View Full Version : Non-console rdp access for windows systems
echain
07-07-2008, 04:39 AM
A quick question. In your experience, does the Windows RDP protocol qualify to comply with requirement 2.3 for logging into windows servers remotely (non-console access)? It natively can be configured for Medium or High encryption, but there are some known "man-in-the-middle" vulnerabilities for this protocol (see http://www.oxid.it/downloads/rdp-gbu.pdf). If this protocol is only being used internally or through a VPN, will it still qualify?
jbhall56
07-07-2008, 11:44 AM
I don't have a problem with RDP as long as:
It is used ONLY internally or over a VPN with two factor authentication if connecting from an external location;
ONLY high encryption connections are allowed; and
Unique user logon credentials are used by all that have access.
echain
07-08-2008, 02:44 AM
Thanks
:)
timcaldwell1
07-09-2008, 08:17 PM
Does RDP also meet the PCI requirements for Logging?
jbhall56
07-10-2008, 03:16 AM
As long as you have the proper settings enabled in the Local Security Policy under System Auditing set, there should not be a problem. This can be accomplished either manually on an individual machine basis or through a Group Policy Object (GPO). If using GPOs, we recommend that the GPO be specifically created and named for PCI compliance so that it can be readily identified and its parameter settings listed off.
vBulletin® v3.7.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.