x404.co.uk
http://x404.co.uk/forum/

Licensing for Test Lab
http://x404.co.uk/forum/viewtopic.php?f=4&t=26444
Page 1 of 1

Author:  big_D [ Wed Feb 28, 2018 12:46 pm ]
Post subject:  Licensing for Test Lab

Is there any way to get a permanent test licensing for Windows products?

We build security scanning equipment and need a decent sized scanning pool. This means a bunch of VMs that are booted up, never get updated, never get logged onto and are just scanned for vulnerabilities on a regular basis.

Putting a couple of dozen Windows clients and servers together to just be scanned and never "used", it seems very expensive and "wasteful" to have to have fully licensed Windows 10 Pro (around 200€ per VM). The server side could be done with a Data Center license, but that is around 3.500€, which is again a "waste of money" for something that is just going to be scanned every couple of hours for known vulnerabilities.

Spinning up a couple of dozen Debian, CentOS and Metasploitable clients isn't a big problem, but getting the Windows side of the test pool up and running is going to need some serious wedge at the moment..

We do have an Action Pack, which will give us about 10 licenses for Windows 10, but having a decent sized VM scan farm is still going to be expensive.

Author:  saspro [ Thu Mar 01, 2018 8:43 am ]
Post subject:  Re: Licensing for Test Lab

Grab a load of trials & spin them up for the lab?

or MSDN/Visual Studio (whatever they call it now)

Author:  big_D [ Thu Mar 01, 2018 3:46 pm ]
Post subject:  Re: Licensing for Test Lab

It is looking like it might have to be MSDN, although that is still damned expensive, or see if we can get some let-over volume licenses on the cheap.

Trials might work, but what we really need is a baseline installation, which will be tested against when new updates to the remote scanner are made. That would mean having to spin up new VMs every 3 months or so, configure them, disable updates and leave them alone for 3 months, then go through the whole rigmarole again in another 3 months... It just feels like a waste of money having to set up a couple of dozen Windows VMs, which nobody will ever use, and having to still have to pay for full licenses.

Even with our Action Pack licenses, it still feels like I am "wasting" a license when setting up such a VM.

Author:  ShockWaffle [ Sat Mar 10, 2018 3:54 pm ]
Post subject:  Re: Licensing for Test Lab

How much configuring do they need? It doesn't sound like you are setting up an awful lot on them.

You could for instance use Fog tp push a sysprepped demo image and post deplyment it can invoke a powershell script to do simple configuration. Reinstallation is then just a case of pixie booting the vm every couple of months. That might be enough to get you up and running without the complexity of Docker/Vagrant, DSC or Ansible.

But you can equally just buy a handful of one time Windows keys off Amazon for £20 each, and those are fine. That's probably what I would do.

Page 1 of 1 All times are UTC
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/