Files
Keith Casko 91fdb51f58
ci/woodpecker/push/woodpecker Pipeline was successful
Tighten homelab security claims and documentation
2026-10-06 08:02:35 -04:00

305 lines
16 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>ByteGeist Windows Server / AD Homelab &mdash; Keith Casko</title>
<meta name="description" content="A verified Windows Server 2022 Active Directory homelab: DC01 with AD DS and DNS, FILE01 with role-based SMB share access, a Windows 11 domain client, and an OPNsense routing/segmentation lab. Audited with PowerShell and WinRM." />
<link rel="stylesheet" href="css/styles.css" />
</head>
<body class="homelab-page">
<header class="site-header" role="banner">
<div class="container">
<div class="brand">
<a class="brand-home" href="index.html#home" aria-label="Keith Casko home">
<span class="name">Keith Casko</span>
<span class="tagline">
IT Support &nbsp;|&nbsp; Systems Administration &nbsp;|&nbsp; Cloud Operations
<span class="location">Kalamazoo, MI</span>
</span>
</a>
</div>
<button class="nav-toggle" aria-expanded="false" aria-controls="primary-nav">Menu</button>
<nav class="site-nav" id="primary-nav" aria-label="Primary">
<ul>
<li><a href="index.html#projects" class="active">Projects</a></li>
<li><a href="index.html#skills">Skills</a></li>
<li><a href="index.html#credentials">Credentials</a></li>
<li><a href="index.html#about">About</a></li>
<li><a href="index.html#contact">Contact</a></li>
<li><a class="nav-resume" href="assets/resume/Keith_Casko_IT_Cloud_Resume.pdf" download>Resume</a></li>
</ul>
</nav>
</div>
</header>
<main>
<section class="hero" id="top" aria-labelledby="lab-title">
<div class="container">
<div class="lab-hero">
<div class="lab-hero-text">
<p class="eyebrow"><a href="index.html#projects">&larr; Projects</a></p>
<h1 id="lab-title">ByteGeist Windows Server / AD Homelab</h1>
<p class="lede">
A multi-VM Windows Server 2022 Active Directory environment I run on
VMware Workstation Pro to practice day-to-day Help Desk and Junior
SysAdmin work: domain services, DNS, OU and group design, SMB file
sharing with role-based access, PowerShell troubleshooting, and the
kind of break/fix that shows up in interview questions.
</p>
<p>
The topology, command output, and configuration details on this page
reflect the lab state verified on <strong>2026-10-03</strong>.
</p>
<div class="lab-tags">
<span>Windows Server 2022</span>
<span>Active Directory DS</span>
<span>DNS</span>
<span>SMB &amp; NTFS</span>
<span>PowerShell / WinRM</span>
<span>VMware Workstation</span>
<span>OPNsense</span>
</div>
</div>
<figure class="lab-hero-figure">
<img src="assets/images/homelab-topology.svg"
alt="Topology diagram: DC01 (192.168.31.10) and FILE01 (192.168.31.20) on VMnet8/NAT, OPNsense between VMnet8 and VMnet2, WIN11-01 domain-joined client" />
<figcaption>Verified topology &mdash; generated from <code>ipconfig</code>, <code>Get-ADDomain</code>, <code>Get-SmbShare</code>, and VMware <code>vmnetdhcp.conf</code>.</figcaption>
</figure>
</div>
</div>
</section>
<section id="systems" aria-labelledby="systems-title">
<div class="container">
<div class="section-head">
<h2 id="systems-title">Systems</h2>
<span class="subtitle">Four VMs, verified from <code>vmrun</code> and in-guest audits</span>
</div>
<div class="lab-table-wrap">
<table class="lab-table">
<thead>
<tr><th>System</th><th>Operating System</th><th>Role</th><th>Address</th><th>Purpose</th></tr>
</thead>
<tbody>
<tr><td><strong>DC01</strong></td><td>Windows Server 2022 Standard</td><td>Domain Controller</td><td>192.168.31.10</td><td>AD DS, DNS, PDC Emulator, Schema &amp; Domain Naming Master, Global Catalog</td></tr>
<tr><td><strong>FILE01</strong></td><td>Windows Server 2022 Standard</td><td>Member server</td><td>192.168.31.20</td><td>SMB file services; <code>IT</code> departmental share</td></tr>
<tr><td><strong>WIN11-01</strong></td><td>Windows 11 Education</td><td>Domain client</td><td>192.168.31.x (NAT)</td><td>Domain-joined workstation</td></tr>
<tr><td><strong>OPNSENSE</strong></td><td>OPNsense (FreeBSD)</td><td>Firewall / router</td><td>VMnet8 &harr; VMnet2</td><td>Segmentation lab; VMnet2 client placement is planned, while current systems remain on VMnet8</td></tr>
</tbody>
</table>
</div>
</div>
</section>
<section id="ad" aria-labelledby="ad-title">
