Link to home
Start Free TrialLog in
Avatar of Netsol-NOS
Netsol-NOS

asked on

RDP Lost after Disable TLS 1.0 on Windows 2012 R2

Dear EE,

Remote Desktop has been disabled after i perform following settings on Microsoft Windows 2012 R2.

DISABLED TLS 1.0
ENABLED TLS 1.1
ENABLED TLS 1.2

User generated image
Please see attached error

Thanks
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

This is a known issue

https://support.microsoft.com/en-us/help/4036954/disabling-tls1-0-can-cause-rds-connection-broker-or-rdms-to-fail

TL;DR

Set up RDS without Connection Broker for a single server installation.
Do not disable TLS 1.0 on a single Connection Broker deployment.
Configure a high availability Connection Broker deployment that uses dedicated SQL Server.
Note Microsoft has released an update to enable SQL Server communication to use TLS 1.2.
How did you disable TLS 1.0?

This should be the good point to do it.
https://gallery.technet.microsoft.com/office/Enable-TLS11-and-TLS12-in-f41c9ab0

Please be specific on what you did.
What about unchecking the NLA option in the target server RDP setting ?
Avatar of Netsol-NOS
Netsol-NOS

ASKER

You mean this option.

User generated image
Dear Jose Gabriel Ortega Castro,

I have disabled the SSL 2.0 SSL 3.0 and TLS 1.0 by this.

User generated imageSAME FOR SSL 3.0 and TLS 1.0


And Enabled TLS 1.1 and TLS 1.2 by this,

User generated imageSAME FOR TLS 1.2
Dear David Johnson, CD, MVP,

Please see that i have to disabled TLS 1.0 its MANDATORY for vulnerability.

Thanks
Dear David Johnson, CD, MVP,

Your link said ONE OF THE FOLLOWING METHODS so its mean any one i can choose.

Can you please tell how can i do these steps.

Set up RDS without Connection Broker for a single server installation.

Thanks
remove connection broker from remote desktop services.User generated image
Dear David,

I have following settings and Connection Broker is already not selected please see below screenshot.

User generated image
I had a similar bug on my script but it was solved  On this question:
https://www.experts-exchange.com/questions/29055597/Remote-Desktop-TLS-1-0.html

So it's safe to use this script, it has all the documentation in it.
https://gallery.technet.microsoft.com/scriptcenter/Solve-SWEET32-Birthday-d2df9cf1
Dear Zaheer Iqbal,

We have resolved the problem on windows 2008 r2. This is not an issue.

PROBLEM is with Windows 2012 R2.

Thanks
Dear Jose Gabriel Ortega Castro,

Can you please confirm how to revert the SCRIPT if any thing bad happens on PRODUCTION SERVER. ??
Dear Jose Gabriel Ortega Castro

I run the script but still error is same.
But after the script TLS 1.1 has also disabled.  Now only TLS 1.2 is enabled in whole server . TLS 1.0 and TLS 1.1 is disabled.
User generated image
ASKER CERTIFIED SOLUTION
Avatar of imtiaza
imtiaza
Flag of Pakistan image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Its Works.
After install below updates on  Windows 7  my workstation starts connecting Windows 2012 R2 through RDP.
1)  Windows6.1-KB2574819-v2-x64
2)  Windows6.1-KB2592687-x64

Note that on Windows 2012 R2 TLS 1.0 is disabled and TLS 1.1 and TLS 1.2 is enabled.