Windows 2003 server and RDP


hello -

company underwent security audit. 1 of our largest issues "man in middle" attacks against our 2003 servers running rdp 5.2. apparently, need able utilize ssl authentication option available in rdp 6.1. (we have few 2008 servers version running).

question @ point is, can upgrade 2003 server use rdp 6.1. sure cant find download if so. can find loads on updating client, client not issue.

in advance assistance!

hi,

you not need upgrade newer version, need configure 2003 server use ssl (and set client pc warn if server authentication fails).  basic steps are:

1. request , purchase certificate public authority godaddy, geotrust, thawte, etc.  import certificate along private key local computer\personal store of ts using certificates mmc snapin.  name choose certificate name people have enter rd client need create dns record pointing public ip of server.

2. configure ts use ssl security layer.  open terminal services configuration (tscc.msc), double-click rdp-tcp, select certificate using edit button, select ssl security layer, , select high encryption level.

3. have clients connect server using name above remote desktop client version 5.2.3790.1830 or later , have set do not connect if authentication fails (or require authentication, depending on client version).  if client using xp sp3, vista, windows 7 have rd client version new enough.

thanks.

-tp



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group