Tighten homelab security claims and documentation
ci/woodpecker/push/woodpecker Pipeline was successful
ci/woodpecker/push/woodpecker Pipeline was successful
This commit is contained in:
@@ -138,8 +138,8 @@ bglab\administrator
|
||||
| # | Problem | Fix | Status |
|
||||
|---|---|---|---|
|
||||
| 1 | PDC time source `Local CMOS Clock` (stratum 1 LOCL — would cause Kerberos skew failures as members drift) | `w32tm /config /manualpeerlist:"time.windows.com,0x9 pool.ntp.org,0x9 time.nist.gov,0x9" /syncfromflags:manual /reliable:yes /update` → PDC now stratum 5 syncing from `time.windows.com` (168.61.215.74) | **Fixed** |
|
||||
| 2 | Stale `dcdiag` SystemLog failure from an unexpected shutdown on 2026-08-07 | `wevtutil cl System`; re-ran `dcdiag /q` — silent | **Fixed** |
|
||||
| 3 | `bglab\keith` is a standard Domain User, couldn't WinRM into FILE01 (Access Denied) | `Add-ADGroupMember 'Domain Admins' keith` as `BGLAB\Administrator` — logged as lab maintenance | **Fixed** |
|
||||
| 2 | Stale `dcdiag` SystemLog failure from an unexpected shutdown on 2026-08-07 | Confirmed the stale shutdown event was the cause, cleared the lab System log, and re-ran `dcdiag /q` — silent. Production-safe procedure would export first with `wevtutil epl System <path>.evtx` before clearing. | **Fixed / procedure improved** |
|
||||
| 3 | `bglab\keith` is a standard Domain User, couldn't WinRM into FILE01 (Access Denied) | Temporarily added `keith` to `Domain Admins` for the lab audit. This restored WinRM access but is documented as a hardening gap; target state is a separate named admin account. | **Functional / hardening pending** |
|
||||
| 4 | FILE01 and DC01 on plain NAT (VMnet8), WIN11-01 on different segment — OPNsense doesn't see east-west server traffic | Documented; migration to pure VMnet2 behind OPNsense is a planned improvement | **Documented** |
|
||||
| 5 | WIN11-01 NIC bridged to physical LAN, no route to DC01 | Snapshots removed, TPM removed, vmx decrypted, adapter switched to NAT, DNS pointed at DC01, `Test-ComputerSecureChannel -Repair` — verified `True` | **Fixed** |
|
||||
| 6 | WIN11-01 vmx encrypted — blocked `vmrun` and automation | Removed via VMware GUI after snapshot/TPM removal | **Fixed** |
|
||||
@@ -149,4 +149,4 @@ bglab\administrator
|
||||
- No passwords, DSRM, krbtgt, SIDs, or recovery credentials captured in transcripts or portfolio artifacts.
|
||||
- Lab is behind VMware NAT; no inbound exposure to the host network or the internet.
|
||||
- Transcripts live under `D:\Repos\ad-lab\transcripts\` on the host, not on the DC.
|
||||
- `keith` was elevated to `Domain Admins` **in the lab only**; this account has no production use.
|
||||
- `keith` was elevated to `Domain Admins` **in the lab only** for this audit. That is not the target operating model; the hardening plan is a separate named admin account plus a non-privileged daily account.
|
||||
|
||||
@@ -118,8 +118,8 @@ Run from DC01 as `BGLAB\Administrator`, output captured to transcripts on the ho
|
||||
## Fixes performed
|
||||
|
||||
- Set external NTP on the PDC: `w32tm /config /manualpeerlist:"time.windows.com,0x9 pool.ntp.org,0x9 time.nist.gov,0x9" /syncfromflags:manual /reliable:yes /update`, `Restart-Service W32Time`, `w32tm /resync /rediscover`. Verified: `w32tm /query /source` now returns `time.windows.com,0x9`, stratum 5.
|
||||
- Cleared the stale System event log (`wevtutil cl System`); re-ran `dcdiag /q` — clean.
|
||||
- Added `keith` to `Domain Admins` as a documented lab-maintenance action so future audits run as my daily account instead of needing an Administrator sign-in each time. Lab-only elevation; this account has no production use.
|
||||
- Confirmed the stale unexpected-shutdown event was the source, cleared the lab System log, and re-ran `dcdiag /q` — clean. For production, preserve evidence first with `wevtutil epl System <path>.evtx` before clearing.
|
||||
- Added `keith` to `Domain Admins` as a lab-maintenance shortcut during this audit. That is intentionally documented as a hardening gap, not a best practice. The target state is a separate named administrative account and a non-privileged daily workstation account.
