Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1132
  • Last Modified:

Certificate error for TS WebApp Server behind TS Gateway

Our SBS2008 server is properly configured with a trusted certificate. We have set up a second server 2008 machine running TS WebApps. We have also published a couple RDP links to the RWW web site using the guides created by Microsoft.

When a user logs into the RWW and clicks the link to launch the Remote WebApp it prompts them for their credentials to the terminal server but then throws the error about the certificate to the LOCAL name of the TS Web Apps server and prevents the connection.

How do i set up a certificate for a local machine to allow the rdp connection to pass through? Or is something setup incorrectly?

 error
0
Joe Sorensen
Asked:
Joe Sorensen
  • 4
  • 4
1 Solution
 
Joe SorensenSystems MgrAuthor Commented:
PS when attempting to connect from Windows Vista i don't see the error. It's my users using Windows 7 that can't connect
0
 
Philip ElderTechnical Architect - HA/Compute/StorageCommented:
By default we do not touch the certificate structure on the TS/RDS box other than to specify the RWW/RWA URL as the TS/RDS Gateway pointer.

Normally there is a check box on that warning that we can check to "Don't Bug Me" again about that.

Have changes been made to the certificate setup on the TS/RDS box?

Philip
0
 
Joe SorensenSystems MgrAuthor Commented:
our TS Gateway/SBS box has the certificate installed for our public dns name and works great for OWA/RWW/TS Gateway, etc.

The rdp files are set to use the TS Gateway to connect through back to the local name of the TS Web App server.

The TS WebApp terminal server itself is NOT exposed directly to the internet. Just our SBS box with the RDP links.
0
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

 
Philip ElderTechnical Architect - HA/Compute/StorageCommented:
Yes, that is how we have all of our TS/RDS setups running through SBS 08/11's TS/RDS Gateway.

The certificate warning always comes up on first connection but it allows us to ignore it going forward.

Philip
0
 
Philip ElderTechnical Architect - HA/Compute/StorageCommented:
The following may help:

Logon using the following structure:

Domain\FirstLast
My crazy l0ng pass phrase!

Users can check the Save Credentials but that will only apply for the Gateway depending on how the GPO security structures are set up.

Philip
0
 
Joe SorensenSystems MgrAuthor Commented:
The authenticate to the Gateway just fine. That certificate works. It prompts them for the certificate for the machine BEHIND the gateway. If I manually change the "authentication:i" property from

authentication:i:2 to authentication:i:1 it will allow me to suppress the warning about the certificate and continue on. I would just rather not see the message at all.

Is there some kind of certificate i need to auth between the sbs08 box and the server 2008 box?
0
 
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0
 
Philip ElderTechnical Architect - HA/Compute/StorageCommented:
To answer your last question, "No".

On first connection by a remotely connecting system there will always be two certificate warnings.

Philip
0
 
Joe SorensenSystems MgrAuthor Commented:
confirmed accept #34964169
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

  • 4
  • 4
Tackle projects and never again get stuck behind a technical roadblock.
Join Now