Server 2012R2 -- RDS Farm with XP and Windows Vista Clients

Hi There,
My team has been having some fun in getting our Server 2012R2 farm operational, annoyingly MS documentation is severely lacking on how to correctly configure a 2012R2 Farm correctly.
We have an RDG1-TCC server, which is the RDGateway, RDConnection Broker and RDWeb Server. We have two session host servers RDS1-TCC and RDS2-TCC.
It took us some time and much online research to figure out exactly how we needed to configure the RDS server as a lot of information online for 2012R2 was apparently incorrect(was based on 2008R2 practices). We started off with using a DNS Round Robin for
the RDS Session hosts servers and after a number of certificate issues, we later found this was incorrect. We're now using RDWeb exclusively, which appears to be the correct way to have the Connection Broker working?
We've ran into a number of issues with certificates too, we have an external certificate for remote.domain.com. Installing this on all 4 options in the certificate manager has made internally work correctly via RDWeb, however externally we are getting a
certificate mismatch as it's trying to connected to RDG1-TCC with a certificate for remote.domain.com. I'm pretty sure I can resolve this with a replacement remote.domain.com certificate that includes a SAN for *.domain.internal. Testing with a self signed
certificate seemed to resolve this issue.
Now providing i've configured everything the correct way, we have an issue where RDWEb RDP files do not work internally or externally for XP, Vista or Windows 7 (With RDP7.1). Windows 8/8.1 and Windows 7 with RDP 8/8.1 updates work perfectly fine. Unfortunately
this new client has a few XP machines that they are not willing to update just yet.
Is there a known fix/workaround to get these older clients working correctly?
Sorry for the extremely long post, but I'm sick of banging my head against the wall trying to get something that we assumed would have been fairly simple to get up and running.
Cheers,
Ben

Thanks for the assistance so fat, now I have all clients connecting, I need to tackle the certificate issues.
The UC SAN certificate is going to cost much more than the current certificate, currently that idea is on the back burner as the client does not wish to pay a few hundred extra.
To quickly sum things up:
AD DNS(internal DNS) override in place for remote.domain.com.au pointing it to the internal IP of the gateway/connection broker/RDWeb server.
Connecting Internally its working perfectly fine under all circumstances (I'm guessing this is because of Kerberos Auth)
When users connect externally via RDWeb they get a certificate missmatch as the cert is for remote.domain.com.au and the server is RDG1-TCC.domain.com.net
When users connect externally via MSTSC using the Gateway option, they get a certificate missmatch as per the above, however they also receive a second "certificate is not trusted" error for whatever RDS server they hit.
I have tried the below previously and they broke other things:
"Change published FQDN for Server 2012 or 2012 R2 RDS Deployment."
This resolved the external certificate issue. However then internal connections stopped working. When connecting via RDWeb, you would get asked for credentials instantly and no matter what you entered, it just asked for credentials again.
There did not seem to be ANY event logs for this connection.
"Changing RDP-Tcp listener on RDSH to use external certificate."
I can't recall the exact error we had when we did this, but I know we had to roll back the change. I have a feeling we then started getting certificate missmatch errors on the Session Hosts.
I'm half thinking that when the farm is free(Currently being used for application UAT), I'm going to try and reconfigure the RDP-Tcp listener on the RDSH servers again and see if that resolves one or more of our issues.
Do you have any suggestions on how I can use the correct published FQDN name without breaking internal access? Or any other ideas on getting this entire thing working both internally and externally?
Also, Dharmesh, I've tried clearing out the certificate cache as suggested, but to no avail.

