RDS 2012 - using Virtulization Host role on HyperV Servers hosting VMs

I have an existing RDS2012 farm which is working great with Session Hosted Desktops.
I'm looking to evaluate pooled Windows 8.1 desktops and know I need to run these on HyperV servers with the RDS Virtualization host role installed.
I have an existing production HyperV cluster for servers and am wondering if i should use this for the Windows 8.1 VMs and if so, do i need to install the virtualization host role on all servers in this cluster.
Or would it be best practise to dedicate a HyperV server/cluster purely for hosting the RDS Win8 client VM's (and keeping the virtualization host role off the production HyperV cluster)?
Thanks.

Virtual Desktops have different performance and capacity requirements than typical server workloads.  It is recommended to visualize desktops on hyper-visors dedicated to desktops only.  For capacity planning for virtual desktops on Hyper V, refer
to this document -> http://download.microsoft.com/download/2/4/B/24B5EC7D-1D03-49A2-B792-C7EDF24549EE/Windows_Server_2012_Capacity_Planning_for_VDI_White_Paper.pdf
HTH,
JB

Similar Messages

  • RDS 2012 - Using a reverse proxy with the Gateway server on the internal LAN

    Hi there,
    I'm looking to introduce an RDS 2012 farm and would like to put the RDS Gateway server on the internal LAN (due to it's AD requirements etc).
    What are the best practise options for using a reverse proxy to forward traffic to the gateway server and is it better to do this than just forward 443 traffic from the DMZ through to the Gateway directly?
    Thanks,
    Paul.

    Hi Paul,
    It is generally considered more secure to have a reverse proxy in front of RDG.  I don't know of a proxy that will handle the RDG UDP traffic, so you will need to consider using direct server return for that or not having the benefit of UDP.  Whether
    or not it is acceptable to simply forward TCP 443/UDP 3391 directly to your internal RDG is up to your security policies.  Many companies are fine with it while many other companies think it is unacceptable and require a reverse proxy or other method
    to provide an extra layer of protection.
    -TP

  • Shared Smartphone storage (Mass Storage, MTP Device) over RDS 2012 using Thin Pro

    Hi, I have a customer using  thin client (t520) really nice devices, running thin pro (I upgraded the one I was working for testing to thin pro 5.2 with no luck with resolving my issue. My issue is :They taking a lot of picture with their smartphone (iphone and android devices) and would like to have the ability to retrieve their photos from their phones in their RDS  session. Redirecting works fine using usb stick but smartphone shows up as unknown device in the RDS session.
    This works fine from Windows 7 or WIndows 8. Do you have a solution for this issue. Thank you. 

    Hi and welcome to the forums!
    GREAT FIRST POST!! Very clear and specific. You don't know how rare that is
    Is the laptop in a docking bay?
    Content "encryption" meaning Content protection is turned off, right?
    Are you able to backup and sync with the Desktop software?
    Do you have the correct folders on the card?
    Blackberry, music, ringtones, pictures, videos, voice notes?
    (blackberry has to be first).
    Last one, how did you format the card?
    Thanks
    Update device drivers manually:
    http://www.blackberry.com/btsc/search.do?cmd=displ​ayKC&docType=kc&externalId=KB13336&sliceId=SAL_Pub​...
    Message Edited by Bifocals on 11-19-2008 08:36 PM
    Click Accept as Solution for posts that have solved your issue(s)!
    Be sure to click Like! for those who have helped you.
    Install BlackBerry Protect it's a free application designed to help find your lost BlackBerry smartphone, and keep the information on it secure.

  • RDS 2012 Connection Broker and Web Access in different domains

    Hello!
    I'm trying to add Web Access (WA) server to RDS 2012 Deployment. WA server and other servers in Deployment are in different domains (in different forests with 2-way forest trust).
    WA server was added to Deployment
    successfully without any warnings.
    We have many applications published but in this new WA server there are no application icons in Rdweb page at all.
    There is nothing interesting in logs on WA server as well as on Connection broker servers. 
    Is this design
    acceptable? Which additional actions are needed to make application icons visible?

