Hi!
I set up two RD-Gateway servers (Server 2008 R2).
First server working fine.
I exported RD-Gateway configuration on first server and imported this file on second server.
I use certificate with correct subject name (and SAN) from our corporate CA.
But second server does not works with smart-card authentification. :-(
When I try to connect to resource through RD-gateway and use NTLM authentification - all OK.
When I try to use smart-card - I receive "the logon attempt failed" error on client PC.
But I may succesfully logged on with this smart-card directly on RD-gateway server (locally or through RDP).
In server event log there are two error in Security log:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: servername
Description:
An account failed to log on.
Subject:
Security ID: SYSTEM
Account Name: servername$
Account Domain: domain
Logon ID: 0x3e7
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name:
Account Domain:
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc0000064
Process Information:
Caller Process ID: 0x1d4
Caller Process Name: C:\Windows\System32\lsass.exe
Network Information:
Workstation Name: servername
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Schannel
Authentication Package: Kerberos
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
And then this error:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: servername
Description: An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name:
Account Domain:
Failure Information:
Failure Reason: An Error occured during Logon.
Status: 0xc000006d
Sub Status: 0x80090325
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Schannel
Authentication Package: Schannel
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
What wrong with smart-card logon on seconf server? Thank you.