Solved

SBS 2011 - TS Gateway / Remote Desktop Certificate Mismatch Failure

Posted on 2012-04-04
2
2,534 Views
Last Modified: 2012-04-05
Please bear with me as I was recently supporting a SBS server already setup. What I do know is that company is using mail.contoso.com certificate from GoDaddy that is used for seemingly all of there certificates against the server. Remote.contoso.com was issued by server-CA for the Terminal Gateway. Everything works fine and resolves to proper mail or remote.contoso address. Problem is when I enter the RWA portal, of which I can do no problem with certificate mismatch which is pulling the mail.contoso.com certificate. When I try to launch remote connection to PC its giving me "Your computer can't connect to the remote computer because the Remote Desktop Gateway server address requested and the certificate subject name do not match. Contact system admin." If I go and change the certificate on the RD Gateway Manager to remote.contoso.com obviously this works fine. No mismatches and I can continue to go to Public/Downloads/Install Cert. Download and install on client and RDP works fine. Only problem is that the Exchange hosted on the same server with the mail.contoso.com will then give all the client Outlook users certificate errors as its pulling remote.contoso.com now instead of mail.contoso.com. SO..how can I get the TS Gateway to just use remote and the mail to use mail? Is there anything I could do with DNS but Im thinking it will still have a cert mismatch. This has been very frustrating to say the least and TIA for any assistance!
0
Comment
Question by:iacovetti72
2 Comments
 
LVL 35

Accepted Solution

by:
Cris Hanna earned 500 total points
Comment Utility
SBS wizards are not designed to support multiple host names for SSL certs
OWA/Outlook Anywhere and RWA are in the same IIS site

The simple solution here is configure outlook anywhere to use remote.contoso.com

The other option is to re-run the Setup My Internet Address Wizard, select I have a domain name, select I want to manage it myself
When you get to the portion that says, enter Domain Name, click on the work "Advanced" under the text box
change Remote to mail, click ok, enter domain name and finish the wizard

Can you now connect to RWA and to the desktops with the https://mail.contoso.com/remote ?
0
 

Author Closing Comment

by:iacovetti72
Comment Utility
Since SBS 2011 has the limitation I went ahead and just used remote. and is working as normal. Thanks for your insight, as thats exactly what I was going to do but wanted to see if I could do something else.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

This is a little timesaver I have been using for setting up Microsoft Small Business Server (SBS) in the simplest possible way. It may not be appropriate for every customer. However, when you get a situation where the person who owns the server is i…
The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now