    Hi,
    Please refer below links and cross verify the Web Acess server settings.
    http://blog.kristinlgriffin.com/2010/03/rd-web-access-is-emply.html
    http://social.technet.microsoft.com/wiki/contents/articles/5974.the-case-of-invisible-remoteapp-programs-a-k-a-no-remoteapp-programs-listed-on-rd-web-access-site.aspx
    Regards,
    Manjunath Sullad

  • RDS 2012 External access for Session Hosts over different port to default 443

    Hello there
    I am having problems solving this problem as you may see on other posts, so I am going to try again.
    I have two Server 2012 machines for RDS. Server 1 one with all roles (Gateway, Broker, Session host etc.) and second machine, Server 2 as a session host only. I am running RDWeb Apps, with CA certificate installed and
    everything works fine internally.
    Due to limitations on the router I had to change the default SSL port on the gateway (Server 1) to 4043. I have this and 3391 for UDP open to Server 1 from the router.
    Working externally, I can login to the RDS site and open apps form Server 1, but when I try to open an app installed on Server 2, I get a certificate error.  The error is:
    “Your computer can’t connect to the remote computer because the Remote Desktop Gateway server address
    and the certificate subject name do not match. Contact your network administrator for assistance". 
    The certificate address the error points to is referring to is an SBS 2011 cert for RWW and email. Experimenting, if I use 443 on the Server 1
    gateway instead of 4043 and change the router accordingly, it then works. I can open apps form both session hosts externally . But not if is set to 4043. 
    For the record Server 2 session host also gives this error:
    Event ID: 1280 Warning Microsoft Windows TerminalServcies-session broker client 
    Remote Desktop Services failed to join the Connection Broker on server sever-vm1.local.
    Error: Current async message was dropped by async dispatcher, because there is a new message which will override the current one.
    Because everything works fine using default 443, I figure this is a communication or firewall issue between the gateway and the session host on Server 2.  
    Can anyone help here? 
    Many Thanks 
    MIS5000

    Hi,
    Thanks for your comment.
    Have you check the connection on your second server?
    Can you ping the server 2 from server 1?
    As from the event ID 1280 it seems there is some network connectivity to RDCB server. Also please “Add the RD Session Host server to the Session Broker Computers group” & RDWeb server's computer account needs to be a member of the local TS Web Access Computers
    group on your RDSH server.  You can get the detailed information from this article.
    In addition, do you have certificate purchased and install from trusted root authority. There is some requirement to use certificate for RDS environment, please consider following points.
    1. The certificate is installed into computer’s “Personal” certificate store. 
    2. The certificate has a corresponding private key. 
    3. The "Enhanced Key Usage" extension has a value of either "Server Authentication" or "Remote Desktop Authentication" (1.3.6.1.4.1.311.54.1.2). Certificates with no "Enhanced Key Usage" extension can be used as well. 
    You can get more details regarding certificatehere.
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • Windows Server 2012 Used: Error Message from Windows 7 PC: Remote session was disconnected because there are no remote desktop license servers available to provide a license. Please contact the server administrator.

