Restructured Documentation
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
This commit is contained in:
+37
@@ -0,0 +1,37 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- Group Policy
|
||||
- Authentication
|
||||
---
|
||||
|
||||
## Purpose
|
||||
To deploy a shortcut to the desktop pointing to a network share's root path. (e.g. `\\storage.bunny-lab.io`). There is a quirk with how Windows handles network shares and shortcuts and doesn't like when you point the shortcut to a root UNC path.
|
||||
|
||||
### Group Policy Location
|
||||
```mermaid
|
||||
graph LR
|
||||
A[Create Group Policy] --> B[User Configuration]
|
||||
B --> C[Preferences]
|
||||
C --> D[Windows Settings]
|
||||
D --> E[Shortcuts]
|
||||
```
|
||||
|
||||
### Group Policy Settings
|
||||
- **Action**: `Update`
|
||||
- **Name**: `<FriendlyName>`
|
||||
- **Target Type**: `File System Object`
|
||||
- **Location**: `Desktop`
|
||||
- **Target Path**: `C:\windows\explorer.exe`
|
||||
- **Arguments**: `\\storage.bunny-lab.io`
|
||||
- **Start In**: `<Blank>`
|
||||
- **Shortcut Key**: `<None>`
|
||||
- **Run**: `Normal Window`
|
||||
- **Icon File Path**: `%SystemRoot%\System32\SHELL32.dll`
|
||||
- **Icon Index**: `9`
|
||||
|
||||
### Additional Notes
|
||||
Navigate to the "**Common**" tab in the properties of the shortcut, and check the "**Run in logged-on user's security context (user policy option)**".
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,17 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- Authentication
|
||||
---
|
||||
|
||||
## Purpose
|
||||
If you have a device that lost trust in the domain for some reason, and won't let you login using domain credentials, run the following command as a local administrator on the device to repair trust.
|
||||
|
||||
```powershell
|
||||
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)
|
||||
```
|
||||
|
||||
If it outputs `True`, go ahead and log out then try to login again with the domain credentials.
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,34 @@
|
||||
---
|
||||
tags:
|
||||
- Windows Server
|
||||
- Windows
|
||||
- SSL
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Sometimes you may find that you need to convert a `.crt` or `.pem` certificate file into a `.pfx` file that Microsoft IIS Server Manager can import for something like Exchange Server or another custom IIS-based server.
|
||||
|
||||
## Download the Certificate Files
|
||||
This step will vary based on how you are obtaining the certificates. The primary thing to focus on is making sure you have the certificate file and the private key.
|
||||
|
||||
```text title="Certificate Folder Structure"
|
||||
certificate.crt
|
||||
certificate.pem
|
||||
gd-g2_iis_intermediates.p7b
|
||||
private.key
|
||||
```
|
||||
|
||||
## Convert using OpenSSL
|
||||
You will need a linux machine such as Ubuntu 22.04LTS, or to download the Windows equivelant of OpenSSL in order to run the necessary commands to convert and package the files into a `.pfx` file that IIS Server Manager can use.
|
||||
!!! note
|
||||
You need to make sure that all of the certificate files as well as private key are in the same folder (to keep things simple) during the conversion process. **It will prompt you to enter a password for the PFX file, choose anything you want.**
|
||||
|
||||
```sh title="OpenSSL Conversion Command"
|
||||
openssl pkcs12 -export -out IIS-Certificate.pfx -inkey private.key -in gd-g2_iis_intermediates.p7b -in certificate.crt
|
||||
```
|
||||
|
||||
!!! tip
|
||||
You can rename the files anything you want for organizational purposes. Afterall, they are just plaintext files. For example, you could rename `gd-g2_iis_intermediates.p7b` to `intermediate.bundle` and it would still work without issue in the command. During the import phase in IIS Server Manager, you can check a box to enable Exporting the certificate, effectively reverse-engineering it back into a certificate and private key.
