top of page
Search


Zero Trust for the Home Lab - IPSec between Windows Domain and Linux using Certs (Part 7)
Rocky Linux version 10 is today's Linux OS of choice and part of the Zero Trust implementation for the home lab. The steps in this blog detail the implementation of IPSec between a Windows Domain and Linux using Strongswan.
Jul 25, 202512 min read


Zero Trust for the Home Lab - Yubikey and Domain Smartcard Authentication Setup (Part 6)
Smart cards store cryptographic certificates that enable two-factor authentication (2FA). Unlike passwords, these credentials cannot be easily stolen or reused, making it significantly harder for attackers to gain access and will be implemented as part of Zero Trust
Jun 7, 20256 min read


Zero Trust for the Home Lab - AD Delegation and Separation of Duties (Part 5)
Zero Trust - This blog will provide an in-depth explanation of the AD delegation model that has been delivered by PowerShell for a Zero Trust Network
Jun 7, 20258 min read


Zero Trust for the Home Lab - IPSec (Part 4)
Zero Trust assumes the network is hostile, even internal traffic can't be trusted without verification. Every connection must be authenticated, authorized, and encrypted. IPSec (Internet Protocol Security) is a key enabler. In this article, I'll implement IPSec in a Domain with certificates using the Microsoft Platform Crypto Provider is the Key Storage Provider (KSP) that allows certificates and their private keys to be stored in the TPM.
Jun 7, 202515 min read


Windows 11 24H2 Smartcard and Accessing File Share Issues with EventID 40960
The Security System detected an authentication error for the server cifs/DomainController. The failure code from authentication protocol NTLM was "The authentication failed since NTLM was blocked (0xc00004189)".
Apr 14, 20252 min read


Bitlocker a Closer Look
The concept of a private key in BitLocker differs from that of traditional asymmetric encryption, where two keys (a private key and a public
Dec 19, 20246 min read
bottom of page