    We are using Windows Server 2012 Standard installed in VMWare / Virtual machine and to access this we use vSphere client and Remote Desktop Connection / service was already enabled and was working fine with User PCs / laptops remote desktop into the server
    2012, until it gave an error message of: Remote session was disconnected because there are no remote desktop license servers available to provide a license.  Please contact the server administrator. whilst logging into the server. 
    We DON'T use Active Directory nor and we don't use domain and not looking to use it any-time soon. 
    I checked the RD Licensing Diagnoser and it says the grace period has expired and the licensing mode for the remote desktop session host server is not configured.  I have checked the Remote Desktop Gateway has been stopped and I tried to start it and it
    resumed to stop, here I assume its where the licensing part comes in to re-enabled this. 
    I have been trying to follow these articles online: http://ryanmangansitblog.com/2013/03/27/deploying-remote-desktop-gateway-rds-2012/ and http://www.concurrency.com/blog/rds8-add-a-licensing-server-2/#Install  the overview part that I cannot get into,
    because I think we have to be is AD DS for this which we don't.  Is there a way around this for non domain / just standalone set-up?  Is it a must / requirement we need to be in a domain in order for Remote Desktop Connection to work? 
    Also, we have a Windows Server 2012 RDS CALs - 10 (software and licence key), will the licence key work for the Windows 2012 Server Standard?  We do not want to install the other Server mentioned which comes with CAL / licence key as its time consuming
    to reinstall other programs.  I have installed  Server role service of Remote Desktop Licencing and automatically installed other associated services needed.  in the RD Licencing Manager, the Server had a red cross and I "Activate Server"
    where I followed: http://www.concurrency.com/blog/rds8-add-a-licensing-server-2/#Install in Install Licences section and I have used the licence key of CAL - 10 mentioned above; it stated I have successfully completed the install licences wizard and displayed:
    10 Windows Server 2012 - RDS Per User CAL installed, and in the RD Licensing Manager the server turned into a green tick and added the licence.  
    I then tested the Remote desktop connection from my PC and the same error message was there and checked the RD Licensing Diagnoser and the same error messages was there.  I haven't restart the services of Remote Gateway / the server itself; do I really
    need to reboot server?  
    Any advice / guidance would be very much appreciated and this is a urgent matter.  
    Thank you for your time.

    Hotfix Released here:
    http://support.microsoft.com/kb/2916846

  • RDS 2012 - Certificates

    Hi all,
    This is my setup :
    RDS 2012 R2
    Two connection brokers setup in HA:  FQDN = RDCB.Internaldomain.com
    Two Web Access servers for internal user setup with DSN Round Robin so I can have a basic HA: FQDN = InternalWA.internaldomain.com
    Two Gateway servers in HA:  FQDN:
     RemoteGW.InternalDomain.com
    Both Gateway server have RD Web Access installed and using DNS Round Robin to have a basic HA): FQDN 
    RemoteWA.ExternalDomain.com
    My company will not approve having a trusted wildcard certificate. So, in the “Edit Deployment Wizard”, I was thinking of deploying
    one public (and trusted) SAN certificate containing all the above FQDNs to all the Role Services (RD Connection Broker –Single Signon, RD Connection Broker -
     Publishing, RD Web Access and RD Gateway).
    Will this be ok or do I need to add other FQDNs to the certificate (for example the FQDN of all the Session Host servers)?
    Best regards,
    Jesmat.

    Hello,
    In your FQDN  did you forget to add a "." as : RDCB.Internaldomain.com
    and RemoteWA.ExternalDomain.com
    are 2 different domain names
    The SAN option i thiink will not be liable here . Except if you use self signed for your internal connection  ans
    the san for the external one.
    refer to :http://en.wikipedia.org/wiki/Wildcard_certificate
    But i cannot confirm that the san certificate will be allowed on the gateways.
    Hope it helps 
    Fred

  • RDS 2012 Deployment guide

    Hi,
    I'm looking for a RDS 2012 Deployment Guide or best practices document but not finding it.  Basically I'm looking for the equivalent of the document below but for Server 2012 R2 instead of 2008 R2
    <won't let me add link to body yet>
    We are planning a new RDS implementation and want to make sure we get the environment and resources right from the beginning.  Initially I'm mainly curious about the recommendations on how many servers are needed and which roles can be combined
    on single servers and which need to be broken out onto their own boxes.  For example is it best to have the RD Gateway and the RD Web Access roles on their own individual servers or should/can they be combined on to one box in the DMZ? 
    If separate; can one of them also double as the connection broker?  That sort of thing. 
    Any help is appreciated.  Thanks

