AWS WorkSpace - allow only trusted devices with certificate authentication

Viewed 1975

I am trying to implement Allow only trusted devices feature on AWS Workspaces with simple AD.

Can someone please guide me how to generate self-signed root & client certificate with following features.

Certificates must be Base64-encoded certificate files in CRT, CERT, or PEM format. Certificates must include a Common Name. The maximum length of certificate chain supported is 4. Amazon WorkSpaces does not currently support device revocation mechanisms, such as certificate revocation lists (CRL) or Online Certificate Status Protocol (OCSP), for client certificates. Use a strong encryption algorithm. We recommend SHA256 with RSA, SHA256 with CEDSA, SHA381 with CEDSA, or SHA512 with CEDSA.

2 Answers

Thanks @IchingChang, article https://www.brunton-spall.co.uk/post/2020/04/28/Using-AWS-Workspaces/ is really helpful.

For future readers, if you still struggling with this problem, also try with bruntonspall's github link: https://github.com/bruntonspall/AWSWorkspacesCA

The following step is create all keys and certificates in same machine (CA machine), for prod use case, you should create client public and private key in client machine:

  1. (only do this step if you want to renew or did not create and upload your CA public key before) run ./CA/gen_CA.sh, which will generate CA's private and public key, copy the public key (.pem file) and upload it onto AWS Workspaces's Directory Service's Access Control Options (https://docs.aws.amazon.com/workspaces/latest/adminguide/trusted-devices.html#configure-restriction).
  2. run ./client/gen_client.sh, which will generate client private and public key and corresponding CA sign certificate.
  3. copy pfx (or say p12) certificate file to your windows laptop, click install, select current user and personal store.

Now you should be able to login with your workspaces client (suppose you already setup AWS Workspaces side correctly with other settings).

Related