TS Gateway - What Certificate?


we have remoteapps server uses ts gateway. @ moment, using self signed certificate proving pain every client machine requires certificate importing trusted root certificate authorities.

to bypass this, want purchase certificate trust ca clients automatically recognize it.

please point me in right direct?

i thinking secure pro site certificate verisign:

http://www.verisign.co.uk/ssl/buy-ssl-certificates/secure-site-services/index.html

any suggestions?

thanks,

matt.

link ( http://support.microsoft.com/kb/931125 )  contains third-party commercial certification authorities (cas) trusted microsoft.

and here points need consider when certificate:

certificate requirements ts gateway

certificates ts gateway must meet these requirements:

  • the name in subject line of server certificate (certificate name, or cn) must match dns name client uses connect ts gateway server, unless using wildcard certificates or san attributes of certificates. if organization issues certificates enterprise certification authority (ca), certificate template must configured appropriate name supplied in certificate request. if organization issues certificates stand-alone ca, not need this.
    if using san attributes of certificates, clients connect ts gateway server must running remote desktop connection (rdc) 6.1. (rdc 6.1 [6.0.6001] supports remote desktop protocol 6.1.). rdc 6.1 included windows server 2008 , windows vista sp1 , windows xp sp3.


  • the intended purpose of certificate server authentication. extended key usage (eku) server authentication (1.3.6.1.5.5.7.3.1).
  • the certificate has corresponding private key.
  • the certificate has not expired. recommend certificate valid 1 year date of installation.
  • a certificate object identifier (also known oid) of 2.5.29.15 not required. however, if certificate plan use contains object identifier of 2.5.29.15, can use certificate if @ least 1 of following key usage values set: cert_key_encipherment_key_usage, cert_key_agreement_key_usage, , cert_data_encipherment_key_usage.
    for more information these values, see advanced certificate enrollment , management (http://go.microsoft.com/fwlink/?linkid=74577).


Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group