. The only computers that will be contacting this website will be your DirectAccess client computers that are inside the network, so there is no need to externally publish your PKI or Certificate Revocation Lists (CRL), and this certificate can be simply issued from the internal CA server without any other considerations. I have seen a few customers place a certificate that was purchased from a public authority on their NLS website, particularly places where they already own a wildcard certificate that can be used as many times and places as they choose, so that is definitely also an option if you are more comfortable doing it that way.

 

SSL certificate for IP-HTTPS

This is another simple requirement. As we already mentioned, the traffic from the client computers that connect via IP-HTTPS will essentially be HTTPS traffic, and so just as any webserver, the DirectAccess server requires an SSL certificate installed onto it to validate those connections. This is a standard SSL certificate that you can import into either the Certificates MMC or directly into IIS, and the Subject Name of this certificate must match whatever name you are going to enter into the DirectAccess wizards as the public DNS name for the connection. Or it can definitely be a wildcard, if you have one available. There is one statement that I always like to make regarding the IP-HTTPS certificate that will save you from a lot of headaches. Use an SSL certificate for IP-HTTPS that was purchased from a public authority. Unlike the NLS certificate, this guy is going to be validated by client computers connecting over the Internet, and they do like to verify connectivity to the CRL. Because of this, if you choose to try and utilize an IP-HTTPS certificate that was issued from your internal PKI, you must externalize some resources so that your CRLs are publicly accessible, or your DirectAccess connections will not work. I have seen countless people try and fail to utilize a certificate from an internal CA server for this purpose, and so I absolutely recommend that you pony up the relatively small cost for this certificate and purchase it from GoDaddy, Entrust, VeriSign, or wherever you normally source your certificates.

 

Source: http://shop.oreilly.com/product/9781782171065.do

  • Thanks 1
Posted
Morning,

I am pushing direct access through a server with an internal network card and an external address. My question is do I need to bother with an official SSL cert or will the self signed one be ok? Im new to SSL cert however the setup clearly reads the certificate is used for the network location server (so not really looking externally) and the current self signed one reads "directaccess-NLS.school.internal" so I assume this is ok to leave this like that?

I guess my point is it looks for an internal cert rather than an external facing directaccess.schoolname.uk (for example) address so wont require a third party certificate.

 

New to SSL certs and a little confused. If someone out there is in the know, do I need an SSL from a third party?

 

THanks

 

I haven't done much more than test the concept but an SSL certificate signed by an internal CA should be adequate. The DirectAccess client is going to be a member of your domain and it should trust your CA so you shouldn't have a problem. A cert signed by the DA server itself though will be problematic.

  • Thanks 1
Posted

DA.JPG

 

Just to confirm, attached is the part I am confused on. Is this the one I want the self signed or publicly signed one or the third party one and if the third party one, it would be the public facing address (directaccess.externaldomainname.uk) SSL.

 

Sorry to be such a goon on this but I keep getting random certificate issues with this and if I am rolling it out to staff next year I need it to be bullet proof.

 

Thanks

Posted

If you have an internal certificate authority (CA), a certificate issued by that will be good enough. If you don't, you'll need to buy a certificate from the likes of Comodo, Janet or GoDaddy.

 

Don't use the self signed certificate. The certificate that you use needs to have the DirectAccess server's public DNS name and it needs to be from an authority which the client trusts.

  • 2 weeks later...
Posted

I now have another problem. I now have an external SSL for remote.school.etc.uk and if I goto deploy direct access it allows me with that SSL, ONLY if I select one network adapter however I need two (internal and external). As soon as I bring the external network adapter into this, it refuses to see the SSL.

Any thoughts into this? Its Friday afternoon, I know little about SSL and want to throw money at this until it goes away. Im happy to pay for another SSL but have no idea what I am asking for and why the second adapter would cause such an issue. I would have thought the SSL proves the location is where it is going to be going too.

 

Thanks all

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...