    Hi Col,
    Have a look at the following articles:
    http://ryanmangansitblog.com/2013/09/27/rds-2012-deployment-and-configuration-guides/ 
    I would recommend that you look at splitting the roles on a large environment or use a layer 7 load balancer so you can scale up the number of Gateway/RDweb servers if your connections grow.
    I would advise against configuring the connection broker on a server which has a connection to the public interface (web and remote access via gateway). I would advise against exceeding 400 connections per RD Gateway server.
    a example configuration:
    Server 1 : connection broker and Licensing role
    Server 2 : Session host
    Server 3 : RDWeb and RD Gateway.
    This may help you with regards to capacity planning:
    http://ryanmangansitblog.com/2014/06/24/capacity-planning-for-a-rds-2012-pooled-2000-seat-vdi-collection/
    Ryan Mangan | Ryanmangansitblog.wordpress.com | Help keep the forums tidy, if this has helped please mark it as an answer

  • Certificate setup RDS 2012 R2

    Hi,
    I have set up an RDS 2012 R2 deployment for internal use. I plan to add a gateway server cluster for external access later (RDGW). That cluster will be placed in DMZ and use a public wildcard cert. It will connect external users to the farm. Internal or
    Direct Access (DA) users will use the Web Access servers to connect internally in the corp. LAN.
    For now, i have the following setup. Web Access role on 2 servers with DNS RR (RDWA). 2 clustered Connection Broker servers (RDCB), two Session Hosts (RDSH) and one licesning server. So a total of 7 servers (+ 2 GRGW servers in DMZ that are not set up
    yet).
    So, the issue is; I need to set up certificates. We have a CA in an AD top domain (our site is a sub.domain.com). We do not have access to that CA and need to order certs. from our corp. HQ. Ok, but what do i ask for? I need 3
    DER encoded binary X.509
    certs. That's the info i have. How can create a cert. request? See pictures below.
    This posting is provided "AS IS" with no warranties or guarantees and confers no rights

    Hi,
    Thank you for your posting in Windows Server Forum.
    Can you exactly let us know which certificate you want for your network (Self-signed or SSL)?
    As per my suggestion you can use wildcard or SAN certificate for your network which can be used for external network also. 
    If you want Self-signed certificate for internal use, you can create the certificate from Deployment properties of RDS page or IIS Manager as per below path.
    IIS Manager>Server Certificate>Create Self-Signed Certificate>Export the certificate on specified location then select the certificate in RDS installation process.
    But see that, the certificate is installed into computer’s “Personal” certificate store with its corresponding private key & it’s added under trusted root certificate authority.
    Please check below articles for detail.
    1. Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services
    2. Configuring RDS 2012 Certificates and SSO
    3. Minimum Certificate Requirements for Typical RDS implementation
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • 2 Separate RDS 2012 R2 Deployments in Same Domain ?

    We have a current RDS 2012 R2 deployment. We are changing hosting vendors and want to completely redo the entire deployment (rather than try to migrated the VMs). What is the best way to go about this?
    We do want to continue to use the GPO and user files will be migrated. How can we have the prod and dev RDS environments coexisting on the same domain? 
    Just to clarify, we do not want to use any of the existing infrastructure because it is all going to go away. Thank you!

    Hi,
    Thank you for posting in Windows Server Forum.
    I thinks that good way to start for new environment without any mixing up. Yes, everything can be setup under same domain. For common domain environment,
    You can buy one single wildcard certificate with domain name which can be used for all roles. As in domain joined environment, we can use to have them both RDS server use the same RD Gateway. For this we need to enter the same FQDN of working RDG into the Deployment
    properties of the second deployment.
    There are several other points which need to check, you can refer following article for depth understanding and configuration.
    1.Step by Step Windows 2012 R2 Remote Desktop Services – Part 2
    2. How To Work with RD Gateway in Windows Server 2012
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • RDS 2012 R2 - RemoteApp Disconnected

