Quantcast
Channel: Remote Desktop Services (Terminal Services) Forum
Viewing all 27656 articles
Browse latest View live

Reboots pending

$
0
0

Hi, when trying to make changes in our RDS 2012 deployment such as deploying license role or adding a session host to a collection, all servers in the deployment state "The server has reboots pending and needs to be restarted" - I have tried the obvious of restarting and a few posts suggests checking the fileoperations pending registry key but so far I am having no luck clearing this issue

Any ideas anyone?

Thanks in advance


Change keyboard layout in remote apps

$
0
0

Hello all,

We are using remote app server along with terminal server on the same machine

How can we make it possible to change input language in remote app (MS Dynamics for example)

Thank you

Remote Desktop Services HA Connection Broker DB Support

$
0
0

Hi All

We are currently in the process of upgrading all of ourSQL Server 2008R2 instances to SP3 (These currently run 2008R2 SP2).

We have an RDS Server 2012 farm using an HA Connection Broker setup where theHA-DB sits on one of the SQL 2008R2 servers.

Any response would be much appreciated!

Many Thanks

Jamie 

Private CA signed certificate for Remote Desktop for Administration

$
0
0

Hi,

I have a signed certificate by a private CA to use as a certificate for Remote Desktop for Administration.

I received a p7b file that I imported via MMC in Certificates (Local Computer) Personal chain. There I got a regular certificate and the private CA certificate.

When I look at the certificate and the certificate path it says "This certificate is OK".  The intended purpose is "Server authentication"

But when I go to Remote Desktop Host Configuration Tool and then the connection section -> properties -> General -> Security and click on the select button it says: "There are no certificates installed on this Remote Desktop Session Host Server."

I have also copied the certificates to the Remote Desktop of MyComputer section and the Private CA key to Trusted Root CA authorities but to no avail.

Can somebody tell me what I am doing wrong?

Thanks!

having trouble with connecting thin clients through rd

$
0
0

Hello,

one of my clients had previously activated a trial version of the server 2012 and remote desktop services and later they purchased a license and we activated the server as well as 4 rd cal's.

right now the problem is i cant connect to rd through thin clients on current date.

but when i change the date to 2 or 3 months back its working fine.

i have activated the licenses correctly and even uninstalled and reinstalled the remote desktop roles. they are on workgroup and not on domain. so need help regarding this.

RDS Gateway Randomly Unavailable

$
0
0

I currently have 3 Servers in an Server 2012 R2 RDS Farm with the following roles on them:

Server1

RD Gateway

RD Connection Broker

RD Web Access

Server 2

Session Host

Server 3

Session Host

When users try to connect externally they sometimes receive the message "RD Gateway Server Unavailable".  If they try a couple more times it eventually lets them connect, and then all is well.

What could be causing this?

When using explorer in RD Web Services not getting a prompt when deleting files off a share

$
0
0

Hi guys,

When using explorer in RD Web Services I'm not getting a prompt when deleting files off a DFS share. 

However when I log into the server in question using username /admin I do get the prompt.

Would any one know how this could be fixed? Just seems to be through the RD Web App explorer. 

Any clues would be much appreciated. 

RemoteAPP and screen resolution

$
0
0

Good afternoon.

Clients (Windows XP) are connected to the one specific program on the server (Server 2012) by the RDP (remoteAPP) shortcut. Many people are not satisfied with the small font, or high brightness of font. We have access to many parameters through connection to the Remote Desktop, including - screen resolution. Here, there are no such parameters on the RDP-shortcut. How can I customize the display settings in remoteapp shortcuts on individual clients (in separate sessions)?

Thank you for Your help.


RemoteApps and security

$
0
0

Hi

I'm doing my first time setup (testing) of RDS and remoteapps.  I'm using a Windows Server 2012R2 to deploy them using standard deployment. My setup includes Session Host, Connection Broker and Web Access on same server, and still have to configure gateway and license server.

I've installed several apps in the server and created a Collection with them. Granted permissions to all domain users to the collection. Accessed it using rdweb, downloaded the rdp file for one of them, and successfully connected to the remoteApp.

Then, I've modified the user group for that collection, REMOVING domain users and adding domain admins instead. Accessing through rdweb now shows an empty collection (as expected), but if I double click the RDP previously downloaded and use my domain user account, it still runs the application.

How can I prevent the application to be started by an unauthorized user that owns an rdp file for that remoteapp?

Thanks!

The request cannot be processed because a recreate job is already running or is scheduled to run in this collection

$
0
0

I have a clustered environment with three servers supporting Hyper-V 2012R2 for VDI's running windows 8.1. I have the environment in production and running just fine! There is one virtual server for connection broker, and another for web access.

 

I have tried relentlessly to update / recreate the base image to update my VDI's without success due to an error shown below.

"The request cannot be processed because a recreate job is already running or is scheduled to run in this collection"

 

I have successfully updated the base image twice before without issues. The problem seemed to have stemmed from deleting one of the VDI's and now the job is stuck? Even though I can create a "job" to successfully remove one of the VDI's, I cannot create a VDI or schedule a recreation without getting this error.