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
+51
@@ -0,0 +1,51 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- LDAPS
|
||||
- Certificates
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Export the CA chain or domain-controller certificate required by an application that connects to Active Directory over LDAPS. Use the certificate objects from the documented CA and domain-controller environment.
|
||||
|
||||
## Export the LDAPS Certificate for Third-Party Applications
|
||||
Some applications do not automatically trust your internal PKI and require you to manually install the certificate used by your domain controllers for LDAPS. In most cases, you should export the issuing CA certificates rather than the individual domain controller certificate. Only export the domain controller certificate if the third-party application explicitly requires it.
|
||||
|
||||
### Export the Root and Subordinate CA Certificates
|
||||
The Root CA and Subordinate CA certificates establish trust for every domain controller certificate issued by your PKI.
|
||||
|
||||
From any domain-joined system:
|
||||
|
||||
- Launch `certlm.msc`
|
||||
- Navigate to "**Trusted Root Certification Authorities > Certificates**"
|
||||
- Locate your Root CA certificate
|
||||
- Right-click the certificate and select "**All Tasks > Export...**"
|
||||
- Select "**No, do not export the private key**"
|
||||
- Export the certificate as either:
|
||||
- `DER encoded binary X.509 (.CER)`, or
|
||||
- `Base-64 encoded X.509 (.CER)`
|
||||
- Navigate to "**Intermediate Certification Authorities > Certificates**"
|
||||
- Locate your Subordinate CA certificate
|
||||
- Repeat the export process
|
||||
|
||||
Import both certificates into the trusted certificate store required by the third-party application.
|
||||
|
||||
### Export a Domain Controller Certificate
|
||||
If the application requires the LDAPS server certificate itself:
|
||||
|
||||
- On the target domain controller, launch `certlm.msc`
|
||||
- Navigate to "**Personal > Certificates**"
|
||||
- Locate the certificate issued to the domain controller's FQDN that includes **Server Authentication** as an intended purpose
|
||||
- If the certificate's intended purpose looks like `Client Authentication, Server Authentication, Smart Card Logon, KDC Authentication` this cert may be more versatile for you.
|
||||
- Right-click the certificate and select "**All Tasks > Export...**"
|
||||
- Select "**No, do not export the private key**"
|
||||
- Export the certificate as either:
|
||||
- `DER encoded binary X.509 (.CER)`, or
|
||||
- `Base-64 encoded X.509 (.CER)`
|
||||
|
||||
!!! warning "Do Not Export the Private Key"
|
||||
Third-party LDAPS clients require only the public certificate. Do **not** export the certificate as a `.pfx` file or include the private key unless the vendor explicitly documents that requirement.
|
||||
|
||||
## Related Documentation
|
||||
- [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Identify the CA chain used by the LDAPS clients.
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
+77
@@ -0,0 +1,77 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- Certificate Services
|
||||
- PKI
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Publish the root and subordinate CA revocation lists for the documented two-tier Active Directory certificate environment. The Root CA and HTTP distribution point must already be configured as described in the certificate deployment.
|
||||
|
||||
## CRL Publishing and Maintenance
|
||||
CRLs must be generated and published on a recurring basis. If a CRL expires, certificate validation may fail even if the CA services themselves are running.
|
||||
|
||||
### Root CA CRL Publishing
|
||||
Because the Root CA is offline, periodically bring it online only long enough to generate a new CRL and copy it to the HTTP distribution point.