    Hi RDS 2012 R2 Experts,
    I would like some guidance here if possible
    My setup is a follow.
    1x 2012r2 with the following role, Broker, Web access, Gateway and License called RDS01
    2x 2012r2 Session Host called RSH01 an RSH02
    1x wildcard cert
    I would like to my users to be able to either internal and external to use the same link, remote.mydomain.com since my internal domain is mydomain.local
    What i have done so far.
    Created a DNS Zone called remote.mydomain.com and added the following records there.
    REMOTE, it points to web access server IP 192.168.1.31 ( same server for Gateway and Broker )
    2x RDSFarm, one record points to RSH01 and the other to RSH02, 192.168.1.32 and 33
    Gateway, the record points to 192.168.1.31 ( same servers as broker and web access)
    Broker, the record points to 192.168.1.31 ( same servers as web access and gateway)
    i have set the gateway manager the following
    Edited the deployment RD Gateway to remote.mydomain.com
    Installed the wildcert for all the roles, *.mydomain.com in all 4 roles
    created Manage Local computer groups and added both RSH01 and 02, RDSFarm record, remote record, gateway record and broker record
    linked the allowed resources with the policy and users ( also tried allow users to connect to any resources )
    configure the gateway in the RD Gateway farm
    Configured the IIS to
    auto redirect
    and the DefaultTSGAteway under Pages to remote.mydomain.com
    Also I used the Set-PublishName (http://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80) to change it to broker.mydomain.com
    Now, the issue I have is, when users either internally or externally try to launch a RemoteApp they get the error.
    RemoteApp Disconnected
    This computer cant connect to the remote computer.
    Try connecting again.
    To overcome this error I did the following:
    Set-PublishName to RDSFarm.mydomain.com ( it is using the round robin to get to the session host servers)
    There is two problem with this setup.
    I no longer can shadow the users under Connections in the broker ( it seems to be bypassed )
    I get certificate mismatch due the servers names
    What I would like to achieve is to fix both problems above.
    Thanks for any advice in advance.
    N0tl3_Bouya

    Hi,
    Thank you for posting in Windows Server Forum.
    Initially check that you have applied external used FQDN of server under Server name in RD Gateway Deployment properties and used Bypass RD Gateway for local address. 
    Please try to perform the steps 
    •  Create a new DNS zone, .COM to allow split-brain DNS (so that internal clients can resolve external names internally)
    •  Create a relevant DNS entry in the aforementioned zone to point to the RDS environment’s internal IP address
    •  Create a relevant DNS entry in external DNS to point to the firewall which is publishing RDS’s external IP address
    •  Use the following script to change the FQDN of the RDP files provided by RD Web Access / RemoteApp and Desktop connection feed 
    Change published FQDN for Server 2012 or 2012 R2 RDS Deployment
    http://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80
    In addition, for shadow related issue you can use the server in administrative mode use mstsc /shadow command and check the result. 
    Detailed walkthrough on Remote Control (Shadowing), reintroduced in Windows Server 2012 R2  
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • RDS 2012 R2 Separate Session Collection Behavior

    Hi everyone!  I should start by saying that I've found a number of threads which are semi-related to this topic, but they just don't seem to address my particular complaint.  I'm not sure if this is a bug, a configuration error on my part, or if
    it is expected behavior (which would be unfortunate for my intended use cases).
    The issue is that I need to provide two separate collections of RemoteApps, and I only want the collection appropriate to the logged-in user to be displayed in Web Access (or in the feed, for that matter).  One collection includes an expansive set of
    RemoteApps, and the other collection includes a limited subset of those published in the first.
    Now, I know that a SH can only belong to one session collection.  That makes sense, and in my case, I wouldn't want it any other way.  It offers better separation between the user environment intended for use by employees, and the user environment
    intended for use by non-employees, which is a bit more restrictive.  (Those are the actual purposes of the two collections described earlier.)  So far, so good.  Now, it seems to me like every other role beside the SH role should be able to
    do its job for all collections.  What other purpose could the concept of a "Collection" possibly serve, after all?  If I had to stand-up Connection Broker, Web Access, Gateway, and Session Host for every collection of RemoteApps, then there
    wouldn't need to exist any concept in RDS 2012 R2 called "Collections".  So, I figured that Connection Broker, Web Access, and Gateway could serve all collections, and Session Host is of course limited to serving one single collection.  And,
    I guess, that's largely the way it works, with one exception.
    My issue is that in Web Access, all RemoteApps from all published RemoteApp collections are presented to every user who has access to one collection OR the other, despite my best intentions of having provisioned each collection with seprate user group assignments
    using two separate AD groups.  I don't want to advertise all RemoteApps from all collections in the Web Access namespace!  To me, the presence of "User Group" configuration at both the Collection level and at the RemoteApp level implies
    that there is some user group filtering going on, but so far that's looking like a false assumption.  Why would the RemoteApp list in one collection bleed into the RemoteApp list in the second collection?  Why would I want the users of one collection
    to see the applications of the other, even when they're not going to be able to launch them anyway?
    Does anyone have anything to add to the equation?  Is there something I'm missing?  Thanks ahead of time.

