Quantcast
Channel: Remote Desktop Services (Terminal Services) Forum
Viewing all 27656 articles
Browse latest View live

Need assistance in completing the cert enrollment.

$
0
0
I am creating a SAN certificate CSR using the option "Certificate Enrollment wizard with a standalone CA" in this link - https://technet.microsoft.com/en-us/library/ff625722(v=ws.10).aspx#BKMK_CertEnroll

When completing the certificate enrollmet, I use the cert from my 3rd party CA and the file will be mycert.CRT.  May someone give me some example of using the CERTREQ.EXE in the link? 

In the name, it says "Servername\CAName".  In my case, it is a godaddy.com.  "CertificaeRequest.req" which I assume it is my certificate request file?  But I usually use the extension .txt.  The "CertificateResponse.cer", again, my 3rd party CA they always give me a final cert with a  .zip files which composes of both the .CRT and another intermediate file.7b.  And the "RequestID" - dont know where to get it.

I do not know how to put the above together.  How do I do this in MMC?

Local FQDN shown when connecting to Session Host through RD-Gateway

$
0
0

Hello,

I'm in the process of deploying remote desktop services for our company to see if it's viable for our situation.
I've got everything working. The only thing that's bugging me is that the local FQDN is show when connecting to a full desktop session host.
I've set the "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\CentralPublishedResources\PublishedFarms\<Collection>\RemoteDesktops\<Collection>\ShowInPortal" to 1 to show the Remote Desktop Connection shortcut in RD Web Access.

> Server certificates are all published in the RDS deployment properties. (We have bought a wildcard certificate from a trusted CA.)
- RDCB SSO: Trusted & OK
- RDCB Publishing: Trusted & OK
- RD Web Access: Trusted & Error (All services are on single server with HA)
- RD Gateway: Trusted & OK

> RD Gateway specific certificates are also uploaded through the RD Gateway Manager.
> RD Connection Broker HA DNS RR is set to remote.domain.com in the deployment properties.
> RD Gateway server name is also configured to remote.domain.com in the deployment properties.
> RD Gateway HA is configured with NLB on the second NIC of each server, with cluster name also set to remote.domain.com.

I've configured the Gateway RAP to only allow connection to the RD Server Farm through the DNS RR name, being remote.domain.com, which we have also configured in our local DNS server to point to the RDCB.

Now, when I try to connect through RD Gateway, I sometimes get the below error.
Remote Desktop can't connect to the remote computer "remote.domain.com" for one of these reasons:
1) Your user account is not listed in the RD Gateway's permission list
2) You might have specified the remote computer in NetBIOS format (for example, computer1), but the RD Gateway is expecting an FQDN or IP address format (for example computer1.fabrikam.com or 157.60.0.1).
Contact your network administrator for assistance.

I don't get this error when I open a RemoteApp in the same session.
When I add the farm members (using local server name) individually to the network resources, this works, but then I get the certificate mismatch. (This is also specified on the Network resources tab:Note: if you are using a Remote Desktop Session Host server farm, the name of the farm and the name of each member must be specified in the computer group.)

Name mismatch
Requested remote computer: servername.domain.local
Name in the certificate from the remote computer: *.domain.com

I've searched the internet for days now, but haven't found a solution yet. Or I must be doing something wrong.
Need to note that I've also tried adding the servers to the network resources using a different DNS name (rds01.domain.com, rds02.domain.com), but that doesn't seem to do anything. Then I get the error again (Remote Desktop can't connect...)

Hope I'm missing something here, cause I don't want local server name or IP to be visible.

Ipad2 rdp access to windows 2008 failing with "The requested session access is denied"

$
0
0
The above error occurs on the users ipad2 , yet the user can access his account from a any pc

Remote desktop Display!

$
0
0

Hello,

I hope someone can help me. a User has passed me a laptop which is new and everytime they log onto remote desktop the icons are so small infact everything is. the laptop OS is win 8.1 and the remote is WS 2008 R2. I can change it via the laptop screen Resolution but its not idea as the screen doesnt look great. the laptop screen resolution is 3200 x 1800.

Any suggestions would be greatful.

Kaveh

RDWeb collection empty - exhausted web research

$
0
0

Hello,

I've been working with a Windows 2012R2 server that was thoroughly mishandled by another engineer. this engineer decided it was a good idea to mess with the local profile of the administrator account (among others) and ended up bricking the server practically completely. Some other engineer managed to salvaged what was left by doing an upgrade and making the server somewhat usable. That's where I came in. To initially solve some permission issues but ending up solving a whole host of other issues (Powershell was totally messed up, Powershell remoting didn't work, ServerManager started up but gave errors, and so on ...)