|
||||
|
||||
On `LAB-CA-01`:
|
||||
|
||||
```powershell
|
||||
certutil -crl
|
||||
```
|
||||
|
||||
Copy the generated CRL from:
|
||||
|
||||
```text
|
||||
C:\Windows\System32\CertSrv\CertEnroll\
|
||||
```
|
||||
|
||||
to the IIS publication directory on `LAB-CA-02`:
|
||||
|
||||
```text
|
||||
C:\inetpub\wwwroot\pki\
|
||||
```
|
||||
|
||||
Validate:
|
||||
|
||||
```powershell
|
||||
Invoke-WebRequest http://pki.bunny-lab.io/pki/BunnyLab-RootCA.crl
|
||||
```
|
||||
|
||||
### Subordinate CA CRL Publishing
|
||||
On `LAB-CA-02`:
|
||||
|
||||
```powershell
|
||||
certutil -crl
|
||||
```
|
||||
|
||||
Copy or confirm the Subordinate CA CRL exists in:
|
||||
|
||||
```text
|
||||
C:\inetpub\wwwroot\pki\
|
||||
```
|
||||
|
||||
Validate the URL from a domain-joined system.
|
||||
|
||||
### Operational Monitoring
|
||||
Monitor CRL expiration and publication. Certificate validation failures can occur if CRLs expire, even if certificates themselves have not expired.
|
||||
|
||||
Recommended operational tasks:
|
||||
|
||||
- Track Root CA CRL expiration.
|
||||
- Track Subordinate CA CRL expiration.
|
||||
- Verify HTTP CRL URLs after each publication.
|
||||
- Keep the Root CA offline except during controlled maintenance windows.
|
||||
- Document the expected CRL filenames generated in `C:\Windows\System32\CertSrv\CertEnroll\`.
|
||||
|
||||
!!! abstract "Raw Unprocessed/Unimplemented Steps"
|
||||
Publish CRLs regularly, configure overlap periods, and monitor expiration. Enable Delta CRLs on the Subordinate CA, but not on the Root.
|
||||
Security Recommendations
|
||||
|
||||
- Harden CA servers; limit access to PKI admins.
|
||||
- Use BitLocker or HSM for key protection.
|
||||
- Monitor issuance and renewals with audit logs and scripts.
|
||||
|
||||
## Related Documentation
|
||||
- [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Confirm the CA names, publication paths, and HTTP distribution point.
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,27 @@
|
||||
---
|
||||
tags:
|
||||
- Gitea
|
||||
- Keycloak
|
||||
- OAuth2
|
||||
- Authentication
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Configure the documented Gitea OAuth2 client settings after Keycloak and Gitea are deployed.
|
||||
|
||||
### OAuth2 Configuration
|
||||
These are variables referenced by the associated service to connect its authentication system to [Keycloak](<../../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>).
|
||||
|
||||
| **Parameter** | **Value** |
|
||||
| :--- | :--- |
|
||||
| Authentication Name | `auth-bunny-lab-io` |
|
||||
| OAuth2 Provider | `OpenID Connect` |
|
||||
| Client ID (Key) | `git-bunny-lab-io` |
|
||||
| Client Secret | `https://auth.bunny-lab.io > Clients > git-bunny-lab-io > Credentials > Client Secret` |
|
||||
| OpenID Connect Auto Discovery URL | `https://auth.bunny-lab.io/realms/master/.well-known/openid-configuration` |
|
||||
| Skip Local 2FA | Yes |
|
||||
|
||||
## Related Documentation
|
||||
- [Gitea Deployment](<../../../deployments/automation/Gitea/Gitea.md>) — Prepare the application before configuring OAuth2.
|
||||
- [Keycloak Integrations](<../../../reference/Identity and Certificates/Keycloak Integrations.md>) — Review the identity-provider deployment and other integrations.
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,30 @@
|
||||
---
|
||||
tags:
|
||||
- Portainer
|
||||
- Keycloak
|
||||
- OAuth2
|
||||
- Authentication
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Configure the documented Portainer OAuth2 settings after Keycloak and Portainer are deployed.
|
||||
|
||||
### OAuth2 Configuration
|
||||
These are variables referenced by the associated service to connect its authentication system to [Keycloak](<../../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>).