    This is now resolved.  There is obviously some additional configuration necessary in some relatively odd places when you want your RemoteApp collections to work as advertised.  I hope this thread can help others in that regard.
    The relevant (error) event generated for each "populate list of RemoteApps for Web Access" process (refreshing the web access portal was my test case), when my IIS application pool is provisioned by the new AD account is Event ID 10, Source: RDWebAccess. 
    In the body, it says "[...] unable to access rdcb1.[local]" and suggests that the RD Web Access server needs to be added to the TS Web Access Computers security group on the connection broker.  However, that was obviously already the case.
    Although not 100% correct in its suggested resolution, this error was helpful, because it shows that the break is occurring when Web Access tries to populate RemoteApps, and is shows that the break is occurring en-route to the CB server.  So, I added
    the new service account (for the Web Access application pool identity) to the Administrators group on the server with the CB role, and all is now resolved.  I now have two separate collections, the list of each appearing for the appropriate user scopes,
    but not for both user scopes like before. 
    Obviously, adding an account as an administrator fixes a lot of access related things very easily, but it is probably not the least-privileged way of doing things.  To that end, I'd like to know the least privileged way, but can certainly live with
    this much improved functionality as-is.
    Thanks for all your help, Razwer.

  • RDS 2012 R2 RemoteApp Server Name Mismatch

    Hi All,
    I wonder if someone can scratch my head on this.
    Brand new RDS 2012 R2 deployment.
    RDS01 with Connection Broker and Session Host Roles installed
    RDS02 with Web Access and Gateway roles installed
    one ssl certificate with one domain remote.mycompany.com 
    the certificate have been imported to all the servers via the Edit Deployment
    the local domain is mycompany.local
    the problem that i am having is that when i launch RemoteApp after login in the remote.mycompany.com externally, i get Certificate mismatch, because it is contact the local name of the Session host server RDS01.
    What i tried so far.
    Used the Set-PublishName (http://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80) without success
    Try to configure RDS01 certificate via (http://ryanmangansitblog.wordpress.com/2013/03/10/configuring-rds-2012-certificates-and-sso/)
    Check Any resources ( http://social.technet.microsoft.com/Forums/en-US/d1b0ebe4-9e53-47ff-8c75-43fd91ff538a/windows-2012-rds-certificate-mismatch?forum=winserverTS)
    Has anybody out there could shade me some knowledge in how to rectify the mismatch name warning.
    Thanks
    Elton

    Hi -TP,
    Answering your queries.
    1_the Set-RDPublishedName was successful, restarted the servers, refreshed the RDWeb page externally, tried to connect unsuccessfully.
    2_I am using externally windows 8 and internally 7 fully updated
    3_it had the green successful message.
    After, set-rdpublishedname command, i get an erro when try to connecting saying, RemoteApp Disconnected.
    Error:
    Remote desktop cant connect to the computer "remote.mycompany.com"
    1)Your user account is not listed in the RD Gateway Permission ( not true, it was set for domain users and my test user is under that group)
    2)you might have specified the remote computer in netbios format or ip
    Do you reckon i am having this problem because the RDS01 with Connection Broker and Session Host Roles installed?
    Cheers
    Elton

  • RDS 2012 Certificates help

    Hi all,
    I am currently implementing a RDS 2012 infrastructure.
    1-2 RDS Host servers
    1 server which contains the gateway and web access role (sits in the DMZ network)
    1 licensing server
    So I have 4 RDS servers in total.
    I have a internal and a external domain so for example:
    test.com (external domain - public facing)
    internal.com (internal domain - lan users)
    1-2 RDS Host servers - INTERNAL
    1 Licensing server - INTERNAL
    1 Gateway and Web Acess server - PUBLIC
    Would purchasing a public san certificate work for my enviroment and applying to all four servers?
    If not, what would work?
    Thanks

