- 181
- 136 241
Keytos Security
United States
Приєднався 29 бер 2021
Keytos has revolutionized the Identity Management and PKI industry by creating cryptographic tools that allow you to go password-less by making security transparent to the user.
The Keytos toolset protects our customers by automating identity management tasks across their multi-cloud and hybrid stacks. Preventing identity related outages and breaches, while freeing resources to focus on other critical security tasks.
The Keytos toolset protects our customers by automating identity management tasks across their multi-cloud and hybrid stacks. Preventing identity related outages and breaches, while freeing resources to focus on other critical security tasks.
The Most Powerful Cloud RADIUS Got Better What is New in EZRADIUS in 2025
EZRADIUS just got a major update, making it an even better cloud RADIUS for Microsoft 365 and Entra ID. Learn about the latest features
Learn More www.keytos.io/cloud-radius-as-a-service-for-azure-and-entra-id
Learn More www.keytos.io/cloud-radius-as-a-service-for-azure-and-entra-id
Переглядів: 25
Відео
How to Setup Self-Service FIDO2 onboarding and Entra CBA with EZCMS From Start to Finish
Переглядів 4314 днів тому
Are you trying to setup Entra CBA and FIDO2 in Microsoft 365 / Entra ID? In this video we teach you how to setup self service FIDO2 and Entra CBA Onboarding in less than 30 minutes. Docs: www.keytos.io/docs/passwordless-onboarding/ Learn More about EZCMS Yubikey Onboarding Solution: www.keytos.io/passwordless-onboarding Learn More about EZCA Cloud PKI: www.keytos.io/azure-pki 0:00 Intro 0:35 Cr...
FIDO2 and Entra CBA Onboarding Just Got Easier: Whats New in EZCMS
Переглядів 5321 день тому
If you are looking to onboard your #fido2 key and Entra CBA, The already powerful EZCMS onboarding tool for phishing resistant onboarding just got better and easier to use, so get your YubiKey or FEITIAN key ready and go password less today! Learn more about EZCMS www.keytos.io/passwordless-onboarding
How To Use Entra ID For SSH - Sir Tifficate explains to Tux about EZSSH
Переглядів 18628 днів тому
Tux learns that Linux has not been forgotten on the Entra ID and Microsoft world. Sir Tifficate explains how EZSSH helps you authenticate to linux using entra ID. You can learn more about EZSSH and Linux Authentication: www.keytos.io/passwordless-ssh-authentication
How To Issue SCEP Certificates to Domain Joined Windows Devices
Переглядів 76Місяць тому
You are using Intune to Issue SCEP Certificates, however, you still have some domain joined windows machines and are looking at how to issue SCEP certificates for them? Learn how EZCA can help you Issue certificates for both Intune and Domain Joined Machines. github.com/markeytos/Certificate-Renewal-Client www.keytos.io/azure-pki
How To Enable WebEnroll for ADCS in Azure
Переглядів 34Місяць тому
Enable Web Based Certificate Issuance for your Active Directory Certificate Services (ADCS) CA, or for a cloud-based Azure PKI using EZCA. This will enable you to allow access to your users using their Entra ID identity. Learn About Azure PKI www.keytos.io/azure-pki
How To Automatically Rotate Azure Key Vault Private Certificates
Переглядів 83Місяць тому
Are you looking for a way to Automate your Private Certificates in Azure Key Vault? EZCA can connect to your existing PKI or create a cloud-based certificate authority in Azure and connect to Azure Key Vault for Automatic Certificate Rotation. Learn more about Azure PKI www.keytos.io/azure-pki
How to Issue Linux SCEP Certificates in Intune
Переглядів 93Місяць тому
Are you trying to distribute wifi certificates on Linux with Intune? In this video we go over how to Issue SCEP certificates to Linux Devices in Intune Docs for Linux SCEP certificates in Intune: www.keytos.io/docs/azure-pki/create-ssl-certificates-with-mdm/intune-certificate-authority/create-intune-certificate-profiles/how-to-create-linux-scep-certificates-in-intune/
