Re: RDP Security and the MITM Attacks...



I wasn't clear enough on that point. I meant for you to have IIS on the same machine as the TS, and use the wizard to walk you through the certificate request and then the certificate install.

After you have done that, the certificate will be in the Personal store for the computer account, thus enabling it to be selected from Terminal Services Configuration.

The method I describe is not the only way to get a certificate requested and installed. I selected it because many people are familiar with the IIS cert process, and you can find plenty of examples on the web that guide you through step by step. Another benefit is that it will make a request that has the correct enhanced key usage.

Yes, the certificates mmc snapin is helpful.

-TP

Andrew Bienhaus wrote:
"TP" wrote:
Yes, the problem is solved, but you need to take the necessary
steps. Preferrably you will need to obtain a public certificate,
install it, and then configure the TS server to use SSL for the
security layer.

On the client side, you need to use version 5.2.3790.1830 or
later, as well as set it to Require Authentication (preferred) or
Attempt Authentication. Please see my response in this thread:

Ok, one question, and my thanks. ;-)

In your example in that post, you create a cert request on a separate
IIS webserver, but then also imply that you install it on the same
webserver.

I would assume, that you actually install the cert on the terminal
server in question, no?

So, one would have to enable/install certificate services?

andrew
.



Relevant Pages

  • How to migrate my VeriSign SSL certificate from IIS 4 to IIS 5
    ... We've got a Verisign SSL certificate installed on our MS IIS 4 server. ... we install the current SSL certificate on the ...
    (Focus-Microsoft)
  • Integrating OWA & Exchange 2007 on ISA 2006
    ... I also have a Windows 2003 Server x32 which is a file server and has ISA ... It also has the certificate server installed. ... website on IIS 6, but I have not got this installed, and really if I can get ... away with it dont want to install it, as I want to use IIS 7 ...
    (microsoft.public.exchange.setup)
  • unable to install mscep.dll: setup failed
    ... On the Production machine i can not install mscep.dll. ... Using the MMC Snapin I can see that there is one Certificate ... MMC i can see that the certificate of Template CEPEncryption has been ... I assumed a problem with IIS setup and switched on logging. ...
    (microsoft.public.win2000.security)
  • RE: Client Certificates
    ... install a certificate on four workstations. ... Microsoft IIS Support ... Newsgroups: microsoft.public.inetserver.iis.security ...
    (microsoft.public.inetserver.iis.security)
  • Re: SSL certificate and IIS problems - HELP!
    ... when you created the certificate request using the IIS ... the response file MUST match the request as no-one else has even ...
    (microsoft.public.win2000.security)