    Hi,
    Thank you for posting in Windows Server Forum.
    You can use single SAN certificate to achieve your goal as it can serve for all server. Apart there is some basic requirement to have RDS certificate.
    Basic requirements for Remote Desktop certificates:
    1. The certificate is installed into computer’s “Personal” certificate store. 
    2. The certificate has a corresponding private key. 
    3. The "Enhanced Key Usage" extension has a value of either "Server Authentication" or "Remote Desktop Authentication" (1.3.6.1.4.1.311.54.1.2). Certificates with no "Enhanced Key Usage" extension can be used as well. 
    More information.
    Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services
    http://blogs.technet.com/b/askperf/archive/2014/01/24/certificate-requirements-for-windows-2008-r2-and-windows-2012-remote-desktop-services.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • RDS 2012 R2 - RemoteApp - Certificate Mismatch

    Hi!
    We have a newly built RDS 2012 R2 setup.
    It consists of the following:
    1 x Server with the Gateway and the Web Access role
    2 x Servers running a Connection Broker HA cluster
    3 x Servers running as Session Hosts
    The internal domain name is example.local
    We have purchased a wildcard certificate for the entire setup. (called *.example.com)
    An external DNS record - RDS.example.com - has been created and it NAT to the Gateway and Web Access server.
    We have used the script from
    https://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80 to publish the FQDN. The name we have publised is Broker.example.com. We have created a split-brain DNS internally so that the clients can resolve external names internally.
    Whenever we try to launch a RemoteApp externally we get the dreaded "Name mismatch" (and it takes about 30 seconds before we get the prompt):
    Any ideas how to solve this issue?

    Hi TP.
    Thank you for your advice.
    I've updated the Windows 7 client to RDP 8.1 and it did the trick! Thank you.
    But we have several external users - and we don't have any chance of controlling if they are running RDP 8.1. I tried to import the wildcard certificate to all RDSH servers
    - using the script in this link: https://social.technet.microsoft.com/Forums/windowsserver/en-US/475fb55f-e394-45d9-a6bd-a37e2a5fe86c/rds-2012-session-host-certificate-assignment?forum=winserverTS
    However - that is when I see the "Name mismatch" warning when launching a RemoteApp (as mentioned in my original post). I suppose this is because the certificate is valid
    only for *.example.com - and not for *.example.local?
    Is there any solution to this?

Maybe you are looking for

  • I want to install and extension globally

    I am an it admin and want to install an extension globally, but placing the .xpi file in C:\Program Files (x86)\Mozilla Firefox\browser\extensions\ or C:\Program Files (x86)\Mozilla Firefox\plugins and restarting the browser does not prompt to instal

  • Please help!!! This expression must have a constant value

    I try to work with cfc and cfinvoke and not sure why I got this error. Searched in google for answer but still don't get any. Can anyone help please...not sure where I had it wrong...I thought my codes should work (?) When a form is submitted I have

  • Has anyone solved the garbled printing issue yet?

    We continue to have garbled printing problems, on two different HP printers, yet it doesn't seem anyone at HP cares to find the cause of the problem.  I've told them that I'll be donating the HP printers and buying something else.  Any suggestions?

  • Long list of warnings in Application event log

    I'm using windows XP SP2, Nokia PC-Suite 6.84.10.4 and a Nokia 6822 phone. I have full administration rights of the machine. Every time I start my laptop up I get about 62 or 63 application log entries all saying the following. . . Detection of produ

  • Paragraph Format / Character Format for Variable address in SAPSCRIPT

    Dear All,    I am trying to print variable address for ship-to-party. But the address is variable address for different vendors. The contents like /:  ADDRESS PARAGRAPH AS /:  TITLE    &LFA1-ANRED& /:  NAME     &LFA1-NAME1&, &LFA1-NAME2&, &LFA1-NAME3