Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Terminal Server 2008 WildCard Certificate Error

Posted on 2013-02-01
5
Medium Priority
?
933 Views
Last Modified: 2013-02-06
I have a basic Windows 2008 terminal server that I have installed my wildcard Comodo certificate on to try to rid my users of the annoying certificate error when they connect via the RDP client.  Unfortunately, it is not working.  The certificate in the error message has definitely changed from the self-generated one to the *.domain.com cert that I installed, but Windows is still throwing a fit because it does not match the hostname that the users must enter to access the host.  Do wildcards work in TS 2008?  I don't have TS Gateway or Web App set up, just a plain jane 2008 Terminal Server.
0
Comment
Question by:marrj
  • 2
  • 2
5 Comments
 
LVL 25

Accepted Solution

by:
Coralon earned 2000 total points
ID: 38845991
Are they entering the full name as they go to access it?  Even if you have a wildcard cert, if you don't use a truly matching name, it will throw an error.

i.e. - if use the shortname of server1 to RDP in, it will throw an error.  But, with the wildcard cert, I should be able to server1.domain.com and it should not throw the error.

Coralon
0
 
LVL 65

Expert Comment

by:btan
ID: 38846181
Understand that Windows Server 2003 Terminal Services implementations don't support wildcard certificates in any of its features. You have to buy named SSL certificates. Server 2008 supports wildcard certificates for all features, such as TS Gateway and TS Web Access

Needed also RDC 6.1 and above on the client.
And For a certificate to be used for RDP it must have Server Authentication ( 1.3.6.1.5.5.7.3.1 )

http://serverfault.com/questions/201451/install-certificate-in-rdp-tcp-properties

Event ID 1054 — Terminal Services Authentication and Encryption
http://technet.microsoft.com/en-us/library/cc775272%28WS.10%29.aspx
0
 
LVL 1

Author Comment

by:marrj
ID: 38852536
The users are entering an alias of the server name created by an alias in DNS so that they don't have to remember the hostname.
0
 
LVL 25

Expert Comment

by:Coralon
ID: 38853525
That won't work.. If you don't want to throw any kind of SSL error, they have to use the full URL.  

Coralon
0
 
LVL 65

Expert Comment

by:btan
ID: 38853685
I am thinking of two possibilities:

a) think it may be more of a need for Subject Alternative Name (SAN) in the certificate.

E.g. SAN attributes take the following form: san:dns=dns.name[&dns=dns.name]

Multiple DNS names are separated by an ampersand (&). For example, if the name of the domain controller is corpdc1.fabrikam.com and the alias is ldap.fabrikam.com, both of these names must be included in the SAN attributes. The resulting attribute string appears as follows: san:dns=corpdc1.fabrikam.com&dns=ldap.fabrikam.com

@ http://support.microsoft.com/kb/931351
@ http://www.bunkerhollow.com/blogs/matt/archive/2009/01/28/install-amp-configure-ts-web-access-for-external-use.aspx


b) I also saw another forum that may have related issue DNS alias issue
http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/001981f5-62a5-4234-9a09-2b442e7bbccf
0

Featured Post

Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is a fairly complicated script that will install the required prerequisites to install SCCM 2012 R2 on a server.  It was designed under the functional model in order to compartmentalize each step required, reducing the overall complexity.  The …
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question