Jump to content

Recommended Posts

Posted

This is my first RDS set up and have got the basics installed and tested - thanks to these forums.

 

My setup = 2008r2 server running remote desktop services role with Gateway and session host set up to allow users to connect to the local server. (not full VDI)

 

I have TS CAP set up so that a user needs to a member of a security group and the client machine also needs to be a member of a security group.

 

I also have the certificates installed on the client computer.

 

I was wondering if it is possible to also make sure any computers are domain computers. I have Googled but not found anything.

 

Any advice about security and how to further lock things down would be handy.

 

Should I be looking at Network Policy and access services to further lock things down?

 

Should I be looking at session host / properties / security layer which has 3 settings, RDP security Layer / Negotiate / SSL(TSL1). Currently set to Negotiate

 

Should I be looking at session host / properties / encryption layer which has Low / Client compatible / High / FIPS compatible. Currently set at Client compatible.

 

Sorry for all the questions but even if you can help me with a few settings I would be very grateful.

  • 3 weeks later...
Posted
Is it possible to require a user has something else locally on the machine like a certificate. When setting RDS / gateway up I thought the user would have to have a certificate installed by a network admin on to the local computer but having played around it seems anyone can simply click install certificate at the certificate warning screen. Or have I not set thing up correctly?
Posted

Think I have just worked out a way of doing what I asked in my post above. If I create a self signed cert and apply this to the default website in IIS, when connecting to the rds gateway using remote desktop connection I get an error that the gateway cert cannot be verified and I have no way to continue as I have no option to install the cert. The only way is to copy the proper gateway cert which is not self signed but a purchased cert and install it manually on the client.

 

Does this sound ok or have I opened up some other back door in to the system?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...