LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 06-20-2011, 02:02 PM   #1
takayama
Member
 
Registered: Sep 2009
Posts: 97

Rep: Reputation: 0
Secure alternative to 2k8 rdp server


Hello
At my work we have a windows 2008 that serves as a "bounce pc" i cant find any better word (thats directly translated from the word we use in my language) What i mean by that is that if we want to access the server net and so on we first have to rdp to a w2k8 computer and from their ssh/rdp/www futher to admin. The few admin have their own account and can be logged on at the same time, also with the rdp client you can mount your local c:\ witch can be very usfull when you need to transfer file to the servers (they dont have access to the internet). Now im looking for a similar service but for linux, suggestions?

The client that you connect with should be avalible to as many platforms as possible?
 
Old 06-20-2011, 02:12 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by takayama
At my work we have a windows 2008 that serves as a "bounce pc" i cant find any better word (thats directly translated from the word we use in my language) What i mean by that is that if we want to access the server net and so on we first have to rdp to a w2k8 computer and from their ssh/rdp/www futher to admin.
What you're describing is generally referred to as a bastion host.
 
Old 06-20-2011, 09:40 PM   #3
Nominal Animal
Senior Member
 
Registered: Dec 2010
Location: Finland
Distribution: Xubuntu, CentOS, LFS
Posts: 1,723
Blog Entries: 3

Rep: Reputation: 948Reputation: 948Reputation: 948Reputation: 948Reputation: 948Reputation: 948Reputation: 948Reputation: 948
Quote:
Originally Posted by takayama View Post
Hello
At my work we have a windows 2008 that serves as a "bounce pc" i cant find any better word (thats directly translated from the word we use in my language) What i mean by that is that if we want to access the server net and so on we first have to rdp to a w2k8 computer and from their ssh/rdp/www futher to admin. The few admin have their own account and can be logged on at the same time.
There seem to be Linux RDP clients, but considering Microsoft's history regarding network security, I would never use it myself. I've used a simple SSH port forwarding via a border server for years, especially when I needed a remote GUI (X11 forwarding).

But, since your use cases are more varied, perhaps you should consider OpenVPN? It is used by many Universities around the world for exactly this.

Although openvpn.net sells something called Access Server, the open-source OpenVPN package is used in that too. You really only need the open-source OpenVPN package, for both the client and the server. Here is the HowTo.

In a multi-OS environment, OpenVPN works best if Public Key Infrastructure (certificates) is used for authentication, instead of usernames and passwords. The secret keys should be stored totally off the net; only the signed certificates (user and the certificate authority) need to reside on the user's machine. Your organisation can be, and probably should be, its own certificate authority for this. (That would also mean you do not need to pay anything to anybody outside your organization for this.)

Mandating that the user certificates must be password protected at all times is a good idea. The users will need to supply the certificate password when opening the VPN, but on the other hand, a nefarious attacker would need both the user certificate file, and the password used to open it, until they can gain access to your organization's network via the OpenVPN server.

If not password protected, the theft of a user's machine or the user certificate on it, will allow access to the internal LAN, until the theft is noticed and reported and the certificate is revoked, or until the certificate expires.

The theft of the certificate authority certificate does not matter. It is on the user's machine only to let the user know if the other end is the expected machine; if not, OpenVPN will complain loudly. The certificate authority certificate is public, and will not open any doors, or allow anyone to posture as the OpenVPN server, as long as the key used to generate is it safe and secure (off the network, preferably).

Hope this helps.
 
Old 06-21-2011, 10:26 AM   #4
takayama
Member
 
Registered: Sep 2009
Posts: 97

Original Poster
Rep: Reputation: 0
FreeNX seems to be what i was looking for.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Win Storage Server 2k8 share to OpenSUSE 10.3 (NFS preferably) fesake Linux - Newbie 3 08-06-2010 09:22 AM
What should I expect if I were to land a job as a windows server 2k8 admin? Dogs General 16 09-24-2009 12:05 AM
How secure is vsftpd? What alternative is there for more secure access? Gum Linux - Security 5 03-24-2009 05:00 PM
Is RDP as secure as SSH veeramani Linux - Security 3 03-12-2007 06:30 AM
Secure server that allows for rdp redogre82 Linux - Software 1 09-04-2004 03:55 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 09:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration