Secure RDP Connections with SSL (2024)

RDP connections to the PSM machine with SSL

Users can configure secure RDP connections to the PSM machine using an SSL connection.

Configure secure RDP connections to the PSM machine with SSL

  1. On the PSM server, set the security layer. Proceed per PSM server operating system:

    • Secure RDP Connections with SSL.

  2. On the PSM server, run gpedit.msc.

    1. Navigate to Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security.
    2. Open the Security setting, Set client connection encryption level.

    3. In the Options area, from the Encryption Level drop-down list, select High Level.

    4. Click OK to save your settings.

    5. Open the Security setting, Require use of specific security layer for remote (RDP) connections.

    6. In the Options area, from the Security Layer drop-down list select:

      OS

      Security Layer

      Windows 2016

      SSL

      Window 2012 R2

      SSL (TLS 1.0).

    7. Click OK to save your settings.

    8. Continue with update all the active connection components described in step 4.

  3. In the PVWA, update all the active connection components to enable RDP over SSL connections to the PSM machine. For example, for PSM SSH connections, update PSM-SSH.

  4. To support Live Session connections, update the target connection component.
    1. Log onto the PVWA as an administrative user.

    2. In the System Configurations page, click Options, then expand the Connection Components.

    3. In each active connection component, add a new Component Parameter.

    4. In the Component Parameter properties, add a new parameter with the following values:

      • Name – The name of the component parameter.
        • For connections with ActiveX, specify AdvancedSettings4.AuthenticationLevel.

        • For connections with RDP files, specify authentication level:i.

        • Add both parameters to use both methods.

      • Value – The value of this parameter name. Specify 1.
    5. Click Apply to apply the new configurations and stay in the Options page.

  5. Connections to the PSM require a certificate on the PSM machine. By default, Windows generates a self-signed certificate, but you can use a certificate that is supplied by your enterprise.

    1. Expand the Privileged Session Management parameters and then expand Configured PSM Servers.

    2. Expand Connection Details, and select Server; the Server Properties are displayed.

    3. In the Address property, specify the certificate common name.

    4. Click Apply to apply the new configurations, or,

    5. Click OK to save the new configurations and return to the System Configuration page.

    In the Privileged Session Management parameters, make sure that the PSM address specifies the exact common name of the certificate.

  6. On the Client machines, make sure that the PSM machine certificate is signed by a trusted CA.

RDP connections to target machines with SSL

Users can configure secure PSM-RDP connections to target machines by verifying the target machine before connecting to it and encrypting the session, using an SSL connection. To facilitate this type of connection, the target machine must have its own certificate. The PSM server machine must trust the CA that signed the certificate used by the target machine.

Before configuring secure RDP connections with SSL

Import the CA Certificate that signed the certificate used by the target machine into the Windows certificate store on the PSM server machine:
Certificates (Local Computer)/Trusted Root Certification Authorities
By storing the certificate in this location, all users will be able to access the remote machine using an authenticated connection.

Configure secure RDP connections with SSL

  1. In the System Configuration page, in the Web Access section, click Options, then select Connection Components; the connection component parameters that define target addresses are displayed in the properties list.

  2. Expand the PSM-RDP connection component, and then expand the Target Settings.

  3. Right-click Client Specific, then in the pop-up menu select Add Parameter; a new parameter is added to the list of client specific parameters.

  4. In the parameter properties, specify the following:

    • Name – The name of the client specific parameter. Specify AuthenticationLevel.

    • Value – The authentication level that will be used for this connection. Specify any of the following values:

    Value Description
    0 The PSM server is not required to authenticate the target machine before connecting to it.
    1 The PSM server will authenticate the target machine before connecting to it.
    2 The PSM server will authenticate the target machine before connecting to it. If the authentication fails, the user will be able to cancel the connection or to initiate a connection without authentication.
  5. Click Apply to apply the new Connection Component configurations,

or,

Click OK to save the new Connection Component configurations and return to the System Configuration page.

  • Secure RDP Connections with SSL
    • RDP connections to the PSM machine with SSL
    • RDP connections to target machines with SSL
      • Before configuring secure RDP connections with SSL

Explore

CyberArk

Learn

Versions 10.1 - 10.9

Resources

Contact

Send us feedback

Support

Follow us

Copyright © 1999-2019 CyberArk Software Ltd. All rights reserved. | Terms and Conditions | Privacy Policy | Acknowledgements

Build VERSION_NO [12 February 2023 11:31:27 AM]

Secure RDP Connections with SSL (2024)
Top Articles
How to file US Tax on NRE, NRO Interest (without 1099-INT) - USA
LinkedIn Skill Assessment Test: Get Noticed by Clients
Melson Funeral Services Obituaries
The Definitive Great Buildings Guide - Forge Of Empires Tips
Asian Feels Login
Horoscopes and Astrology by Yasmin Boland - Yahoo Lifestyle
Jennette Mccurdy And Joe Tmz Photos
Programmieren (kinder)leicht gemacht – mit Scratch! - fobizz
Wgu Admissions Login
Money blog: Domino's withdraws popular dips; 'we got our dream £30k kitchen for £1,000'
Love In The Air Ep 9 Eng Sub Dailymotion
9044906381
Icommerce Agent
Directions To Advance Auto
Grandview Outlet Westwood Ky
Conan Exiles: Nahrung und Trinken finden und herstellen
Conan Exiles Sorcery Guide – How To Learn, Cast & Unlock Spells
Teekay Vop
Kroger Feed Login
Sony Wf-1000Xm4 Controls
Kamzz Llc
A Plus Nails Stewartville Mn
Mark Ronchetti Daughters
J&R Cycle Villa Park
Chadrad Swap Shop
Six Flags Employee Pay Stubs
Chattanooga Booking Report
Craigslist Georgia Homes For Sale By Owner
Craigslist Boats Eugene Oregon
State Legislatures Icivics Answer Key
Priscilla 2023 Showtimes Near Consolidated Theatres Ward With Titan Luxe
Dying Light Nexus
Planet Fitness Santa Clarita Photos
Ktbs Payroll Login
Craigslist Pa Altoona
How To Upgrade Stamina In Blox Fruits
2700 Yen To Usd
303-615-0055
Bcy Testing Solution Columbia Sc
The Angel Next Door Spoils Me Rotten Gogoanime
Lamont Mortuary Globe Az
R: Getting Help with R
Dickdrainersx Jessica Marie
Elven Steel Ore Sun Haven
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Motorcycle For Sale In Deep East Texas By Owner
Here’s What Goes on at a Gentlemen’s Club – Crafternoon Cabaret Club
Prologistix Ein Number
Grace Charis Shagmag
What Responsibilities Are Listed In Duties 2 3 And 4
The Love Life Of Kelsey Asbille: A Comprehensive Guide To Her Relationships
login.microsoftonline.com Reviews | scam or legit check
Latest Posts
Article information

Author: Barbera Armstrong

Last Updated:

Views: 5387

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Barbera Armstrong

Birthday: 1992-09-12

Address: Suite 993 99852 Daugherty Causeway, Ritchiehaven, VT 49630

Phone: +5026838435397

Job: National Engineer

Hobby: Listening to music, Board games, Photography, Ice skating, LARPing, Kite flying, Rugby

Introduction: My name is Barbera Armstrong, I am a lovely, delightful, cooperative, funny, enchanting, vivacious, tender person who loves writing and wants to share my knowledge and understanding with you.