How To Go Passworldess in Hybrid Environments - FEITIAN Webinar
Переглядів 1792 місяці тому
How To Go Passworldess in Hybrid Environments - FEITIAN Webinar
How To Find Similar Domains that Might Be Phishing Your Customers
Переглядів 782 місяці тому
How To Find Similar Domains that Might Be Phishing Your Customers
How Phishing Resistant Authentication Works
Переглядів 1702 місяці тому
How Phishing Resistant Authentication Works
How EAP-TLS Wi-Fi Certificate Authentication Works
Переглядів 1,3 тис.3 місяці тому
How EAP-TLS Wi-Fi Certificate Authentication Works
How To Connect to Wi-Fi Using Entra ID Using Cloud RADIUS
Переглядів 5503 місяці тому
How To Connect to Wi-Fi Using Entra ID Using Cloud RADIUS
Can I Go Passwordless with Windows Hello For Business
Переглядів 16 тис.3 місяці тому
Can I Go Passwordless with Windows Hello For Business
How To Enable MAC Address Authentication in Cloud RADIUS
Переглядів 2193 місяці тому
How To Enable MAC Address Authentication in Cloud RADIUS
How To Prevent Phishing Attacks with Unphishable credentials - Sir Tifficate Journey to Zero Trust
Переглядів 763 місяці тому
How To Prevent Phishing Attacks with Unphishable credentials - Sir Tifficate Journey to Zero Trust
How To Install EAP-TLS Wifi Proflies for Apple Devices Using EZRADIUS
Переглядів 6134 місяці тому
How To Install EAP-TLS Wifi Proflies for Apple Devices Using EZRADIUS
How To Create Wi-Fi Certificates Without Intune
Переглядів 3154 місяці тому
How To Create Wi-Fi Certificates Without Intune
FIDO2 + SmartCard (PIV) functionality is the best hardware token for Entra ID and Active Directory
Переглядів 6274 місяці тому
FIDO2 SmartCard (PIV) functionality is the best hardware token for Entra ID and Active Directory
Why Should You Modernized Your PKI and Move your Certificate Authorities to the Cloud
Переглядів 1075 місяців тому
Why Should You Modernized Your PKI and Move your Certificate Authorities to the Cloud
How To Troubleshoot RADIUS with EZRADIUS Cloud RADIUS
Переглядів 1635 місяців тому
How To Troubleshoot RADIUS with EZRADIUS Cloud RADIUS
The problem with SSH keys. Are SSH Keys Secure?
Переглядів 3925 місяців тому
The problem with SSH keys. Are SSH Keys Secure?
What Certificate Authority To Use for Azure IoT
Переглядів 996 місяців тому
What Certificate Authority To Use for Azure IoT
Setup Meraki VPN to User RADIUS with Entra ID
Переглядів 5276 місяців тому
Setup Meraki VPN to User RADIUS with Entra ID
How to Enable Certificate Based Authentication in Meraki Networks with EZRADIUS Cloud RADIUS
Переглядів 1,7 тис.6 місяців тому
How to Enable Certificate Based Authentication in Meraki Networks with EZRADIUS Cloud RADIUS
Great video! The right tools are a must for MSPs. Robust cybersecurity, reliable backups, and Thirdlane Multi Tenant PBX help maintain secure and efficient communication.
Just wondering, what is that device model? Does it have a mac-based radius authentication and does it have an option for bandwidth accounting?
I don't remember which model we used for the video but it works with any TP link that supports RADIUS. Yes we also support Mac-Based auth www.keytos.io/docs/cloud-radius/manage-cloud-radius-pap-user-passwords/how-to-enable-mac-address-bypass/ and accounting
Thanks for this wonderful knowledge base. Just to know one thing ... can we have fido2keys stored on smartcard..... just for curious about it...
There are new smartcards that now also support FIDO2 keys. If you purchase one of those then yes the same smartcard can have both the FIDO2 and the SmartCard Certificate
Hey buddy I see you’ve done a lot of videos and are quite dedicated and knowledgeable about what you do. I just want to show my sincere appreciation for your hard work.m and cheer you one. Good luck in life.