Similar Messages

  • Server 2012R2- RDS Farm Certificate Miss-Match on Session Hosts

    Hi Guys,
    I've another RDS2012R2 issue. Internal and external domains do not match. External: domain.com.au; Internal: domain.com.net.
    I'm getting certificate miss-match errors when connecting to the Farm/RemoteApps.
    I have performed the follow fixes:
    Change published FQDN for Server 2012 or 2012 R2 RDS Deployment (http://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80). This resolved the original issue where I was getting a certificate miss-match error externally
    for the FQDN of the server.
    Updated the RDP-Tcp certificate used on the Session Host Servers. This was to resolve an issue where using mstsc to RDP to the farm externally(via gateway) would give a Certificate is not trusted error on the RDSH side.
    Now whenever RDWeb is used to launch a RemoteApp or the farm, I get a certificate miss match error as the RDSH server is called RDS1-TCC.domain.com.net and the certificate is for remote.domain.com.au.
    I rolled back the last change so that RemoteApps and the Farm would work successfully internally without certificate issues. How do I go about resolving the certificate errors?
    For extra background details see my orignal thread, It was marked as answered when only 1 out of 2 issues was resolved. http://social.technet.microsoft.com/Forums/windowsserver/en-US/b664ddaf-6c11-49e2-8a69-0df3b8ef13a1/server-2012r2-rds-farm-with-xp-and-windows-vista-clients?forum=winserverTS
    Cheers,
    Ben

    Hi Ben,
    Thank you for posting in Windows Server Forum.
    In your case, I can suggest you to check that the certificate must match the FQDN of the server. If you are creating SSL certificate then it must be signed by trusted authority and also the certificate must be stored under “local computer/personal store“.
    Also you can buy the certificate from 3rd party which is wild card certificate and only 1 certificate can be used for your network. Please check below links for more information regarding certificate issue.
    1. Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services
    2. Configuring RDS 2012 Certificates and SSO
    3. Windows 2012 RDS Certificate mismatch
    Hope it helps!
    Thanks,
    Dharmesh

  • Is Verizon going to acknowlege the problems with FIOS and Windows Vista

    For months now, I have been reading the numerous problems Fios internet customers are having with Fios internet/Actiontech Router and Windows Vista and there has been no acknowledgement by Verizon of this current major issue.
    I have also experienced the exact same issue for months now since I switched to Verizon FIOS internet. Previously I had Comcast HSI using my Windows Vista laptop.  I had their service for over a year and I NEVER has a problem with the Windows Vista globe icon disappearing and loosing internet connection. The Globe always stayed on and never went away and I never lost connection when I had Comcast
    I had Verizon FIOS installed last September with my Windows Vista computer and my wireless internet connection started to drop from day 1 and it has been a daily occurrence for over 5 months now.  It has gotten so bad, I have had to hardwire my laptop to to be able to use the internet uninterrupted.
    This is what daily scenario is:
    When I turn on my laptop(with Windows Vista, I can initially get full internet access(with the globe on and it says "Local and internet). After about 10 minutes or less, the globe switches to "local only" and I can still get  internet access.  After another 5 or so minutes, a large X covers the globe and I lose internet connection entirely. The actiontech router wireless signal is no longer listed as one of the wireless networks.  The only way for me to regain internet access is either to restart my laptop or reboot the actiontech router.
    Numeorus posts here, over by DSL forums(Broadband Reports),Microsoft's website and a few othere websites detail this issue.
    I am extremely shocked and surprised that Verizon has not tried to fix this issue by working with both the makers of the Actiontech Router as well as Microsoft to find out what the problem is and how to fix it.
    I would just like to reiterate I strongly believe this is primarily a FIOS internet issue since I previously had Comcast HSI for over a year with the same Windows Vista laptop and I NEVER had that problem. Also,  I can connect to my neighbors wireless connection(she uses Comcast HSI) and when I do, the globe stay on all the time on my computer and the internet does not lose connection.
    I know that there are a couple of Verizon employees here. Please tell the higher ups who handle FIOS internet that this is a major issue that needs to be resolved as soon as possible.
    P.S: Please don't tell me to go by my own router because then, I will have to deal with the issues of setting it up to work with Fios TV and the related VOD, widgets, remote DVR compatability issues to deal with. I don't think I can deal with the additional headaches. 

    FIOS is short for fiber optics.  fiber optics is different technology than DSL.   
    With that said, if you search the Microsoft databases for vista issues with fiber optics, (CURRENTLY THERE IS ONLY ONE PROVIDER OF FIBER TO THE HOUSE, that being Verizon, so yes you can also search Vista issues with verizon and\or fios) and you will find that Microsoft already acknowledges this issue with their software.  AND they offer you a fix.
    cjacobs001

  • Is Magic Mouse compatible with PC and Windows Vista

    Hello to everyone, I'm a new member of this forum, I hope someone will help me, please.
    I'm taking a look at the latest beautiful Apple's product and I felt in love with Magic Mouse, I'd like to have it for ma PC (not a Mac) with OS Vista.
    Is there anyboby who knows if this mouse is compatible with a Pc and Windows Vista OS?
    Actually I don't have bluetooth thecnology on my pc but if Magic Mouse were compatible I'd buy an usb adaptor.
    Thanks to everyone will help e!