<div class="container">
<div class="section-head">
<h2 id="ad-title">Active Directory &amp; DNS</h2>
<span class="subtitle">Captured from <code>Get-ADDomain</code> / <code>Get-ADForest</code> on DC01</span>
</div>
<div class="lab-grid-2">
<div class="lab-panel">
<h3>Forest &amp; Domain</h3>
<ul class="kv">
<li><span>Forest / Domain</span><code>ad.bytegeist.lab</code></li>
<li><span>NetBIOS</span><code>BGLAB</code></li>
<li><span>Forest mode</span><code>Windows2016Forest</code></li>
<li><span>Domain mode</span><code>Windows2016Domain</code></li>
<li><span>FSMO roles</span>all held by <code>DC01</code></li>
<li><span>Global Catalog</span><code>DC01</code></li>
<li><span>DNS zones</span><code>ad.bytegeist.lab</code>, <code>_msdcs.ad.bytegeist.lab</code>, 3 reverse</li>
<li><span>PDC time source</span><code>time.windows.com</code> (fixed from <code>Local CMOS</code>)</li>
</ul>
</div>
<div class="lab-panel">
<h3>Organizational Units</h3>
<pre class="lab-tree">ad.bytegeist.lab/
├── ByteGeist/
│ ├── Groups
│ ├── Servers
│ ├── Workstations
│ └── Users/
│ ├── HR
│ ├── IT
│ └── Sales
└── Domain Controllers</pre>
<h3 class="h3-sub">Lab-created groups</h3>
<p class="mono-list">
Accounting &middot; Help Desk &middot; HR Employees &middot;
IT Employees &middot; Management &middot; Sales Employees &middot;
VPN Users
</p>
</div>
</div>
</div>
</section>
<section id="files" aria-labelledby="files-title">
<div class="container">
<div class="section-head">
<h2 id="files-title">File services &amp; permissions</h2>
<span class="subtitle">FILE01 &mdash; <code>Get-SmbShareAccess</code> and <code>Get-Acl</code></span>
</div>
<p>
FILE01 publishes one departmental share and uses the <code>IT Employees</code>
security group to grant access &mdash; accounts never get rights directly on
resources, groups do. The share-level cap is <strong>Change</strong>; NTFS
grants <strong>Modify</strong> explicitly to <code>BGLAB\IT&nbsp;Employees</code>.
</p>
<div class="lab-grid-2">
<div class="lab-panel">
<h3>Share <code>IT</code> at <code>C:\Shares\IT</code></h3>
<h4>Share-level ACL</h4>
<table class="lab-table lab-table-sm">
<thead><tr><th>Account</th><th>Type</th><th>Right</th></tr></thead>
<tbody>
<tr><td><code>BGLAB\Domain Admins</code></td><td>Allow</td><td>Full</td></tr>
<tr><td><code>BGLAB\IT Employees</code></td><td>Allow</td><td>Change</td></tr>
</tbody>
</table>
<h4>NTFS ACL</h4>
<table class="lab-table lab-table-sm">
<thead><tr><th>Identity</th><th>Rights</th><th>Inherited</th></tr></thead>
<tbody>
<tr><td><code>BGLAB\IT Employees</code></td><td>Modify, Synchronize</td><td>No (explicit)</td></tr>
<tr><td><code>NT AUTHORITY\SYSTEM</code></td><td>FullControl</td><td>Yes</td></tr>
<tr><td><code>BUILTIN\Administrators</code></td><td>FullControl</td><td>Yes</td></tr>
<tr><td><code>BUILTIN\Users</code></td><td>ReadAndExecute + CreateFiles + AppendData</td><td>Yes</td></tr>
<tr><td><code>CREATOR OWNER</code></td><td>Full on child objects</td><td>Yes</td></tr>
</tbody>
</table>
<p><strong>Hardening note:</strong> the inherited <code>BUILTIN\Users</code> entry is broader than the intended IT-only access model. The next ACL change is to disable inheritance and retain only the required administrative and IT group permissions.</p>
</div>
<div class="lab-panel">
<h3>How it was verified</h3>
<pre class="lab-code">PS&gt; Invoke-Command FILE01 {
Get-SmbShare |
Where-Object Name -NotIn 'ADMIN$','C$','IPC$' |
Get-SmbShareAccess
(Get-Acl C:\Shares\IT).Access
}</pre>
<p>
Run from DC01 as a Domain Admin via WinRM, output captured to a transcript
on the host (not inside the VM) so no sensitive data lives on a shared
share.
</p>
</div>
</div>
</div>
</section>
<section id="validation" aria-labelledby="validation-title">
<div class="container">
<div class="section-head">
<h2 id="validation-title">Validation &amp; fixes applied</h2>
<span class="subtitle">Real problems found &amp; resolved during the audit</span>
</div>
<div class="lab-grid-2">
<div class="lab-panel">
<h3>Problem: PDC was using the local CMOS clock</h3>
<p>
The PDC Emulator is the authoritative time source for a Windows forest.
If it drifts, Kerberos tickets outside the 5-minute skew window fail &mdash;
a classic "I can't log in" root cause. <code>w32tm /query /source</code>
returned <code>Local CMOS Clock</code>.
