Solved

Certificate error for TS WebApp Server behind TS Gateway

Posted on 2011-02-23
10
1,125 Views
Last Modified: 2012-05-11
Our SBS2008 server is properly configured with a trusted certificate. We have set up a second server 2008 machine running TS WebApps. We have also published a couple RDP links to the RWW web site using the guides created by Microsoft.

When a user logs into the RWW and clicks the link to launch the Remote WebApp it prompts them for their credentials to the terminal server but then throws the error about the certificate to the LOCAL name of the TS Web Apps server and prevents the connection.

How do i set up a certificate for a local machine to allow the rdp connection to pass through? Or is something setup incorrectly?

 error
0
Comment
Question by:Joe Sorensen
  • 4
  • 4
10 Comments
 

Author Comment

by:Joe Sorensen
ID: 34963820
PS when attempting to connect from Windows Vista i don't see the error. It's my users using Windows 7 that can't connect
0
 
LVL 38

Expert Comment

by:Philip Elder
ID: 34963907
By default we do not touch the certificate structure on the TS/RDS box other than to specify the RWW/RWA URL as the TS/RDS Gateway pointer.

Normally there is a check box on that warning that we can check to "Don't Bug Me" again about that.

Have changes been made to the certificate setup on the TS/RDS box?

Philip
0
 

Author Comment

by:Joe Sorensen
ID: 34964053
our TS Gateway/SBS box has the certificate installed for our public dns name and works great for OWA/RWW/TS Gateway, etc.

The rdp files are set to use the TS Gateway to connect through back to the local name of the TS Web App server.

The TS WebApp terminal server itself is NOT exposed directly to the internet. Just our SBS box with the RDP links.
0
Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

 
LVL 38

Accepted Solution

by:
Philip Elder earned 500 total points
ID: 34964169
Yes, that is how we have all of our TS/RDS setups running through SBS 08/11's TS/RDS Gateway.

The certificate warning always comes up on first connection but it allows us to ignore it going forward.

Philip
0
 
LVL 38

Expert Comment

by:Philip Elder
ID: 34964189
The following may help:

Logon using the following structure:

Domain\FirstLast
My crazy l0ng pass phrase!

Users can check the Save Credentials but that will only apply for the Gateway depending on how the GPO security structures are set up.

Philip
0
 

Author Comment

by:Joe Sorensen
ID: 34964292
The authenticate to the Gateway just fine. That certificate works. It prompts them for the certificate for the machine BEHIND the gateway. If I manually change the "authentication:i" property from

authentication:i:2 to authentication:i:1 it will allow me to suppress the warning about the certificate and continue on. I would just rather not see the message at all.

Is there some kind of certificate i need to auth between the sbs08 box and the server 2008 box?
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 37419175
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0
 
LVL 38

Expert Comment

by:Philip Elder
ID: 37393243
To answer your last question, "No".

On first connection by a remotely connecting system there will always be two certificate warnings.

Philip
0
 

Author Comment

by:Joe Sorensen
ID: 37399895
confirmed accept #34964169
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall SHA issue 4 40
Is there any way to limit concurrent connection in IIS7? 6 39
aes256 Ransomware on SBS 2011 13 37
Exchange 2010 and Outlook 2010 2 32
I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question