Thank you for the kind words, I really appreciate it!
A better analogy which can be more easily understood world wide is your passport issuance office. DMV means nothing to me in the UK it would be DVLA instead 😢.
Where did you get the certificate ? I missed that part
We used EZCA, here is a video that guides you through the whole process ua-cam.com/video/LV6gN15QWLI/v-deo.htmlsi=Hdhsh9DicdUlpIz3
great information
Jepang
awafull music in the background , which is also too loud
For curiosity, which unifi device did you use for this example?
I don't remember which model we used for the video but it works with any UniFi that supports RADIUS
How do you prevent token loss? It’s all good until they steal a valid cookie.
While using phishing resistant credentials dramatically reduce the attack surface, you are correct it is not a silver bullet for that you have to have a defense in layers. Depending on your organization needs it might even mean having dedicated workstations and identities just for production (Microsoft PAW), these are some of the steps we take here at Keytos: www.keytos.io/blog/cloud-security/azure-ad-identity-security-best-practices
Please clarify this for me. You are adding a public IP address to Meraki for the Radius server but not selecting "RadSec," so how is the connection secured? My understanding is that radius auth via the WAN is not an encrypted connection unless you are using a VPN or RadSec.
EAP-TLS creates a TLS tunnel by default using the server and client certificate. If you are using EAP-TTLS then it is encrypted using the server certificate. We have a video explaining that here: ua-cam.com/video/A-rNeYL9BUI/v-deo.html
How about OpenVPN?
Unfortunately OpenVPN uses a RADIUS protocol that is not supported by Entra ID
You bet I keep using passwords. Using the same way to unlock your device to unlock all your accounts is stupid. It reduces security as a hacker only needs to steal one thing to get into ALL your accounts at once.
BUT USEFUL 🤣🤣🤣🤣
which way is he looking
That is an excellent explanation! Just reviewing for a Job Interview.
Best of luck in the interview :)
Thank you!
Simple Explanation
Everyone and no one 🦎
Who is this guy looking at?
Hi there, Will this work for Entra ID accounts that have MFA?
Unfortunately not, this is for username and password authentication. For a more secure authentication we recommend using certificates issued by your MDM ua-cam.com/video/LV6gN15QWLI/v-deo.html
We have tested this feature, it is working fine on windows, android devices, however, it is not working on iPhones, it seems the iPhones doesn't support EAP-TTLS/PAP by default, any workaround for this?
Hi, yes there is, you must create a profile for the iPhone, www.keytos.io/docs/cloud-radius/setup-radius-in-mdm/in-device/#how-to-configure-eap-ttlspap-on-macos-for-radius-authentication-with-entra-id-passwords
nice graphics but the amount of content does not match the title.
Thanks for the feedback, we have updated the title to match the content
hay i cannot login to keytos with my Gmail am i supposed to have a work email for this to work?
yes, this is only for Microsoft 365 work accounts
wooooowwwwwwwww
Can we try Ezca demo edition for free ?? Also, Ezca is based on Ejbca or Mspki in the backend ?
Yes, you can try it for free no credit card required www.keytos.io/docs/azure-pki/getting-started/registering-a-new-tenant/selecting-a-plan/select_plan_in_ezca/ We use our own in house built Certificate Authority as our backend this was built to be cloud native allowing us to scale faster while being more affordable.
Good I got here before a lot of people see this. This only affects you if you're on a public Wi-Fi and it is configured to where you can see other users on the network. If you use public Wi-Fi is a lot. Then yes you definitely need this update. If you're just at home on your Wi-Fi. As long as somebody doesn't get access to your internet. You are fine. They need to physically be on your network. They can't just drop a packet from outside the network without authentication. Yes it is a severe vulnerability and it affects all versions of Windows. But it only affects people who are on the same Wi-Fi as the attacker. This needs to be clarified.
you saved me from tons of hours of investigation, pretty appreciated. cheers man
As i said on the other channel of this guy (for whatever reason he has 2 of them). Attacker needs to be in range of your wifi card. The malicious packet is sent to the device itself. If you are not connect anywhere you are still vulnereable
@@aridlintm Okay, first off, you have to be using your laptop per se if you're out in public. Not connected to a Wi-Fi. If you put your laptop to sleep, it's not sending or receiving packets anymore. Unless you are connected to a Wi-Fi. The only way that somebody could be in proximity to you without you being connected to a wireless network is if you are using your machine, out in public, willy-nilly without an internet connection, and who does that?