 

I have used PowerShell to check for Jobs running or failed etc. But NO jobs are running or have failed. I have rebooted all the servers without any success of being able to "release" this mystery job, and now my environment cannot do anything but run the VDI's.

 

Please help?

 

Thanks

Issues with certificate mismatch connecting to Session Host server

$
0
0
I am in the process of configuring a remote desktop environment in 2012 R2. I am allowing internal and external access through RDWeb. My configuration is as follows: 

RDWeb/Gateway on server NAT'd through firewall
Server DNS name (internal) rdweb.company.com
192.168.1.1 (Internal)/ 345.678.901.1 (external IP, secured with SSH. Gateway.company.com/rdweb)

RD Connection Broker
Server DNS Name (internal) rdbroker.company.com (assigned by changing the server name using a powershell script)
(192.168.1.2)

RD Session Host
Server DNS name (internal) rdsh.internal.company.com
(192.168.1.3)

Each server has a wildcard certificate installed on it.
Have DNS multi-zoned internal: company.com, internal.company.com

I have published apps on the RDWeb site. When launching an app, my issue arises when the connection broker hands off to the session host server - only when connecting from an external (off domain) machine - I get a "name mismatch" error certificate pop-up saying:

The remote computer could not be authenticated due to problems with its security certificate
Name mismatch
Requested remote computer: rdsh.internal.company.com
name in the certificate for the remote computer: *.company.com (wildcard cert)

Certificate errors
The server name on the certificate is incorrect.

Now, from what I can see, this only occurs when connecting from a remote computer - not from a computer connected to the domain. How, if I can, do I stop this from happening? I ultimately would want this session host server to use the wildcard certificate, but why does the session broker seem to use the internal FQDN instead of the name I specify through the wildcard?

Also, in a sewnse, I guess I am trying to figure out is if there is a way to either fix this with a self-signed cert from the machine (tried that, it just says that this is an untrusted cert from an untrusted provider) or manipulate the RDS implementation/Session Host server in a way which mimics the name I want to pass through. My wildcard certs work on the Web/gateway server and on the connection broker - this is configured automatically through the RDS configuration when building out the servers. There is nothing in the configuration, however, which talks about securing the session host server. Has anyone run into this, and how have you fixed it? Internal on the domain, Kerberos fixes it. When external though, it does not use Kerberos. How does this get fixed for external access where the cert error will not come up? I've read that having the 8.0 RDP client installed on a client machine will fix it, but I tried this, and I still get certificate errors when the connection broker hands off the connection to the session host server. 



Any help is appreciated!


usrlogon.cmd

$
0
0

Hi,

On our terminal services server, every time a user logs in, the usrlogon.cmd window pops up and prevents logging on until it has been closed down. I have disabled the command prompt which i'm guessing is why this usrlogon.cmd window pops up but is there any way i can hide it during the logon process?

I have seen numerous threads that adjust a registry key to run a batch file or executable or override the userlogon.cmd window. If anyone could shed some light on this, it would be much appreciated.

Regards,

Hasan

RemoteApp Source not working from RDWeb

$
0
0
I have 2 servers at the moment managed by a connection broker. If I choose a RemoteApp source instead of RD conncection broker then 1 of my servers populates all the apps fine. If I choose the other host then it errors and says 'RD Web Access was not able to access xxxx. Verify that the RD Session Host server name was entered correctly, that the server is running and connected to the network, and try again.' All the servers are R2 and I can RDP to each of the session hosts fine.
Amit MCSA 2003, VCP, CCA, MCTS:2008 AD

Configure Remote Desktop Services (RDP) on Server 2008R2 to accept TLS1.2 only

$
0
0
I am currently struggeling to get the RDP Connections working with TLS1.2 on Server 2008R2 SP1

Initially my RDP Service (out of the box), allowed Connections no better than TLS1.0
I am verifying this with an "openssl s_client" Connection

For example, a Server 2012R2 offers TLS1.2, if I check against its RDP port. Its RDP Version is 6.3


So I started with installing the Remote Desktop Packages Version 6.2+6.3 on my Server 2008R2
openssl s_client still connects with TLS1.0 at its best.

Next i tried to configure the Schannel Registry to support TLS 1.0, 1.1 and 1.2 via
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client]
"Enabled"=dword:00000001
"DisabledByDefault "=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server]
"Enabled"=dword:00000001
"DisabledByDefault "=dword:00000000
and so on for TLS1.1, but still only offers TLS1.0 on RDP port


I restricted the ciphers via GPO "Computer../Administrative.../Network/SSL Configuration.../SSL Cipher Suite Order" to be
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384_P521,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384_P384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P521,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P256,TLS_RSA_WITH_NULL_SHA256,TLS_DHE_DSS_WITH_AES_256_CBC_SHA256,TLS_DHE_DSS_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384_P521,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384_P384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P521,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P256,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P521,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P521,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256,TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256

Which IMO should only allow TLS 1.2 implicitly.

But afterwards the RDP session totally refuses ANY connections. I had to log on to the console and Switch off that GPO again.

I read many articles on the net where others hat similar Problems getting this configuration to work.
Some of them have pretty current postings (2015-AUG)

Whats the trick with activating this? It seems to work perfect on the same RDP Version in 2012R2 Servers.

