SERVER-INITIATED SECURE SESSIONS
Methods, systems, and devices for server-initiated secure sessions are described. A browser application may connect to a portal, where the portal may transmit a command to a server agent to initiate a secure session with an endpoint device. The server agent may be housed in a destination server, and may establish a secure connection with an intermediary server using a secure communication protocol. The secure connection may be made by directing the destination server to open an out-bound connection through a firewall of the destination server. A browser session may be redirected to the intermediary server from the browser application, and the intermediary server may route the browser session traffic to the secure connection.
1 . (canceled)
2 . A method for secure network communications, comprising:
receiving a first indication that a device has selected a destination device for a secure session between the device and the destination device, the destination device associated with a first communication protocol;
transmitting, to the destination device, a command to initiate the secure session via an intermediary device and using a second communication protocol, wherein the intermediary device is external to a firewall of the destination device and wherein the intermediary device is connected to an outbound port of the firewall of the destination device; and
transmitting a second indication to route communications between the device and the destination device through the intermediary device in accordance with the secure session, wherein an inbound port of the firewall of the destination device associated with the first communication protocol remains closed during the communications between the device and the destination device.
3 . The method of claim 2 , further comprising:
transmitting a list of candidate destination devices, wherein the list of candidate destination devices includes the destination device and wherein the first indication is received based at least in part on the list of candidate destination devices.
4 . The method of claim 3 , wherein the list of candidate destination devices is based at least in part on an identity of the device, a user of the device, or any combination thereof.
5 . The method of claim 2 , further comprising:
receiving a message comprising credentials for a user of the device or the device; and
authenticating the user of the device or the device based at least in part on a comparison of the credentials to stored credentials.
6 . The method of claim 2 , further comprising:
receiving, from an agent installed on the destination device, credentials of the agent; and
authenticating the agent based at least in part on the credentials, wherein the command is transmitted based at least in part on the authentication.
7 . The method of claim 6 , further comprising:
verifying an identity of the agent based at least in part on the credentials; and
verifying an identity of the destination device based at least in part on the identity of the agent.
8 . The method of claim 2 , wherein the command indicates to initiate the secure session via a long-poll mechanism while an inbound port of the firewall of the destination device associated with the first communication protocol remains closed.
9 . The method of claim 2 , wherein the first communication protocol is a Secure Socket Shell protocol and the second communication protocol is a Hypertext Transfer Protocol Secure protocol.
10 . The method of claim 2 , wherein a communication path between the device and the destination device through the intermediary device comprises:
a first portion between an agent installed at the destination device and the intermediary device that uses the second communication protocol, and
a second portion between the intermediary device and the device that uses the first communication protocol or a third communication protocol, wherein communications over the communication path are converted between the second communication protocol and the first communication protocol or the third communication protocol.
11 . The method of claim 10 , wherein the first communication protocol is a Secure Socket Shell protocol, the second communication protocol is a Hypertext Transfer Protocol Secure protocol, and the third communication protocol is the Hypertext Transfer Protocol Secure protocol.
12 . An apparatus, comprising:
one or more processors; and
one or more memories storing instructions executable by the one or more processors to cause the apparatus to:
receive a first indication that a device has selected a destination device for a secure session between the device and the destination device, the destination device associated with a first communication protocol;
transmit, to the destination device, a command to initiate the secure session via an intermediary device and using a second communication protocol, wherein the intermediary device is external to a firewall of the destination device and wherein the intermediary device is connected to an outbound port of the firewall of the destination device; and
transmit a second indication to route communications between the device and the destination device through the intermediary device in accordance with the secure session, wherein an inbound port of the firewall of the destination device associated with the first communication protocol remains closed during the communications between the device and the destination device.
13 . The apparatus of claim 12 , wherein the instructions are further executable by the one or more processors, individually or collectively, to cause the apparatus to:
transmit a list of candidate destination devices, wherein the list of candidate destination devices includes the destination device and wherein the first indication is received based at least in part on the list of candidate destination devices.
14 . The apparatus of claim 13 , wherein the list of candidate destination devices is based at least in part on an identity of the device, a user of the device, or any combination thereof.
15 . The apparatus of claim 12 , wherein the instructions are further executable by the one or more processors, individually or collectively, to cause the apparatus to:
receive a message comprising credentials for a user of the device or the device; and
authenticate the user of the device or the device based at least in part on a comparison of the credentials to stored credentials.
16 . The apparatus of claim 12 , wherein the instructions are further executable by the one or more processors, individually or collectively, to cause the apparatus to:
receive, from an agent installed on the destination device, credentials of the agent; and
authenticate the agent based at least in part on the credentials, wherein the command is transmitted based at least in part on the authentication.
17 . The apparatus of claim 12 , wherein the command indicates to initiate the secure session via a long-poll mechanism while an inbound port of the firewall of the destination device associated with the first communication protocol remains closed.
18 . The apparatus of claim 12 , wherein the first communication protocol is a Secure Socket Shell protocol and the second communication protocol is a Hypertext Transfer Protocol Secure protocol.
19 . A non-transitory computer-readable medium storing code, the code comprising instructions executable by one or more processors to:
receive a first indication that a device has selected a destination device for a secure session between the device and the destination device, the destination device associated with a first communication protocol;
transmit, to the destination device, a command to initiate the secure session via an intermediary device and using a second communication protocol, wherein the intermediary device is external to a firewall of the destination device and wherein the intermediary device is connected to an outbound port of the firewall of the destination device; and
transmit a second indication to route communications between the device and the destination device through the intermediary device in accordance with the secure session, wherein an inbound port of the firewall of the destination device associated with the first communication protocol remains closed during the communications between the device and the destination device.
20 . The non-transitory computer-readable medium of claim 19 , wherein the instructions are further executable by the one or more processors to:
transmit a list of candidate destination devices, wherein the list of candidate destination devices includes the destination device and wherein receiving the first indication is based at least in part on transmitting the list of candidate destination devices.
21 . The non-transitory computer-readable medium of claim 19 , wherein the instructions are further executable by the one or more processors to:
receive a message comprising credentials for a user of the device or the device; and
authenticate the user of the device or the device based at least in part on a comparison of the credentials to stored credentials.