Thanks for the interesting and exemplary information. At JetSoftPro, a software development service, we see these trends in cybersecurity continuing today. The trend is also constant verification of protection, such as a penetration test or a simulation of a phishing attack
nice info
They sound different to me.
You are correct, they are different, but the underlying technology is the same for both
Is that Cloudflare doing that thing with their lava lamps?
They do use lava lamps for some of their random generators, but for most encryption they use the regular random generators that are approved by the industry www.cloudflare.com/learning/ssl/lava-lamp-encryption/
From this video, i dont see how OSCP is better than a CRL.
It is not better, they are both great tools for checking revocation, one offloads the search to the server and the other to the device. Most devices use CRL but for devices or networks that cannot handle large CRLs, OCSP is a great option.
www.keytos.io/blog/passwordless/what-are-ssh-certificates.html
Informative. Thank you
Glad it was helpful!
I could not listen to you. Please, volume down.
thanks for the feedback we will make sure to change it in our next videos
music is too loud
thanks for the feedback we will make sure to change it in our next videos
Do you have any job opportunities for cyber security professional?
you can always check our www.keytos.io/careers page for the latest job postings
I can't create a subscription without entering a credit card number. Is this really free, or is it only free for a month?
you should be able to create a test subscription by clicking skip for now. It is only free for a month, after the first month it is $200 per CA per month and can be charged either to your credit card or to your Azure account.
Great explanation! The spokesman makes the issue clear and interesting.
I have to admit it was a very concise video - both short and helpful :)
Thanks for sharing, but your face blocks the content. Can't see some stuff :(((
Sorry about that, here is the presentation with all the information marketing.keytos.io/hubfs/Presentations/Cybersecurity%20Trends%20for%202024.pdf
Very interesting!
I notice there is no password or other authorization information other than the SCEP URL being unique and difficult to guess. If someone has your SCEP URL could they enroll into your service without having any passphrase and obtain a certificate for your infrastructure? If the SCEP URL is the only thing authorizing enrollment creation, then it might be good to note that in the UI (please keep this URL private). I also assume that that URL is not embedded into the certs issued?
Hi thanks for your comment - while the experience seems simple, what happens in the backend is more complex; we talk about it at 4:30, but the gist is that each request has an encrypted password that is set by the MDM and EZCA (Intune sets their own, some MDM solutions only support a static password that is encrypted with the CA public key meaning that the CA is the only one that can access it, and some support dynamic challenge requests meaning that each specific request has it's own password set by the CA (this one is also encrypted), if you are interested, we have a full deep dive on how SCEP works in this video ua-cam.com/video/da6LrQJcSgs/v-deo.html please let us know if you have other questions
Awesome! Thanks!
Great video! i am studying for my enterprise network administration exam for university and this was great for providing clarity on the difference between private and public CA's
Glad we could help:)
Is it possible to place pages on a captured subdomain?
yes, anyone with an Azure account can create those resources and create pages. This is why we recommend all organizations to verify that they do not have any dangling DNS that can be exploited.
TIL
That loop was CLEAN
Sir Tificate rules!!
Hi, does Keytos have a OCSP endpoint in their offerings? Specifically in EZCA?
Hi Currently, EZCA only supports CRL. OCSP support is coming by end of Q3 2023
We are happy to announce that now you can setup your EZCA ca with OCSP docs.keytos.io/azure-pki/creating-your-first-ca/first_subordinate_ca/#ocsp-online-certificate-status-protocol-settings