I made it possible again to publish remote apps without it erroring out (renaming the collection was in the process). But now I'm still facing one issue, the remote apps are not visible in the RWeb page. No icons, nothing. I've tripple-checked every setting, permission and whatnot but nothing budges. I've searched the Internet high and low, tried many, many suggestions made in many, many blogs, but I think something is still not working like it should and I can't pinpoint it. I'm also unable for some reason to connect to the rdweb page from another PC, only locally.

The many logs don't shed any light on the situation either. And yes, all this time spent on trying to fix the issue could've been better spent rebuilding the server, but as is often the cause, this is not really possible at the moment.

So I'm looking for some ideas, tips, anything to get me on the path again.Thanks for any help at all!

RemoteApp - Pop-ups hidden behind main window

$
0
0

We are using RemoteApp in Windows Server 2012 to publish Microsoft Dynamics AX 2012.

Sometimes when the user clicks on something inside the application that generates a popup of a new windows, this new window is opened behind the main windows. This causes confusion to the users.

I have found the following Kb articles/hotfixes that seem to describe the problem:
http://support.microsoft.com/kb/2580346
http://support.microsoft.com/kb/2384602
http://support.microsoft.com/kb/983533

However, all these hotfixes are applicable only to Windows 2008 (R2), and not Windows Server 2012.

Are there any updated hotfixes for 2012 somewhere?

Printer redirection issue

$
0
0

We have a new windows server 2012(not r2), which is used as a remote desktop server. We had sat up group policy and everything worked great untill printer redirection stopped working. The redirected printers does not redirect at all no more. We allso have alot of errors in event viewer: 

Event ID 1107: The printer *printername* could not be deleted. 

Event ID 354:\\*printerserver*\*printer* initialization failed at \\*printerserver*\print$\COLOR\CNZ007.ICC. Error: 2. The system cannot find the file specified.. This can occur because of system instability or a lack of system resources.

Event ID 7000: The Portable Device Enumerator Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Event ID 7011: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AllUserInstallAgent service.

Event ID 10028: DCOM was unable to communicate with the computer RDservername.domain.local using any of the configured protocols; requested by PID      af4 (C:\Windows\system32\ServerManager.exe).

Event ID 3: Filter Manager failed to attach to volume '\Device\HarddiskVolume95'.  This volume will be unavailable for filtering until a reboot.  The final status was 0xC03A001C.

Event ID 137: The default transaction resource manager on volume C:\Users\*user* encountered a non-retryable error and could not start.  The data contains the error code.


I suspect that event id 1107 has something to do with it as the server fails to delete the redirected printers after logof or something. 

The print spooler does not stop, but when i restart it, printer redirection works, but after any user logs off the server, it stops working again. 

The clients get the printers from a print server, and the remote desktop server get the drivers from the same print server so i dont think it is a driver issue. 

Has anyone experienced something similar? 




Remote Desktop Services, Overview never refresh

$
0
0
Hello,

We have a 2012 R2 AD DS server that also has the RD Licensing roles, RD Connection Broker and RD Web Access

And an other server with Host RD Remote Desktop session.

The system worked well for several months.

I wanted to add a virtualization Host and the result of this operation is that I can't no longer access the configuration in the Server Manager:

When going to "Remote Desktop Services" it begins by having the message "Connecting to the RD connection Broker server" then I arrive in "Overview" where deployment overview doesn't fill the various nodes of the diagram (RD Web Access, RD Connection Broker, RD Licensing, ...) remain with (+) and the gauge "runs" as if the update was in progress. Deployment servers block remains empty and in Task menu everything is gray.

In the "Servers" both servers are visible and are "Online", all services are running.

In the "Collections" everything is empty and appears being updated.

Otherwise clients can connect and everything works fine !

Any idea ?

Denis Ramstein


IIS redirect for RDWeb when web access and gateway roles are on the same server. Does it work?

$
0
0

I would like to set up IIS redirect as per: http://miscproject.blogspot.co.uk/2015/07/branding-microsoft-remote-desktop-web.html

This should allow users to remember an even simpler URL for web access.