|
||||
|
||||
Client restoration (completed 2026-10-03, VMware GUI + guest PowerShell):
|
||||
|
||||
@@ -136,10 +136,12 @@ Client restoration (completed 2026-10-03, VMware GUI + guest PowerShell):
|
||||
|
||||
## Skills demonstrated
|
||||
|
||||
Windows Server 2022 administration · Active Directory Domain Services · DNS · OU and group design · users and groups · SMB file services · NTFS and share permissions · PowerShell (`Get-AD*`, `Invoke-Command`, `w32tm`, `Get-SmbShareAccess`, `Get-Acl`) · VMware Workstation Pro 17 · network segmentation with OPNsense · WinRM remoting · structured troubleshooting · writing honest audit documentation.
|
||||
Windows Server 2022 administration · Active Directory Domain Services · DNS · OU and group design · users and groups · SMB file services · NTFS and share permissions · PowerShell (`Get-AD*`, `Invoke-Command`, `w32tm`, `Get-SmbShareAccess`, `Get-Acl`) · VMware Workstation Pro 17 · OPNsense routing and segmentation lab design · WinRM remoting · structured troubleshooting · writing honest audit documentation.
|
||||
|
||||
## Future improvements
|
||||
|
||||
- Create a separate named administrative account, remove daily-user Domain Admin membership, and use least-privilege workstation sign-in.
|
||||
- Disable inherited `BUILTIN\Users` access on the IT folder and apply explicit NTFS ACLs for administrators and the intended department group.
|
||||
- Move DC01 and FILE01 behind OPNsense (VMnet2) so firewall rules actually see server-side traffic — foundation for the Net+/Sec+ firewall drills in my `opnsense-lab-networking` skill.
|
||||
- Publish HR and Sales shares with the same RBAC pattern already proven on the IT share.
|
||||
- Add a first GPO (desktop wallpaper or password policy) linked to `OU=Users,OU=ByteGeist`.
|
||||
|
||||
+15
-7
@@ -4,7 +4,7 @@
|
||||
<meta charset="UTF-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<title>ByteGeist Windows Server / AD Homelab — Keith Casko</title>
|
||||
<meta name="description" content="A verified Windows Server 2022 Active Directory homelab: DC01 with AD DS and DNS, FILE01 with role-based SMB shares, a Windows 11 domain client, and OPNsense firewall segmentation. Audited with PowerShell and WinRM." />
|
||||
<meta name="description" content="A verified Windows Server 2022 Active Directory homelab: DC01 with AD DS and DNS, FILE01 with role-based SMB share access, a Windows 11 domain client, and an OPNsense routing/segmentation lab. Audited with PowerShell and WinRM." />
|
||||
<link rel="stylesheet" href="css/styles.css" />
|
||||
</head>
|
||||
<body class="homelab-page">
|
||||
@@ -50,8 +50,8 @@
|
||||
kind of break/fix that shows up in interview questions.
|
||||
</p>
|
||||
<p>
|
||||
Everything on this page was captured from the live lab on
|
||||
<strong>2026-10-03</strong>. No fabricated screenshots, no stock art.
|
||||
The topology, command output, and configuration details on this page
|
||||
reflect the lab state verified on <strong>2026-10-03</strong>.
|
||||
</p>
|
||||
<div class="lab-tags">
|
||||
<span>Windows Server 2022</span>
|
||||
@@ -87,7 +87,7 @@
|
||||
<tr><td><strong>DC01</strong></td><td>Windows Server 2022 Standard</td><td>Domain Controller</td><td>192.168.31.10</td><td>AD DS, DNS, PDC Emulator, Schema & Domain Naming Master, Global Catalog</td></tr>
|
||||
<tr><td><strong>FILE01</strong></td><td>Windows Server 2022 Standard</td><td>Member server</td><td>192.168.31.20</td><td>SMB file services; <code>IT</code> departmental share</td></tr>
|
||||
<tr><td><strong>WIN11-01</strong></td><td>Windows 11 Education</td><td>Domain client</td><td>192.168.31.x (NAT)</td><td>Domain-joined workstation</td></tr>
|
||||
<tr><td><strong>OPNSENSE</strong></td><td>OPNsense (FreeBSD)</td><td>Firewall / router</td><td>VMnet8 ↔ VMnet2</td><td>Segmenting server (VMnet8) and client (VMnet2) networks</td></tr>
|
||||
<tr><td><strong>OPNSENSE</strong></td><td>OPNsense (FreeBSD)</td><td>Firewall / router</td><td>VMnet8 ↔ VMnet2</td><td>Segmentation lab; VMnet2 client placement is planned, while current systems remain on VMnet8</td></tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
@@ -172,6 +172,7 @@
|
||||
<tr><td><code>CREATOR OWNER</code></td><td>Full on child objects</td><td>Yes</td></tr>
|
||||
</tbody>
|
||||
</table>
|
||||
<p><strong>Hardening note:</strong> the inherited <code>BUILTIN\Users</code> entry is broader than the intended IT-only access model. The next ACL change is to disable inheritance and retain only the required administrative and IT group permissions.</p>
|
||||
</div>
|
||||
<div class="lab-panel">
|
||||
<h3>How it was verified</h3>
|
||||
@@ -216,9 +217,13 @@ w32tm /resync /rediscover</pre>
|
||||
<h3>Problem: stale <code>dcdiag</code> SystemLog failure</h3>
|
||||
<p>
|
||||
A past unexpected shutdown left an entry that <code>dcdiag</code> flagged on
|
||||
every run. Cleared the System log and re-ran <code>dcdiag /q</code>.
