edutech4schools Posted February 7, 2013 Posted February 7, 2013 This is my first RDS set up and have got the basics installed and tested - thanks to these forums. My setup = 2008r2 server running remote desktop services role with Gateway and session host set up to allow users to connect to the local server. (not full VDI) I have TS CAP set up so that a user needs to a member of a security group and the client machine also needs to be a member of a security group. I also have the certificates installed on the client computer. I was wondering if it is possible to also make sure any computers are domain computers. I have Googled but not found anything. Any advice about security and how to further lock things down would be handy. Should I be looking at Network Policy and access services to further lock things down? Should I be looking at session host / properties / security layer which has 3 settings, RDP security Layer / Negotiate / SSL(TSL1). Currently set to Negotiate Should I be looking at session host / properties / encryption layer which has Low / Client compatible / High / FIPS compatible. Currently set at Client compatible. Sorry for all the questions but even if you can help me with a few settings I would be very grateful.
TheScarfedOne Posted February 8, 2013 Posted February 8, 2013 Here is a great resource on getting a Remote Desktop system up and running... Configuring Windows 2008 R2 Remote Desktop Farm with Connection Broker « Aaron Walrath – Another IT Guy's Meanderings Ive also blogged about this a bit myself, EduGeek.net - TheScarfedOne - Blogs
edutech4schools Posted February 23, 2013 Author Posted February 23, 2013 Is it possible to require a user has something else locally on the machine like a certificate. When setting RDS / gateway up I thought the user would have to have a certificate installed by a network admin on to the local computer but having played around it seems anyone can simply click install certificate at the certificate warning screen. Or have I not set thing up correctly?
edutech4schools Posted February 23, 2013 Author Posted February 23, 2013 Think I have just worked out a way of doing what I asked in my post above. If I create a self signed cert and apply this to the default website in IIS, when connecting to the rds gateway using remote desktop connection I get an error that the gateway cert cannot be verified and I have no way to continue as I have no option to install the cert. The only way is to copy the proper gateway cert which is not self signed but a purchased cert and install it manually on the client. Does this sound ok or have I opened up some other back door in to the system?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now