However, our WA and GW roles are combined on the same server, so I am wondering if this is an acceptable change in this scenario, or if setting the redirect will break the gateway connectivity?

Cheers.

Default Printer changes - Users terminal server

$
0
0
I have three 2008 terminal servers and they are 64 bit running fairly well.

We have some users that call up saying that there default printer keeps changing.

We have one local printer on all the TS's ... and that is PDF Creator, rest are network printers

So sometimes when they log into the TS their default printer changes to the PDF Creator.

It's not a printer on the 'local' computer so it's not being redirected
It doesn't happen all the time
I have made fully sure that they are logging off and not disconnecting the session.

any tips ?

The settings for this terminal server cannot be retrieved. The remote server does not support running Terminal Services Configuration Tool remotely.

$
0
0

I'm trying to change a couple of options on one of our TS but when I go into the Terminal Services Configuration I get the following error:

The settings for this terminal server cannot be retrieved.  The remote server does not support running Terminal Services Configuration Tool remotely.

The thing is..... I'm not running it remotely, this on trying to retrieve the settings on the local machine.

I get the same error when trying to run it from within the mmc or by just running tsconfig.msc

The server is running Windows Server 2008 Std SP2 x64

Any ideas why it won't run?

Cheers

Adam.

Is there a way to check if the handle created through WTSVirtualChannelOpen is already stale?

$
0
0
When the workstation for some reason disconnects from the terminal server then reconnects, the handle to the current virtual channel that is tracked by the server piece/program might no longer be valid for the reconnected session. Is there a way to prove the handle/connection if it is still valid or not?

Requested session denied remote control

$
0
0

We have two Windows 2008 R2 server as remote desktop servers for clients to access remotely. We use Remote Control to access the client remote session whenever they have a problem.  That works fine. However, since yesterday, we can't remote control one client remote session with this error: Requested session denied remote control.

I have tried two different domain admin accounts. All get the same error. Any suggestions?


Bob Lin, MCSE & CNE Networking, Internet, Routing, VPN Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net How to Install and Configure Windows, VMware, Virtualization and Cisco on http://www.HowToNetworking.com


RemoteFX/Hyper-V Artifacting with Windows 10 Client on Windows Server 2016 Technical Preview 5

$
0
0

With the introduction of H.264 acceleration in RemoteFX/RDS I'm finally trying to replace a handful of ageing workstations with one central server. So far, the testing has been going almost seamlessly. AutoCAD Fusion 360 and some of the editing workflows have been taking advantage of vGPUs. However, I seem to get this problem when using RemoteFX where there are substantial and persistent artifacts on system windows (Start Menu and Settings for example). This wouldn't be an issue if they disappeared quickly but they sometimes persist for 30-45 seconds which really hurts usability.

Any thoughts on cause?

Server 2012r2 unpin from taskbar file explorer

$
0
0

I have asked this question on several forums now with no luck, so maybe someone here can give me some help??? I don't understand why this is so difficult... Some one on the powershell forum said to try this, but it didn't work either...

 ----------------------------------                    

$sa = new-object -c shell.application
$pn = $sa.namespace($env:windir).parsename('explorer.exe')
$pn.invokeverb('taskbarunpin'

-------------------------------

So here is my post again......

Hello, I have tried this on a few different forums including server 2012 general... Is there a powershell script to unpin file explorer for all new users when they log in on a rds/citrix session but still allows me to use my powershell script to pin our companies icons to the taskbar as we have it setup in the all users startup? Here is my post from another forum...

I posted this on the server group and got a few replies but no one was able to help me and the MVP said I should try here.

All I am trying to do is:

Server 2012r2, I use classic shell to lock down most of it and it works fine. I have file explorer left that is pinned to the taskbar. I would like to get rid of it altogether for every

user that logs on.

1.) I don't want to use the GPO to do this as it doesn't allow anything to be pinned afterwards and I have a vbs in the all user startup that points to powershell needs to pin our default apps. So all I need

is something to remove file explorer at logon..

1.) I have tried to use the same powershell and added the file explorer.lnk  to the remove apps part and that didn't work.