|
||||
every run. I confirmed the stale shutdown event was the source, cleared the
|
||||
lab System log, and re-ran <code>dcdiag /q</code>. In a production workflow,
|
||||
I would export the log before clearing it to preserve evidence.
|
||||
</p>
|
||||
<pre class="lab-code">wevtutil cl System
|
||||
<pre class="lab-code"># Production-safe sequence:
|
||||
wevtutil epl System C:\Temp\System-before-clear.evtx
|
||||
wevtutil cl System
|
||||
dcdiag /q</pre>
|
||||
<p class="status-ok">Verified: <code>dcdiag /q</code> now silent (clean).</p>
|
||||
<h3 class="h3-sub">Client domain restoration (completed)</h3>
|
||||
@@ -238,6 +243,9 @@ The command completed successfully
|
||||
PS> whoami
|
||||
bglab\administrator</pre>
|
||||
<p class="status-ok">Verified: secure channel healthy, DC01 reachable as PDC / GC / KDC / DNS.</p>
|
||||
<p><strong>Security note:</strong> this repair transcript was captured from a built-in
|
||||
Administrator maintenance session. A separate named administrative account and
|
||||
non-privileged daily workstation sign-in are the preferred next hardening step.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
@@ -253,7 +261,7 @@ bglab\administrator</pre>
|
||||
<li><strong>Windows Server 2022</strong> — installed, promoted to a DC, operate day-to-day.</li>
|
||||
<li><strong>Active Directory</strong> — domain / forest design, OUs, users and groups, FSMO awareness, Global Catalog.</li>
|
||||
<li><strong>DNS</strong> — AD-integrated primary zones, reverse zones, understanding why the client's DNS must point at the DC.</li>
|
||||
<li><strong>SMB & NTFS</strong> — share creation, share-level vs. NTFS permissions, role-based access through groups.</li>
|
||||
<li><strong>SMB & NTFS</strong> — share creation, share-level vs. NTFS permissions, and role-based access through groups. The current IT folder still inherits <code>BUILTIN\Users</code> permissions; disabling inheritance and applying explicit ACLs is a documented hardening task.</li>
|
||||
<li><strong>PowerShell</strong> — <code>Get-AD*</code>, <code>Invoke-Command</code>, <code>Get-SmbShareAccess</code>, <code>Get-Acl</code>, <code>w32tm</code>, <code>Test-ComputerSecureChannel</code>.</li>
|
||||
<li><strong>Troubleshooting</strong> — recognizing <em>Local CMOS Clock</em> as a future Kerberos failure; diagnosing a broken secure channel as a bridged-NIC / wrong-DNS fault and restoring it with <code>Test-ComputerSecureChannel -Repair</code>.</li>
|
||||
<li><strong>Virtualization & networking</strong> — VMware Workstation Pro, VMnet subnetting, OPNsense placement, bridged vs. NAT NIC implications.</li>
|
||||
|
||||
+8
-12
@@ -96,10 +96,10 @@
|
||||
<p>
|
||||
Windows Server 2022 Active Directory lab in VMware: domain
|
||||
controller with AD DS and DNS, member file server with
|
||||
role-based SMB shares, Windows 11 domain client, and an
|
||||
OPNsense firewall segmenting the networks. Audited and fixed
|
||||
real problems (PDC time source, stale event log) via
|
||||
PowerShell and WinRM.
|
||||
role-based SMB share access, a Windows 11 domain client, and
|
||||
an OPNsense firewall/router used for segmentation practice.
|
||||
The current client and servers remain on VMnet8 while the
|
||||
VMnet2 segmented client layout is the next networking exercise.
|
||||
</p>
|
||||
<a class="view-link" href="homelab.html">View Lab Details</a>
|
||||
</div>
|
||||
@@ -311,15 +311,11 @@
|
||||
<div class="panel">
|
||||
<h3>Western Governors University</h3>
|
||||
<div class="meta">Bachelor of Science, Software Engineering · In Progress</div>
|
||||
<h4>Relevant Study</h4>
|
||||
<h4>Recent Coursework</h4>
|
||||
<ul>
|
||||
<li>Cloud Computing</li>
|
||||
<li>Networking</li>
|
||||
<li>IT Operations</li>
|
||||
<li>Software Development</li>
|
||||
<li>Java</li>
|
||||
<li>Web Development</li>
|
||||
<li>Security Fundamentals</li>
|
||||
<li>Cloud Foundations — completed</li>
|
||||
<li>Java Frameworks — completed project work</li>
|
||||
<li>Hardware & Operating Systems Essentials — current study</li>
|
||||
</ul>
|
||||
</div>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user