D
DavidB
Cross posting from micorosft.public.security.crypto:
I need to issue some certificates to my terminal servers so I can
secure RDP sessions. I want to use the negotiate TLS and I want to
get rid of the warning messages from the new RDP client. I've been
having a difficult time issuing a certificate which will have all the
names I need for a particular server.
The default certificate only includes the FQDN of the server which is
not too smart in my opinion because locally connected machines use
the
common or short name or ip address to connect up.
From Exchange 2007 certificates I know that we need a SAN or subject
alternative name to get these to authenticate correctly. I wanted to
enter the dns entry for the server short name and the ip address if
possible to the SAN.
I can't get these issued correctly using the mmc console because it
just streamlines the process and never asks me for the SAN entries.
I've tried the command line certreq but that certificate always gets
issued to the administrator and the terminal server won't allow me to
use it! I don't have the IIS pages installed for security.
Anyone else run into this issue and solve it? Driving me nuts!!
Thanks in advance,
DavidB
I need to issue some certificates to my terminal servers so I can
secure RDP sessions. I want to use the negotiate TLS and I want to
get rid of the warning messages from the new RDP client. I've been
having a difficult time issuing a certificate which will have all the
names I need for a particular server.
The default certificate only includes the FQDN of the server which is
not too smart in my opinion because locally connected machines use
the
common or short name or ip address to connect up.
From Exchange 2007 certificates I know that we need a SAN or subject
alternative name to get these to authenticate correctly. I wanted to
enter the dns entry for the server short name and the ip address if
possible to the SAN.
I can't get these issued correctly using the mmc console because it
just streamlines the process and never asks me for the SAN entries.
I've tried the command line certreq but that certificate always gets
issued to the administrator and the terminal server won't allow me to
use it! I don't have the IIS pages installed for security.
Anyone else run into this issue and solve it? Driving me nuts!!
Thanks in advance,
DavidB