Solved

Certificate error for TS WebApp Server behind TS Gateway

Posted on 2011-02-23
10
1,121 Views
Last Modified: 2012-05-11
Our SBS2008 server is properly configured with a trusted certificate. We have set up a second server 2008 machine running TS WebApps. We have also published a couple RDP links to the RWW web site using the guides created by Microsoft.

When a user logs into the RWW and clicks the link to launch the Remote WebApp it prompts them for their credentials to the terminal server but then throws the error about the certificate to the LOCAL name of the TS Web Apps server and prevents the connection.

How do i set up a certificate for a local machine to allow the rdp connection to pass through? Or is something setup incorrectly?

 error
0
Comment
Question by:Joe Sorensen
  • 4
  • 4
10 Comments
 

Author Comment

by:Joe Sorensen
ID: 34963820
PS when attempting to connect from Windows Vista i don't see the error. It's my users using Windows 7 that can't connect
0
 
LVL 38

Expert Comment

by:Philip Elder
ID: 34963907
By default we do not touch the certificate structure on the TS/RDS box other than to specify the RWW/RWA URL as the TS/RDS Gateway pointer.

Normally there is a check box on that warning that we can check to "Don't Bug Me" again about that.

Have changes been made to the certificate setup on the TS/RDS box?

Philip
0
 

Author Comment

by:Joe Sorensen
ID: 34964053
our TS Gateway/SBS box has the certificate installed for our public dns name and works great for OWA/RWW/TS Gateway, etc.

The rdp files are set to use the TS Gateway to connect through back to the local name of the TS Web App server.

The TS WebApp terminal server itself is NOT exposed directly to the internet. Just our SBS box with the RDP links.
0
 
LVL 38

Accepted Solution

by:
Philip Elder earned 500 total points
ID: 34964169
Yes, that is how we have all of our TS/RDS setups running through SBS 08/11's TS/RDS Gateway.

The certificate warning always comes up on first connection but it allows us to ignore it going forward.

Philip
0
Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

 
LVL 38

Expert Comment

by:Philip Elder
ID: 34964189
The following may help:

Logon using the following structure:

Domain\FirstLast
My crazy l0ng pass phrase!

Users can check the Save Credentials but that will only apply for the Gateway depending on how the GPO security structures are set up.

Philip
0
 

Author Comment

by:Joe Sorensen
ID: 34964292
The authenticate to the Gateway just fine. That certificate works. It prompts them for the certificate for the machine BEHIND the gateway. If I manually change the "authentication:i" property from

authentication:i:2 to authentication:i:1 it will allow me to suppress the warning about the certificate and continue on. I would just rather not see the message at all.

Is there some kind of certificate i need to auth between the sbs08 box and the server 2008 box?
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 37419175
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0
 
LVL 38

Expert Comment

by:Philip Elder
ID: 37393243
To answer your last question, "No".

On first connection by a remotely connecting system there will always be two certificate warnings.

Philip
0
 

Author Comment

by:Joe Sorensen
ID: 37399895
confirmed accept #34964169
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
530 User cannot login, home directory inaccessible 18 57
web.config redirect issues 5 38
Windows 10 VPN? 6 73
Mac users not seeing updated files on web site 3 12
I work for a company that primarily works with small businesses as their outsourced IT vendor. As such the majority of these customers utilize some version of Small Business Server. Due to the economics of running a small business, many of these cus…
When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now