    I asked a similar question a few hours back and no answers yet. I think nobody knows since nobody has had the chance to test them. If previous releases are any indication, you'll probably get basic functionality because it is bluetooth, but for the advanced features or setting options you'll have to wait for a Windows driver, which can sometimes take a few months or more.
    My thread: http://discussions.apple.com/thread.jspa?threadID=2205313

  • Network problems with TC and windows vista

    When I try to transfer data from my laptop using Windows vista to the TC, I get an network error message after a few seconds saying the computer is not connected to the network. I have no problems transferring small files (that take less than a few seconds to transfer) and the external router, my laptop and the TC are located close to each other. I tried almost everything but i don't know what the problem is.
    Any suggestions?

    Hello Bastiaandp. Welcome to the Apple Discussions!
    There is quite a bit of dialogue going around the Internet about Windows Vista & Windows 7 when it comes to file sharing with either the Apple AirPorts or Time Capsules. Most of this dialogue seems to be revolving around the version of SMB used by the newer Microsoft OSs and that used by these routers for files sharing.
    A number of suggested solutions have been proposed, but none at this time, have provided a "permanent" solution. I too have experienced this same issue and have tried a number of these solutions. What finally worked for me was to make sure that: 1) The Workgroup name used on my Win 7 computer exactly matched the Workgroup name setting on the Disks > File Sharing tab within the AirPort Utility for my base station, & 2) That this name did NOT include any spaces. In my case, I used WORKGROUP for both settings.
    Since doing so over six months ago, I have had no problems copying/moving files between my PC and the AirPort, regardless of their size.

  • Problems with iTunes and Windows Vista

    I just got a new dell computer that came with Windows Vista. I'm new to Vista, and just downloaded iTunes. I was able to add my music and it will play, but I can't edit track information. I downloaded iTunes from the administrator account, so I don't know what the problem is or how to fix it. Please help!!

    For windows vista, like someone suggested, it may change your permission for editing a file and appear grey screen. As such, the following step might solve this problem.
    Go to "Computer", go to your portable hard drive, right click and go to "Properties". Select "Security" Under the "group and user names" choose your user name. To change the permission, choose "Edit" Under permission column, choose "Full Control". After this you may able to edit song information in your itunes.

  • Burning issues with itunes and Windows Vista Ultimate

    I recently purchased a new computer with Windows Vista Ultimate 64 bit version. Since loading itunes on my new computer I can not burn a CD. The message that I receive says that there is no burner available. I know the burner works because I have burned music out of different software programs. I have loaded and reloaded Nero 7 but I am finding that is not the problem. Itunes does not recognize any type of CD burner on my computer. Any thoughts?
    Thanks

    paul's onto it.
    if you run your DVD/CD diagnostics (in itunes "help > DVD/CD diagnostics", select DVD/CD diagnostics) and you see a 2380 error showing up down near the bottom of the diagnostics (you may need to scroll down a bit), try reinstalling the 64-bit version of the GEAR drivers iTunes uses for importing and burning.
    here's a link through to the GEAR drivers. note that there are two different versions of the 64-bit drivers. be sure to get the one that matches your hardware:
    GEAR drivers

  • Burning cds with itunes and Windows Vista

    It seems like my problems with itunes are never ending on my HP laptop with Windows Vista. Originally, itunes screwed up my disc drive, but then I downloaded the 64 bit version of it and that turned out ok. However, whenever I started itunes it says it wasn't downloaded properly and I won't be able to import or burn cds. I've downloaded it before multiple times to see if that message would go away when I started it up, but it didn't. That was fine for a while because I never burn cds but today I wanted to and it wouldn't work. It would say Disc Recording not found. So, I thought I should upgrade to the new itunes 8.1 but I was afraid to because it might screw up the disc drive again. And of course, it did. I even downloaded the 64 bit version. So I guess my question is, how can I install the 64 bit version without that error message and be able to burn cds?