</p>
<pre class="lab-code">w32tm /config /manualpeerlist:"time.windows.com,0x9 pool.ntp.org,0x9 time.nist.gov,0x9" `
/syncfromflags:manual /reliable:yes /update
Restart-Service W32Time
w32tm /resync /rediscover</pre>
<p class="status-ok">Verified: <code>Source: time.windows.com,0x9</code>, Stratum 5.</p>
</div>
<div class="lab-panel">
<h3>Problem: stale <code>dcdiag</code> SystemLog failure</h3>
<p>
A past unexpected shutdown left an entry that <code>dcdiag</code> flagged on
every run. I confirmed the stale shutdown event was the source, cleared the
lab System log, and re-ran <code>dcdiag /q</code>. In a production workflow,
I would export the log before clearing it to preserve evidence.
</p>
<pre class="lab-code"># Production-safe sequence:
wevtutil epl System C:\Temp\System-before-clear.evtx
wevtutil cl System
dcdiag /q</pre>
<p class="status-ok">Verified: <code>dcdiag /q</code> now silent (clean).</p>
<h3 class="h3-sub">Client domain restoration (completed)</h3>
<p>
WIN11-01's NIC was moved from a bridged physical-LAN adapter to the lab
NAT network, DNS was pointed at DC01, and the machine account trust was
repaired. Verified domain authentication and DC discovery:
</p>
<pre class="lab-code">PS&gt; Test-ComputerSecureChannel -Verbose
VERBOSE: The secure channel between the local computer and the domain ad.bytegeist.lab is in good condition.
True
PS&gt; nltest /dsgetdc:ad.bytegeist.lab
DC: \\DC01.ad.bytegeist.lab
Address: \\192.168.31.10
Flags: PDC GC DS LDAP KDC TIMESERV ... DNS_DC DNS_DOMAIN DNS_FOREST
The command completed successfully
PS&gt; whoami
bglab\administrator</pre>
<p class="status-ok">Verified: secure channel healthy, DC01 reachable as PDC / GC / KDC / DNS.</p>
<p><strong>Security note:</strong> this repair transcript was captured from a built-in
Administrator maintenance session. A separate named administrative account and
non-privileged daily workstation sign-in are the preferred next hardening step.</p>
</div>
</div>
</div>
</section>
<section id="skills" aria-labelledby="skills-title">
<div class="container">
<div class="section-head">
<h2 id="skills-title">Skills demonstrated</h2>
<span class="subtitle">Why this project matters for IT roles</span>
</div>
<ul class="lab-skill-list">
<li><strong>Windows Server 2022</strong> &mdash; installed, promoted to a DC, operate day-to-day.</li>
<li><strong>Active Directory</strong> &mdash; domain / forest design, OUs, users and groups, FSMO awareness, Global Catalog.</li>
<li><strong>DNS</strong> &mdash; AD-integrated primary zones, reverse zones, understanding why the client's DNS must point at the DC.</li>
<li><strong>SMB &amp; NTFS</strong> &mdash; share creation, share-level vs. NTFS permissions, and role-based access through groups. The current IT folder still inherits <code>BUILTIN\Users</code> permissions; disabling inheritance and applying explicit ACLs is a documented hardening task.</li>
<li><strong>PowerShell</strong> &mdash; <code>Get-AD*</code>, <code>Invoke-Command</code>, <code>Get-SmbShareAccess</code>, <code>Get-Acl</code>, <code>w32tm</code>, <code>Test-ComputerSecureChannel</code>.</li>
<li><strong>Troubleshooting</strong> &mdash; recognizing <em>Local CMOS Clock</em> as a future Kerberos failure; diagnosing a broken secure channel as a bridged-NIC / wrong-DNS fault and restoring it with <code>Test-ComputerSecureChannel -Repair</code>.</li>
<li><strong>Virtualization &amp; networking</strong> &mdash; VMware Workstation Pro, VMnet subnetting, OPNsense placement, bridged vs. NAT NIC implications.</li>
<li><strong>Honest audit documentation</strong> &mdash; problems (PDC time source, bridged client NIC) recorded with the exact fix applied, not hidden.</li>
</ul>
</div>
</section>
<section>
<div class="container">
<div class="contact-cta">
<div>
<h2>Want to see the full audit log?</h2>
<p>Phases, verified command output, problem-and-fix table, security notes.</p>
</div>
<div class="contact-actions">
<a class="btn btn-primary" href="docs/windows-server-homelab.md">Project write-up</a>
<a class="btn btn-secondary" href="docs/homelab-audit.md">Full audit log</a>
</div>
</div>
</div>
</section>
</main>
<footer class="site-footer" role="contentinfo">
<div class="container">
<div>&copy; <span id="year">2026</span> Keith Casko. All rights reserved.</div>
<ul class="footer-links">
<li><a href="assets/resume/Keith_Casko_IT_Cloud_Resume.pdf" download>Resume</a></li>
<li><a href="https://github.com/kcasko" rel="noopener">GitHub</a></li>
<li><a href="https://www.linkedin.com/in/keith-casko/" rel="noopener">LinkedIn</a></li>
<li><a href="mailto:keith.casko@gmail.com">Email</a></li>
</ul>
</div>
</footer>
<script src="js/main.js" defer></script>
</body>
</html>