Jump to content

Recommended Posts

Posted

Hi all

 

I'm setting up a new remote access solution and using the standard remote desktop session roles in Server 2016. I have 3 servers with various roles:

 

1. RD Connection Broker and RD Licensing

2. RD Gateway and RD Web Access

3. RD Session Host

 

So far I've been using self-signed certificates but now I'm ready to buy some trusted certs. There are 4 certs in use across the remote desktop solution - 2 identical for the connection broker (issued for the internal server name) and 2 identical for the gateway/web access (issued for the external subdomain name). I know I need a cert for the external address but can I get away with continuing to use self-signed certs for the internal connection broker?

 

When I tested our solution using the RDP client, specifying both the session host address and the gateway address, I got an error saying that it couldn't verify the identify of our RD Gateway. That makes sense and presumably a trusted cert will fix this but I want to make sure I'm not going to hit another error after that saying it couldn't verify the identify of an internal server. The documentation suggests that all certs have to be trusted but I'm trying to keep costs down where possible.

 

Thanks

Posted
Why have you got three servers could you not get away with one we have a remote desktop with the RD Gateway, Connection broker and the RD Session host only had to buy one trusted certificate that is it then you costs will be kept down the costs. We bought a UCC 5 certificate and installed that on the remote desktop server and other server eg: mail, webserver, etc that will keep the cost down to. hope this helps?
  • Thanks 1
Posted

I'm following Microsoft's guidance on how to distribute the roles (https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/desktop-hosting-logical-architecture). I had them all running on the same server during testing and it was fine but you lose a bit of flexibility, especially if you want to expand it in the future and if you want limit which roles are exposed to the Internet. It's probably a bit excessive for now, but it might prevent some difficulties down the line.

 

Thanks for your reply, I'll have a look in case we have space on an existing UCC cert, otherwise I think I'll just go ahead with a single domain cert.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...