Solved

Remote Desktop Services Certificate Mismatch

Posted on 2015-01-05
9
370 Views
Last Modified: 2015-01-11
I am setting up a remote desktop services farm, and I'm getting a certificate mismatch when connecting to the session host. The notification says that the requested computer has a local domain, but the certificate on the remote computer is a .com domain. Does anyone know what I'm missing to make this work? It would seem that I have to change the FQDN of each TS to remote.company.com, but I don't know how to do that. Any help is greatly appreciated.
0
Comment
Question by:Brad212
  • 6
  • 3
9 Comments
 

Author Comment

by:Brad212
ID: 40531888
Screenshot of the certificate mismatch notification
0
 

Author Comment

by:Brad212
ID: 40531890
These are the details of my deployment: My farm has 4 servers all running Windows Server 2012 R2. One server, let's call it TS-Services, holds 3 roles - RD Web Access, RD Gateway, and RD Connection Broker. The other 3 servers are session hosts. Let's call them TS1, TS2, and TS3. All 4 servers use the same wildcard certificate - *.company.com, and my RD Gateway external FQDN is set to remote.company.com. I believe I had to change the published RDS name of the Connection Broker (TS-Services) from the local FQDN to remote.company.com. However, I can't seem do that on the TSs because they are not connection brokers. My clients are connecting from Windows 7 PCs.
0
 

Author Comment

by:Brad212
ID: 40531931
This is the notification that appears when trying to connect externally over the internet.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 12

Assisted Solution

by:David Paris Vicente
David Paris Vicente earned 100 total points
ID: 40531941
Hi,

You can find here in EE an answer to a similar problem.

If you continue to struggle with the problem let us know.


Hope it helps.

D.
0
 

Author Comment

by:Brad212
ID: 40532399
Update: My second screenshot is unrelated. I had neglected to setup a computer group in Remote Desktop Gateway Manager. Once that was I done, I was able to connect to the session hosts.
0
 
LVL 12

Expert Comment

by:David Paris Vicente
ID: 40533034
Ok.

But the certification problem persists?
Did you check the EE link?
0
 

Accepted Solution

by:
Brad212 earned 0 total points
ID: 40533817
Thanks for you comment. While the post you referenced is similar, I found a different solution. The other post recommends a SAN certificate, but because I had already purchased a wildcard cert - as most of the documentation I found online suggested, I was reluctant to change the cert. After some digging I found that RDP 8.0 (included with Windows 8) somehow works around the problem and doesn't present the certificate mismatch notification. My solution will be to update my Windows 7 clients to RDP 8.1 which is the latest version. Hopefully this will help someone else save some time and effort.
0
 
LVL 12

Expert Comment

by:David Paris Vicente
ID: 40533900
Great, keep the good work.

Regards
0
 

Author Closing Comment

by:Brad212
ID: 40542922
I believe that using RDP 8.0 in conjunction with a Windows Server 2012 R2 RDS farm configured with 3rd party and self-signed certificates is the more modern approach than using SAN certificates. Some SSL cert providers have discontinued SAN certs.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

At the beginning of the year, the IT world was taken hostage by the shareholders of LogMeIn. Their free product, which had been free for ten years, all of the sudden became a "pay" product. Now, I am the first person who will say that software maker…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question