Mac OS RDP client cannot connect with RDP Gateway

$
0
0

HI,

I've set up an RDP gateway and can connect to hosts behind the gateway when I use a Windows machine (mstsc.exe or the Remote Desktop Connection Manager) and specify the gateway.

The gateway is running Windows Server 2012 R2.

I am attempting the same with a Mac machine running the Microsoft RDP app and keep getting a "connection reset by peer" message as soon as I hit connect. Same configuration as the windows machine -- rdp gateway specified along with the internal server name and user names.

I'm wondering if this is a known issue or common problem? I've done some searching and haven't turned anything up. RDP and Apple machines are not my specialty so please forgive me if this information is easily available.

Thank you,

Jason



Users not showing in Terminal Server Under Remote desktop services manager and Task Manager

$
0
0

Hi All,

I have a problem here in Terminal Server. I can not see the users logged in to Server but i know users are accessing the files and currently working.

1. From the Task Manager-- Show processes from all users displayed all the processes accessing by users.

2. From the Task Manager-- From Users Tab--No users list at all

3. From the Command Prompt- Query users-- No information

4. From the Remote desktop services Manager-- used with IP/Host name-- Still can not see the users list and processes. So i can not kill the session if needed.

Enviroment:

TS CALS 20 currently accessing 15 users

VM-WARE GUEST: 2008 RS Terminal Services/Remote Desktop services installed

Windows up to date-- Just updated last month

Problem is here for long time. Just couldn't find the time to trouble shoot.


UMESH DEUJA MCP,MCTS,MCSA,CCNA


Force "I am using a private computer..." option to be ticked

$
0
0

Hello.

I have built a Remote Desktop Services environment on Windows 2012 R2 servers.  It all works perfectly but I'd like to force the "I am using a private computer..." option to be checked when people open the "Connect to a remote PC" page (/en-us/Desktops.aspx).  I have read various blogs and articles, many suggestion the same or similar approaches, but for me the option is never checked by default.  I have:

1. Changed document.getElementById("rdoPblc").checked tofalse in webscripts-domain.js

2. Set public bool bPrivateMode to true in Desktops.aspx

Is there anything else I need to do?  Am I missing something simple?  I have tried running IISRESET and also restarting the server hosting the Web Access role.  The option is always ticked on the Default.aspx page (RemoteApp) but never on the Desktops.aspx page.

Thanks in advance.
D

Remote Desktop RDWeb Session Caching?

$
0
0

Hello, 

I have an unusual issue.  We are running Dynamics GP as a RemoteAPP.  Our RD environment is server 2012 R2 and the client machine is Windows 7 64bit. 

We run GP in two environments, a test and a production.  I created two collection groups to achieve this.  

1. GP

2. GPTest

When we open GP production from the RemoteApp shortcut (RDWeb, and start Menu Shortcut) it works perfectly fine every time.  When we try Test it opens correctly the fist time, but the when we close the application the and open it a second time it opens a session in the GP Production collection group.  

I can't seem to find anything in regards to caching this kind of connection and it seems very odd.  Has anyone heard of this happening?

Remote Desktop Gateway service timeout and hang with Azure MFA

$
0
0

I've installed a server with Remote Desktop Gateway role and configured it according to guidance in http://www.rdsgurus.com/uncategorized/step-by-step-using-windows-server-2012-r2-rd-gateway-with-azure-multifactor-authentication/. This works fine when I accept or reject the phone call within 30 seconds. If the MFA server doesn't respond within those 30 seconds the Remote Desktop Gateway service hangs itself and needs a restart to start working again (it also doesn't shut down gracefully, needs to time out).

I've set the Remote Radius Server timeouts to different values between 20 and 90 seconds but this timeout seems to be hardcoded somewhere as suggested in https://social.technet.microsoft.com/Forums/en-US/cbcb46e3-9dc4-4079-a254-d5d8a0f78b95/remote-desktop-gateway-authentication-timeout-change?forum=winserverTS (original post is old but newest post is in regards to Azure MFA)

I've tried installing again from scratch with Windows Server 2012R2, with just Windows 2012. I've also tried different setups:

- Local NPS proxying to MFA server

- Central NPS proxying to MFA server

- Local NPS proxying to MFA which proxies to Central NPS

They all work but all have the same 30 second limit and my Remote Desktop Gateway service hangs.

Looking around on the internet it looks like there are people that have this working so I'm not sure what the difference is between their setup and mine or if they've never tested this scenario. I think the 30 seconds timeout should be enough for just voice call authentication without PIN if I can just stop my RDG service from dying.

Publish RDP connections through RDWeb App

$
0
0

Hello,

I know it is possible to publish a RDP connection through the RDWeb App but adding a command line switch for /v:<server name> but is it possible to just do a straight RDP connection to the RDS Server?

The problem with adding a mstsc remote app and using the /v:<servername> switch, is that it spawns two RDP sessions on the server itself. 

How is it possible to just publish a straight RDP connection to the RDServer?

Cheers!

Peter

Viewing all 27656 articles
Browse latest View live