Jump to content

Recommended Posts

Posted

Hi

 

I have just setup an RDS 2012r2 Farm consisting of 1 session broker/Gateway and 2 session hosts, and i have certificate mismatch error when a remoteapp is run externally.

 

I have a wildcard cert assigned to the session broker and gateway server and its only when the remoteapp is run externally using rdweb and using non domain joined computers.

 

The user logs in to the portal, clicks on the remoteapp, authenticates again (using domain\username) and then the error attached comes up.

 

Does anyone know why this is happening? and how i can prevent the mismatch error? As you can see in the attached, the remote session host computer is displaying the .local address.

 

Many Thanks

 

Capture.JPG

Posted
RD Session Host Config > Double click on the connection > Click Select under certificates at the bottom. You will have needed to imported this certificate on the RD session host. Works for me although throws a revocation check error but I think that is because I'm using the wrong type of certificate!
Posted
RD Session Host Config > Double click on the connection > Click Select under certificates at the bottom. You will have needed to imported this certificate on the RD session host. Works for me although throws a revocation check error but I think that is because I'm using the wrong type of certificate!

 

Is this for 2012 R2?

Posted
That is for Server 2008 R2, as my staff do not like the Windows 8 esque display for RD sessions, however the steps are pretty much the same between the two.
Posted
Do i need one cert for the RDWEB/Geteway (currently my wildcard cert *remote.domain.lea.sch.uk) and another one for the .local when it tries to connect to either of the session hosts?
Posted
I'm not sure as I dont run two session hosts, although I have an internal DNS pointer for my external pointer rdsfarm.schoolname.co.uk pointing to the internal IP address of the session host server, so that works.
Posted (edited)
Internally you should be able use a self cert as it's from Gateway->Session

 

Steve

 

Internally i get no cert error, however when accessing externally, i get the cert error. The hostname on the error is one of the session hosts. Would the session hosts have to have the FQDN of sh.domain.lea.sch.uk instead of the .local?

 

Ive also noticed that the cert (which looks like its the default for the session host is only valid for 6 months!

Edited by techie08
Posted
Internally i get no cert error, however when accessing externally, i get the cert error. The hostname on the error is one of the session hosts. Would the session hosts have to have the FQDN of sh.domain.lea.sch.uk instead of the .local?

 

I meant that as in the cert from gateway to server only needs to be internally valid as it's all within the domain. So doesn't need a CA approved one. Thus you can create a self certified one using the .local :)

 

Steve

Posted
I meant that as in the cert from gateway to server only needs to be internally valid as it's all within the domain. So doesn't need a CA approved one. Thus you can create a self certified one using the .local :)

 

Steve

 

So does that mean the cert error shouldn't display even when users are accessing externally?

Posted
So does that mean the cert error shouldn't display even when users are accessing externally?

 

Which one? :p

 

There will be two errors by default, the one when you connect to the gateway saying "amg fake gimme CA approved cert" and then the one when you connect from the gateway to a session saying "amg fake host"

 

The external gateway one needs to be CA approved for no errors, the session one can be self cert and then as you're already logged in to domain it'll not show a warning :)

 

If you're accessing the server internally (through gateway) you'll need to be using the full external URL else it'll show internally as it's the wrong url blah rather than MyServer etc

 

Steve

Posted

I have this working correctly in my environment, if you want we can set up a remote session and I can show you how I have done it (pm me if interested)

Mike

Posted

Hi guys

 

I found what the problem was. The RDP client was at verson 7 and for the cert errors to go away, it needs to be at verson 8.1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...