    paul's onto it.
    if you run your DVD/CD diagnostics (in itunes "help > DVD/CD diagnostics", select DVD/CD diagnostics) and you see a 2380 error showing up down near the bottom of the diagnostics (you may need to scroll down a bit), try reinstalling the 64-bit version of the GEAR drivers iTunes uses for importing and burning.
    here's a link through to the GEAR drivers. note that there are two different versions of the 64-bit drivers. be sure to get the one that matches your hardware:
    GEAR drivers

  • External Monitor with Bootcamp (and Windows Vista Business)

    It looks like this has been discussed quite a bit already, but as a computer neophyte I've had a hard time deciphering an answer that applies to my unique circumstance. So apologies if some of you've already been over this.
    Anyway, here's my question/problem:
    My second monitor (Gateway HD2250) doesn't work when I'm using Bootcamp (Windows Vista Business). I'm running a VGA cord from the Gateway monitor to a VGA adapter that's plugged in to the back of my Mac. My computer's a late '06 iMac w/ Mac OS X 10.5.5. BTW, my virtual Windows does seem to register the second monitor; it's just that nothing shows up on the Gateway screen.
    Ideas for help? Thanks everyone!!

    I managed to get an upgrade version of XP to run by using the internal DVD drive for the main all disc and an external DVD drive for my qualifying disc. Has to be that way round because the Apple keyboard ceases to function for a while and the required USB windows keyboard dosen't have an eject button. The whole business was very painful however, trying to get the installer restarts to select the correct drive each time.

  • Security issues with applets and windows Vista when printing to file

    Hi, everyone
    I am currently developing an application that prints out the result of some calculations.
    from a Javascript file, the output finally ends up in a java applet that should print the file in a special printer.
    For debugging purposes I have created a File printer that creates a file from the output comming to the printer; this way I can debug what commands the printer is receiving.
    This worked well on Windows Xp; Vista always asks for permissions for the applet, and altough I guarantee these permissions, printer is not allowed to create the output file and reports an error writing
    after a little research, I have found that java applets have all permissions when certificated as trusted applications; all but file creating permissions
    anyone has any idea of how could I fix this problem?
    Thanks in advance

    HI,
    Have you actually signed your applet? If the signers certificate is the trusted key store for Java it should treat your applet as trusted. You can use a self signed certificate for testing as long as the cert is in the trusted key store.
    Some links that might help:
    [http://java.sun.com/j2se/1.4.2/docs/tooldocs/windows/keytool.html]
    [http://java.sun.com/j2se/1.4.2/docs/guide/plugin/developer_guide/rsa_signing.html]
    Cheers,
    Shane

  • Trouble with iTunes and Windows Vista

    Hello,
    I have a new Win Vista system and need to move over all my old music to existing IPOD. I installed the latest version of itunes, and the Windoes patch (can't recall the number). I been able to successfully install itunes and port over my music. However when I attach the iPod and sync it I get the following errors: Attempting to copy to disk "name of iPod" failed. an unknown error occured (-124), and then "The iPod "name of Ipod" can't be synced. The required file cant be found, and "the iPod "name of iPod" can't be synched. The required folder can't be found.
    The odd thing is that it appeard as if it was synching up songs accorning to the status bar across the top.
    Any help please....
    Thanks,
    Mark

    Hi,
    got it fixed! My Son had both files on his Win7 iTunes installation. Never mind he had no issues whith ths iTunes and iPhone Sync. So I checked my other Win XP PC, where I don't have this problem syncing my ipad, and surprise. Both files do NOT show up on this PC. So I renamed the iTunesPhotoProcessor.exe I found under c:\program file\iTunes and synced again my iPhone and it went through without any error. So the problem might be and unremoved iTunesPhotoProcessor.exe or the missing iTunesPhotoProcessor.dll under the iTunes install root folder and this even if I had checked that the folder was completely removed during iTunes unistall.
    Please try yourselve and just rename the iTunesPhotoProcessor.exe to iTunesPhotoProcessor.exe_ under c:\program file\iTunes or get a copy of the missing iTunesPhotoProcessor.dll and cp to c:\program file\iTunes.

