Re: TS Gateway configuration/issues with non-domain membership
- From: Kaus <Kaus@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 22 Jul 2009 04:39:01 -0700
What is the error coming when the clients are trying to connect ?
If TSG is deployed in workgroup mode, you cannot use domain accounts to
authenticate or authorize users.
Thanks,
Kaustubh
"Alex Borleis" wrote:
Hi Kaustubh,.
thanks for your reply!
Yes - it seems that the network service (the service account for the TS
Gateway) has no access to the private key. When I use a different
account to run the TS gateway service and use the same account to import
the certificate, the error won't appear.
But the clients are still not able to connect to TS gateway - Microsoft
says, the TS gateway has to be a domain member
/http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/27c39b63-9e4d-4c30-ab24-aabde8ae93af)
But this is not the same information as in
http://technet.microsoft.com/en-us/library/cc754010(WS.10).aspx
I'm not sure, which information is correct...
Greetings,
Alex
Kaus wrote:
Hi Alex,
The error no "2148081675" is :
2148081675 CRYPT_E_NO_KEY_PROPERTY: The certificate doesn't have a private
key property
Are you sure that the certificate installed on the gateway had a
corresponding private key (pfx file format) . If yes, can you please try
installing the certificate on the gateway once more and see if the problem
still persists.
Thanks,
Kaustubh
"Alex Borleis" wrote:
One more point - it works pretty good with a self-signed certificate...
but it does not worked if I choose the certifate from the AD integrated PKI.
If I choose that certifcate, a critical event occurs (ID 103): The
Terminal Services Gateway service does not have sufficient permissions
to access the Secure Sockets Layer (SSL) certificate that is required to
accept connections. To resolve this issue, bind (map) a valid SSL
certificate by using TS Gateway Manager. For more information, see
"Obtain a certificate for the TS Gateway server" in the TS Gateway Help.
The following error occurred: "2148081675".
I checked the read permission for the network service. Seemed to be ok...
Greetings,
Alex!
- References:
- TS Gateway configuration/issues with non-domain membership
- From: Alex Borleis
- Re: TS Gateway configuration/issues with non-domain membership
- From: Alex Borleis
- Re: TS Gateway configuration/issues with non-domain membership
- From: Kaus
- Re: TS Gateway configuration/issues with non-domain membership
- From: Alex Borleis
- TS Gateway configuration/issues with non-domain membership
- Prev by Date: Re: Windows and office 2003 on TS
- Next by Date: Time to renew certificate used for signing .rdp files
- Previous by thread: Re: TS Gateway configuration/issues with non-domain membership
- Next by thread: Terminal Server installed in SBS 2003 environment
- Index(es):
Relevant Pages
|
Loading