|
||||
|
||||
| **Parameter** | **Value** |
|
||||
| :--- | :--- |
|
||||
| Client ID | `container-node-01` |
|
||||
| Client Secret | `https://auth.bunny-lab.io > Clients > container-node-01 > Credentials > Client Secret` |
|
||||
| Authorization URL | `https://auth.bunny-lab.io/realms/master/protocol/openid-connect/auth` |
|
||||
| Access Token URL | `https://auth.bunny-lab.io/realms/master/protocol/openid-connect/token` |
|
||||
| Resource URL | `https://auth.bunny-lab.io/realms/master/protocol/openid-connect/userinfo` |
|
||||
| Redirect URL | `https://192.168.3.19:9443` |
|
||||
| Logout URL | `https://auth.bunny-lab.io/realms/master/protocol/openid-connect/logout` |
|
||||
| User Identifier | `email` |
|
||||
| Scopes | `email openid profile` |
|
||||
|
||||
## Related Documentation
|
||||
- [Portainer Deployment](<../../../deployments/Containers/Docker/Deploy Portainer.md>) — Prepare the application before configuring OAuth2.
|
||||
- [Keycloak Integrations](<../../../reference/Identity and Certificates/Keycloak Integrations.md>) — Review the identity-provider deployment and other integrations.
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,19 @@
|
||||
---
|
||||
tags:
|
||||
- MFA
|
||||
- Identity and Certificates
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Sometimes you may need to change the MFA on an account, by adding a new email or phone number for SMS-based MFA. This can be done fairly quickly and only involves a few steps:
|
||||
|
||||
- Navigate to the [Azure Web Portal](https://portal.azure.com) and log in using your Office365 admin credentials.
|
||||
- Navigate to the [Azure Active Directory (Microsoft Entra ID) Users List](https://portal.azure.com/#view/Microsoft_AAD_UsersAndTenants/UserManagementMenuBlade/~/AllUsers)
|
||||
- Click on the User Account that needs their MFA information changed / wiped
|
||||
- On the left-hand navigation menu, click on "**Authentication Methods**" at the bottom
|
||||
- Make adjustments to existing methods or click on "**+ Add Authentication Method**"
|
||||
- Valid options generally are Phone Numbers, Email Addresses, and a "**Temporary Access Pass**"
|
||||
- Save the changes by clicking the "**Add**" button, then have the user attempt to log in again using their MFA method configured
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,82 @@
|
||||
---
|
||||
tags:
|
||||
- Ansible
|
||||
- WinRM
|
||||
- Windows
|
||||
- Automation
|
||||
---
|
||||
|
||||
## Purpose
|
||||
You will need to enable secure WinRM management of the Windows devices you are running playbooks against, as compared to the Linux devices. The following powershell script needs to be ran on every Windows device you intend to run Ansible playbooks on. This script can also be useful for simply enabling / resetting WinRM configurations for Hyper-V hosts in general, just omit the Powershell script remote signing section if you dont plan on using it for Ansible.
|
||||
|
||||
```powershell
|
||||
# Script to configure WinRM over HTTPS on the Hyper-V host
|
||||
|
||||
# Ensure WinRM is enabled
|
||||
Write-Host "Enabling WinRM..."
|
||||
winrm quickconfig -force
|
||||
|
||||
# Generate a self-signed certificate (Optional: Use your certificate if you have one)
|
||||
$cert = New-SelfSignedCertificate -CertStoreLocation Cert:\LocalMachine\My -DnsName "$(Get-WmiObject -Class Win32_ComputerSystem).DomainName"
|
||||
$certThumbprint = $cert.Thumbprint
|
||||
|
||||
# Function to delete existing HTTPS listener
|
||||
function Remove-HTTPSListener {
|
||||
Write-Host "Removing existing HTTPS listener if it exists..."
