nathan Posted February 7, 2014 Posted February 7, 2014 Thought i'd create a new thread on this as i'm now using Server 2012 R2 for remote app. Just wondering as in order for me to get this working correctly i'll need a simple third party ssl cert. All users will be accessing the remote apps via remote.domain.com so i guess i would just need an SSL to cover this. Would the following be acceptable? Buy RapidSSL® - Cheap - From Only £13.49 - Issued Instantly
fiza Posted February 7, 2014 Posted February 7, 2014 sorry @nathan cant help with your query other than to say make sure the certificate is recognised by the major browsers. I am also experimenting with Remoteapp, mainly for SIMS access for staff. Were you able to test remoteapp access over the internet without an SSL certificate or do you have to have one in place before configuring RD Gateway?
fiza Posted February 7, 2014 Posted February 7, 2014 I have got it working over a VPN and tested accessing SIMS on an IPAD and a Samsung Galaxy S3 and it all works!! I now want to try without the VPN.
nathan Posted February 7, 2014 Author Posted February 7, 2014 I'm testing using the external name and its working but i'm on the inside of our network, if i PM you the details would you be able to test?
fiza Posted February 7, 2014 Posted February 7, 2014 I'm testing using the external name and its working but i'm on the inside of our network, if i PM you the details would you be able to test? Sure no problem pm me and I will test it straight away.
fiza Posted February 7, 2014 Posted February 7, 2014 Nathan - Have you tried using a self-signed certificate - just for testing purposes before you buy a certificate? Configure a Certificate for the Remote Desktop Gateway Server
nathan Posted February 7, 2014 Author Posted February 7, 2014 Nathan - Have you tried using a self-signed certificate - just for testing purposes before you buy a certificate? Configure a Certificate for the Remote Desktop Gateway Server thats what i'm using now. I've had the ok to buy a 3rd party one, it's only £15 a year. I'll let you know how it goes.
fiza Posted February 7, 2014 Posted February 7, 2014 thats what i'm using now. I've had the ok to buy a 3rd party one, it's only £15 a year. I'll let you know how it goes. Ah I see - and is that the one that is preventing access from external users?
nathan Posted February 7, 2014 Author Posted February 7, 2014 yeah, i haven't tried installing the certificate on the client pc's mind you, i imagine that would work.
fiza Posted February 11, 2014 Posted February 11, 2014 @nathan You might find these articles interesting if you want to brand & customise the RDWeb experience. Step by Step Customizing RD Web Access 2012 R2 – Part 1 | msfreaks Fix my IT system: Customise RDS Web access login pages
nathan Posted February 11, 2014 Author Posted February 11, 2014 thanks for those, there certainly interesting and something i'll do once i can get the thing working. I've installed the certificate and now all the warnings have gone. But i still can't get it working. the following error i get when trying to open a remoteapp.
harriuk Posted February 11, 2014 Posted February 11, 2014 Hi. Not sure this is what you were after but you msy find it useful. We have been using RDS gateway with remoteapps for a while and use a third party certificate on our gateway. This works for external clients without any issues. We also had to figure out how to make it work internally too using remote.domain.com. I came across a solution whilst reading about split dns for another issue. What we did was create a dns zone of domain.com (this is not authorative of course) on our internal dns server. Then added an entry called remote and assigned it the address of the gateway's internal ip address for example 192.168.90.4. So now whenever we type in remote.domain.com internally our clients go to the servers internal address but the url matches the certificate. And externally clients using remote.domain.com would connect to the server's published external ip address, again the url matched the certificate. If this is something you cannot do on your network then maybe you could look into into SANs for the certificate gor both internal and extetnal url. Harriuk
nathan Posted February 11, 2014 Author Posted February 11, 2014 that also sounds useful so thank you for that. i found the problem. I had to add the netbios and ip to the resource authorisation policy, i also disable both and created my own.
harriuk Posted February 11, 2014 Posted February 11, 2014 Yes as I finished typing my essay I saw your last post and was going to suggest that! Glad you got it all working.
nathan Posted February 12, 2014 Author Posted February 12, 2014 Well, i told a lie. It isn't working, now i've added those the certificate is complaining again. Sorry about this but AAHHHHHHHHH
fiza Posted February 12, 2014 Posted February 12, 2014 You may already have checked this but : In you RD Gateway Manager look at the properties of the server and check SSL Certificate. Make sure the "Issued to:" option is correct. It should be the public name of your server.
harriuk Posted February 12, 2014 Posted February 12, 2014 Hi Nathan, when you say it isn't working, what isn't working? Do you have any error messages you can share? OR is it exactly the same as the issue you were experiencing earlier in the thread?
nathan Posted February 12, 2014 Author Posted February 12, 2014 (edited) You may already have checked this but : In you RD Gateway Manager look at the properties of the server and check SSL Certificate. Make sure the "Issued to:" option is correct. It should be the public name of your server. Just checked and thats what i have, it could be that ive bought the incorrect certificate. I have a certificate with only our remote.domain.com external name, should it also have the internal fully qualified server name? EDIT: after more reading i dont think the above is correct. Edited February 12, 2014 by nathan
harriuk Posted February 12, 2014 Posted February 12, 2014 Hi Nathan, I need more info for example there are a few answers to your issue. You could set up the split DNS as I suggested before so that the gateway always receives a request for remote.domain.com or you could also set your clients up to bypass the gateway altogether if they are internal. if you PM me with how you have it set up I can help you better! Thanks Harriuk
nathan Posted February 12, 2014 Author Posted February 12, 2014 It's strange as im getting a certificate mismatch. Requested remote computer: Internal FQDN Name on the cert from the remote computer; remote.domain.com i thought the only thing showing to the outside world would be the remote.domain.com one and that it wouldnt know anything about the internal one.
nathan Posted February 12, 2014 Author Posted February 12, 2014 (edited) I've found this and wondering if it could be whats happening. TechNet Change published FQDN for Server 2012 or 2012 R2 RDS Deployment Internally we're working fine, no errors at all. I've created an A record for remote.domain.com to point to our internal server. Edited February 12, 2014 by nathan
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now