Solved

The publisher of this remote connection cannot be verified. Type RemoteApp program.

Posted on 2011-09-08
5
1,517 Views
Last Modified: 2012-08-13
When user try to open a RDP file to lunch program on the one of the Terminal Servers, warning message pop up:
The publisher of this remote connection cannot be verified. Do you wwant to connect?
Publisher: Unklnown publisher
Type: RemoteApp program.

It work if click Connect button. How to get rid of this message?
RDP file is aleredy signed with self signed certificate from that server.
   
9-8-2011-4-59-08-PM.jpg
0
Comment
Question by:CompGenHosp
  • 3
  • 2
5 Comments
 
LVL 8

Expert Comment

by:Shmoid
ID: 36506570
The easy way is to check the box on the popup that says "Don't aks me again..." and then click connect.

The better way is to install the certificate used to sign into the trusted root store on the client computer.
0
 

Author Comment

by:CompGenHosp
ID: 36509714
We have multiple Terminal server users, so we look for centralized solution. That will apply to all users.
How to install certificate into the trusted root store? What kind of certificate? How to create one?
We have 8 Terminal Servers. Do I need to get a 8 certificated (one per server)?
I really need answer on these questions in details. Thank you.
0
 
LVL 8

Expert Comment

by:Shmoid
ID: 36513022
I'll try to answer all your questions but first can you give me some additional information about your environment?

You mention in your original post that the RDP file is signed with a self signed certificate.

Does each terminal server have a unique self signed cert?

Are you willing to change that?

Do you have have an internal PKI?

Do any of your users access the RemoteApp from external (public) computers?

If so, have you considered a 3rd party cert from a CA such as VeriSign?

Are all users/computer domain members?
0
 

Author Comment

by:CompGenHosp
ID: 36513215
You mention in your original post that the RDP file is signed with a self signed certificate.

Does each terminal server have a unique self signed cert?
         Yes
Are you willing to change that?

Do you have have an internal PKI?
No

Do any of your users access the RemoteApp from external (public) computers?
No,

If so, have you considered a 3rd party cert from a CA such as VeriSign?
Yes, but like to review a option on having own CA
Are all users/computer domain members?
Yes
 
0
 
LVL 8

Accepted Solution

by:
Shmoid earned 500 total points
ID: 36513941
If you want to have your own CA that would work very well for your scenario. You already have an environment that is well suited. By that I mean that all your users are domain joined so you can use group policy to push certs. You don’t have external users or public computers accessing the terminal servers.

Before turning up a PKI you first need to make a few decisions. For example, how large is your environment? Do you plan to buy dedicated servers or install CA’s on existing servers? Would a single stand-alone server be sufficient or would a two tier setup with an offline root CA and an online issuing CA be more reasonable, especially from a security stand point. If two tier or dedicating a box just for certificate services is not practical or cost effective then you can install a CA on any server but a hardware security module (HSM) to protect the CA’s private key might be a good investment. Your root CA’s private key is the heart of your PKI security. If compromised all certificates should be considered worthless so protect that private key at all costs.

Once you make those decisions and get a CA or CA hierarchy in place you can do the following.

Manually create a certificate for signing the RDP files. Install that one certificate on all terminal servers. Some would use unique certificates on each server but it isn’t necessary. Although you could do that as well. Once installed create new RDP files using the new certificates to sign them. Finally, modify your domain group policy to push the CA’s public key to all clients trusted root store.

I’m sure you’ll need more info than the above but this will give you a starting point.
0

Featured Post

[Webinar] Disaster Recovery and Cloud Management

Learn from Unigma and CloudBerry industry veterans which providers are best for certain use cases and how to lower cloud costs, how to grow your Managed Services practice in IaaS clouds, and how to utilize public cloud for Disaster Recovery

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now