XP SP3 CredSSP and an authentication problem


environment made of few windows server 2008 sp2 servers terminal services role, dozens windows xp sp3 rdp client 6.1 , smartcards used logging.

in default configuration works fine. if enable nla on clients (as described in http://support.microsoft.com/kb/951608/) cannot connect ts farm. following error "an authentication error has occured. requested security package not exist. remote computer: tsfarm.domain.local". appears either if use smartcard or enter username , password. if create rdp file "enablecredsspsupport:i:0" can connect. of course without nla. did miss in configuration?

applying http://support.microsoft.com/kb/969084 (rdp 7.0) didn't help.

regarding kb951608 - on xp sp3 key credentialsdelegation , below must manually created?

hi,

in kb951608, have following steps of "how turn on credssp". make sure credssp configured correctly on clients. client access ts (not farm) directly?

let know detailed information of farm certificate.

to monitor logon process, please collect network traffic troubleshooting:

download microsoft network monitor.
http://www.microsoft.com/downloads/details.aspx?familyid=983b941d-06cb-4658-b7f6-3088333d062f&displaylang=en

1. run network monitor , start capturing on client.
2. reproduce problem.
stop capturing, save result , upload file windows live skydrive (http://www.skydrive.live.com/). if other community member analyze report, can paste link here, if not, can send link tfwst@microsoft.com.


reference:
configuring terminal servers server authentication prevent “man in middle” attacks
http://blogs.msdn.com/b/rds/archive/2008/07/21/configuring-terminal-servers-for-server-authentication-to-prevent-man-in-the-middle-attacks.aspx

thanks.


this posting provided "as is" no warranties, , confers no rights. please remember click "mark answer" on post helps you, , click "unmark answer" if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group