  • Is there a fix for the incompatibility between itunes and Windows Vista?

    I'm having a problem with itunes and Windows Vista. When I download itunes it disables my dvd drive. I have found a fix for that by deleting some registry items, but when I do that itunes is disabled. Does anyone know of a solution to this problem?

    Hey Don,
    What exactly happens after you install iTunes? Do you see an error message?
    This article describes device filter issues that can be caused by application conflicts:
    http://docs.info.apple.com/article.html?artnum=305422
    Jason

  • Ipod nano first generation and windows vista

    I finally got everything to work right with Itunes and Windows Vista except one minor problem.
    On my ipod, the blue "dot" does not show up when a podcast is new, so in a long lists of podcasts, I can't tell which ones I already listened to.
    Is there a way to fix this?
    Thank you, Debra

    I have a new ipod nano and can not download iTunes to Winnows Vista.
    Need all the help that i can get. Thanks,
    Capt g

  • Project Server 2010 compatibility with IE11 and Windows 8.1

    Hi All!
    Maybe a silly question since compatibility is always asked about older versions, but here is my question:
    Is Project Server 2010 compatible with IE11 and Windows 8.1?
    I personnaly tested with IE11 and it seems to be ok. All views and pages can be opened with IE11.
    But what about windows 8.1? 
    Has Microsoft done any communication about this?
    Thanks in advance for your helps.
    Guillaume.
    Guillaume Rouyre - MBA, MCP, MCTS

    I am seeing a minor issue with the timesheet grid after users are upgraded from IE8 to IE11.
    We are using Project Server 2010 with SP1 and Oct 2013 CU.
    When some users (using IE11) switches between filters or views in the Timesheet page, the grid shrinks making to content un readable.  The only way to get it back is to refresh the page. After a refresh, the grid returns to normal size, but the pane
    divider is too far to the left and always must be dragged to the right in order to see the task names in the left grid. 

  • SharePoint Multi-Server Farm with LB and SQL Cluster.

    Helllo,
    We are setting up a Multi Server SharePoint 2013 Farm with a Load-Balancer. 
    We are also using SQL Server 2012, Two Node Cluster. 
    We have SQL Server Instance Running as a Service. Also I managed to install PowerPivot for SharePoint as a Instance. 
    Looking at various article's I have question if this Cluster Setup supported in SharePoint 2013. 
    Can the SharePoint Farm use this PowerPivot Instance as a failover service? 
    Or do I have to install Analysis services separately on Both SQL Nodes? 
    If so how do I configure Excel Services on SharePoint? 
    Thank you
    Sham

    PowerPivot is installed on the SharePoint server and is a scale-out service (you just install it on multiple SharePoint servers and make sure the Service Instance is started in SharePoint). Same with Excel Calc Services (but for this one you don't have
    to install anything, just start it).
    Trevor Seward
    Follow or contact me at...
    &nbsp&nbsp
    This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

Maybe you are looking for

  • ERROR DURING  MIRO FOR IMPORT P.O.

    Dear All ,                       i m doing MIRO for import P.O , here i m doing MIRO for CVD (in USD)  only , but as i m about to post the I.V an error arise as -->"Tax code V0 country IN does not exist in procedure TAXINN Message no. FF713 But in FT

  • Focusing a field/column in the new row of adf table

    Hi all,      I am using JDeveloper 11.1.2.4.0. and UI-Shell Template in Main application and sub applications are added to this master application as ADF library jar files. Application is working fine. I am trying to focus to make focus on a column i

  • How to add row in a JTable at runtime.

    Hi, How to add a row in JTable at runtime? I am using my own TableModel object extended from AbstractTableModel. Thanks in advance.

  • Reflective access-list in a WS-C3560G-24TS

    I have a reflective access-list in a switch doesn't seem to work. What I want is allow our campus traffic (141.225.0.0/16) to flow freely, and block outside traffic come in except for certain users. Allow inside network (141.225.216.0/24) to go outsi

  • White Border upper left

    Oh, I know this is probably a rookie error, but...  My coding knowledge is minimal and I'm trying create a video portfolio for a friend.  I'm starting in Fireworks and dropping into Dreamweaver.  I've read through endless information and not quite fi