2.) I have tried another powershell written to remove apps from taskbar but it didn't work either... I tried off this forum the one that was reposted by syntax 53 who altered it to reflect taskbar.. 

http://www.tenforums.com/customization/21002-how-automatically-cmd-powershell-script-unpin-all-apps-start.html

 I put the above in the gpo user startup powershell scripts... Didn't work

3.) I logged in to server as myself and got the taskbar to be empty went to regedit opened hkcu.......taskband, exported that out put it in our scripts folder on the server and

then went to the gpo users startup bat and added he line   Regedit.exe /S C:\Scripts\TaskBand.reg....   That still didn't do it for me.. (I tried this option twice as the first time I forgot

to clear out the user profile off the profile server and start with a fresh one)

4.) This was interesting and was almost there, but it stopped short of getting rid of file explorer..

http://clintboessen.blogspot.com/2014/12/remove-power-shell-and-server-manager.html

I am to my wits end on this... Can someone tell me how to get rid of file explorer off the taskbar but still let me have the ability to run the powershell to pin the default apps which happens from script in the all users startup?

========================

If I can't have that happen is there a way to have file explorer only show the users z:drive?  home directory? That would be acceptable....

On that note, on our 2008r2 servers we have the document folder pointing to z.... I can't get that to happen in server 2012r2... Is there something different you have to do for that

in 2012r2?   So if I can get file explorer and documents folder to go to z, then I would be good with that...

Thanks.


Windows 7 machine cant connect to Remote desktop gateway after windows update

$
0
0

Hi All,

We have a remote desktop gateway server running windows server 2012 R2 standard serving 20 internal machines.The clients are connecting from their windows box (running windows 7 professional 64bitsp1) to the internal computers through remote desktop gateway server.

Recently after updating the remote desktop client to version 8.1 from 7.1 clients are not able to connect to the server.We dont want to downgrade remote desktop client.

I believe the issue is client is initiating a TLS 1.2 which the remote desktop gateway server does not support.

I am stuck for last three days..Please help me

Thanks in advance


Arjun

Still have users getting logged in with Temporary Profiles using UPD

$
0
0

Hello,

I keep waiting for a hotfix or a cure for an issue we have for quite some time with our Windows 2012R2 RDS Farm. It seems that about 10% of the users are getting logged in on a daily basis with temporary profiles. The UPD store has the correct permissions and everything seems to be setup correctly. Often times the users that are new are not getting a UPD created and instead are using a temp profile. It seems that sometimes we have to go to Edit the Properties of the Collection and turn UPD off click Save and then turn UPD on again and this will have an effect (maybe we are just imagining this).

Anyway we are hoping to continue to use UPD, but we need it to be more reliable.

Thank you


Steve J.


Remote Desktop Connection Issue

$
0
0

When using RDC to connect from Computer 1 to Computer 2, I am running into an issue. Both machines are running Windows 10.

Upon connection, Computer 2 (remote), gets a black screen while Computer one (local) takes over as a logged in user.

The issue is the user on Computer 2 (remote) can simply click the black screen, to get to the user account sign in screen and simply sign in again thereby disconnecting the remote session.

How can I prevent the user on Computer 2 (remote) from doing this until I have completed my updates and ended the session?

Windows 2012 - Not Able to Copy Paste Files over RDP.

$
0
0

Hi,

We have Windows 2012 R2 Servers and having Terminal Services Installed, the proper resource redirection settings is in plance (Drive, Clipboard etc) but still we are not able to copy / paste the files over RDP, when i take RDP of Windows 2012 R2 and trying to copy files from my laptop to server the paste option is always showing as grayed out.

We are able to copy/paste files over RDP on Windows 2008 Server which is located in same OU in Domain where Windows 2012 R2 located, same GPO's are applying on both servers. We have also tried on Physical/Virtual/Domain/Workgroup/Terminal Servers/Non Terminal Services Windows 2012 R2 servers and found same issue.

Please suggest what needs to be check further.

Regards,

SGH.


MCP, MCTS

SSL cert needed for Windows 2012 RDS environment.

$
0
0
I am trying to create a seamless login experience for my Windows 2012 RDS environment. 

Currently, in my collection broker security settings, I am using "Negotiate" under security layer, and I have "Allow connections only from computers running Remote Desktop with Network Level Authentication" checked.  

When I purchase a SSL certificate for the RD Connection Broker Enable Single Sign On and Publishing role services, can I just use a single cert such as mybrokerserver.mydomain.com?  

As for the RD Web Access role service and RD Gateway, can I use another single cert such as remote.mydomain.com?

Using a wildcard probably makes more sense here, but we want to use an already existed Go Daddy UCC and add additional websites.  

Please advise if you have an idea of what I should get.  

Thanks.
Viewing all 27656 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>