I don't want the cert added to trusted roots!!!


hi,

been fighting server 2012 certs set in rd.  (overall i'm finding things counter-intuitive on server os.)

i have internal public key infrastructure set off-line root ca , issuing enterprise ca.  clients trust root cert.

i use certificates (local computer) request 2 certs - 1 gateway , web, , other broker roles.  rd on same server right now.  (i didn't want use same cert on both because gateway outfacing , don't want include machine's internal dns name in cert - gateway's public dns.)  i'm using "web server" template both.

i import them issuing ca (it doesn't issue automatically) computer's personal store , export them files in order able them certs page under "deployment properties" in server manager.  (i find little silly can't reference them computer's cert store can in separate rd gateway manager application unfortunately has no analog can find other rd roles.)

in "select existing certificate" dialog, "choose different certificate" , provide path , password.

however, cannot click ok unless elect "allow certificate added trusted root certification authorities certificate store on destination computers."

i'm not sure means "destination computers," know don't want cert in trusted root certification authorities of given computer.  see no reason it, trusted anyway on basis of root cert chains from.  rather not have needless certs floating around in trusted roots, both because it's clutter , because i'm not sure if clients revocation checks on trusted roots - think remember reading somewhere don't.

so, what's going on, why have accept unwelcome trusted root, , there way can avoid it?

thank advice or insight.

kevin

hi kevin,

destination computers = servers role service have selected.  example, if have selected rd web access destination computers servers in deployment have rd web access role service installed on them.

it doesn't add certificate trusted root certificate authorities store on target server(s).  add certificate target's local computer\personal certificate store add intermediate certs in chain intermediate certification authorities store , root cert trusted root certificate authorities store.

for self-signed certificates add local computer\personal store on target server(s).

-tp



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file