|
||||
$listeners = Get-WSManInstance -ResourceURI winrm/config/listener -Enumerate
|
||||
foreach ($listener in $listeners) {
|
||||
if ($listener.Transport -eq "HTTPS") {
|
||||
Write-Host "Deleting listener with Address: $($listener.Address) and Transport: $($listener.Transport)"
|
||||
Remove-WSManInstance -ResourceURI winrm/config/listener -SelectorSet @{Address=$listener.Address; Transport=$listener.Transport}
|
||||
}
|
||||
}
|
||||
Start-Sleep -Seconds 5 # Wait for a few seconds to ensure deletion
|
||||
}
|
||||
|
||||
# Remove existing HTTPS listener
|
||||
Remove-HTTPSListener
|
||||
|
||||
# Confirm deletion
|
||||
$existingListeners = Get-WSManInstance -ResourceURI winrm/config/listener -Enumerate
|
||||
if ($existingListeners | Where-Object { $_.Transport -eq "HTTPS" }) {
|
||||
Write-Host "Failed to delete the existing HTTPS listener. Exiting script."
|
||||
exit 1
|
||||
}
|
||||
|
||||
# Create a new HTTPS listener
|
||||
Write-Host "Creating a new HTTPS listener..."
|
||||
$listenerCmd = "winrm create winrm/config/Listener?Address=*+Transport=HTTPS '@{Hostname=`"$(Get-WmiObject -Class Win32_ComputerSystem).DomainName`"; CertificateThumbprint=`"$certThumbprint`"}'"
|
||||
Invoke-Expression $listenerCmd
|
||||
|
||||
# Set TrustedHosts to allow connections from any IP address (adjust as needed for security)
|
||||
Write-Host "Setting TrustedHosts to allow any IP address..."
|
||||
winrm set winrm/config/client '@{TrustedHosts="*"}'
|
||||
|
||||
# Enable the firewall rule for WinRM over HTTPS
|
||||
Write-Host "Enabling firewall rule for WinRM over HTTPS..."
|
||||
$existingFirewallRule = Get-NetFirewallRule -DisplayName "WinRM HTTPS" -ErrorAction SilentlyContinue
|
||||
if (-not $existingFirewallRule) {
|
||||
New-NetFirewallRule -Name "WINRM-HTTPS-In-TCP-PUBLIC" -DisplayName "WinRM HTTPS" -Enabled True -Direction Inbound -Protocol TCP -LocalPort 5986 -RemoteAddress Any -Action Allow
|
||||
}
|
||||
|
||||
# Ensure Kerberos authentication is enabled
|
||||
Write-Host "Enabling Kerberos authentication for WinRM..."
|
||||
winrm set winrm/config/service/auth '@{Kerberos="true"}'
|
||||
|
||||
# Configure the WinRM service to use HTTPS and Kerberos
|
||||
Write-Host "Configuring WinRM service to use HTTPS and Kerberos..."
|
||||
winrm set winrm/config/service '@{AllowUnencrypted="false"}'
|
||||
|
||||
# Configure the WinRM client to use Kerberos
|
||||
Write-Host "Configuring WinRM client to use Kerberos..."
|
||||
winrm set winrm/config/client/auth '@{Kerberos="true"}'
|
||||
|
||||
# Ensure the PowerShell execution policy is set to allow remotely running scripts
|
||||
Write-Host "Setting PowerShell execution policy to RemoteSigned..."
|
||||
Set-ExecutionPolicy RemoteSigned -Force
|
||||
|
||||
Write-Host "Configuration complete. The Hyper-V host is ready for remote management over HTTPS with Kerberos authentication."
|
||||
```
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
tags:
|
||||
- Identity and Certificates
|
||||
- Workflows
|
||||
- Documentation
|
||||
---
|
||||
|
||||
# Identity and Certificates
|
||||
## Purpose
|
||||
Find workflows for identity and certificates. Follow the subject guide to choose the relevant environment and connect this material to the other document types.
|
||||
|
||||
## Includes
|
||||
- Active Directory
|
||||
- Certificates
|
||||
- Keycloak
|
||||
- Microsoft 365
|
||||
- Windows
|
||||
|
||||
## Follow the Subject
|
||||
[Identity and Certificates](<../../reference/Identity and Certificates/index.md>) explains the relationships and offers starting points for the documented tasks.
|
||||
Reference in New Issue
Block a user