<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx</link><description>Why create Kerberos Identity for farms? In Windows 2008, it is possible to provide server authentication by issuing a Secure Sockets Layer (SSL) certificate to the Remote Desktop Session Host (Terminal Server) farm and deploying it to each server in the</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#10187577</link><pubDate>Mon, 18 Jul 2011 18:03:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10187577</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Lee,&lt;/p&gt;
&lt;p&gt;I&amp;#39;d first check that the target name used by your client is the same you created the Kerberos identity for. For example, if you created Kerberos identity for MyFarm.fabricam.com, then the client should use the same name exactly to connect to the farm.&lt;/p&gt;
&lt;p&gt;Thx,&lt;/p&gt;
&lt;p&gt;Sergey.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10187577" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#10186934</link><pubDate>Fri, 15 Jul 2011 15:24:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10186934</guid><dc:creator>LeeDnc</dc:creator><description>&lt;p&gt;I am trying to set up Kerberos in my lab. The server looks fine but I get an error on the client saying the &amp;quot;The remote computer cannot be authenticated due to problems with its security certificate.&amp;quot; The only solution I can find ( &lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/ee891358(WS.10).aspx"&gt;technet.microsoft.com/.../ee891358(WS.10).aspx&lt;/a&gt; ) says to install a cert.&lt;/p&gt;
&lt;p&gt;What have I done wrong?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10186934" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#10028041</link><pubDate>Mon, 21 Jun 2010 17:39:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10028041</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Andrey,&lt;/p&gt;
&lt;p&gt;It might happen that your Connection Broker failed to propagate the farm credential to the server. Look for error messages in the Connection Broker event log.&lt;/p&gt;
&lt;p&gt;Thx,&lt;/p&gt;
&lt;p&gt;Sergey.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10028041" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#10027862</link><pubDate>Mon, 21 Jun 2010 11:53:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10027862</guid><dc:creator>Andrey</dc:creator><description>&lt;p&gt;I enabled TS farm identity and had the following error:&lt;/p&gt;
&lt;p&gt;&amp;quot;The coonection cannot be completed because the remote computer that was reached is not the one you specified. This could be caused by an outdated entry in the DNS cache. Try using the IP address of the computer instead of the name.&amp;quot;&lt;/p&gt;
&lt;p&gt;I use farm name in the RDP file.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10027862" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#9988275</link><pubDate>Wed, 31 Mar 2010 17:54:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9988275</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;To Mauro:&lt;/p&gt;
&lt;p&gt;The account is created automatically when you do Set-Item...&lt;/p&gt;
&lt;p&gt;You do not need to configure anything else for authentication to work.&lt;/p&gt;
&lt;p&gt;To Sam:&lt;/p&gt;
&lt;p&gt;Having Kerberos identity for the farm does not eliminate the need to sign your RDP files.&lt;/p&gt;
&lt;p&gt;Thx,&lt;/p&gt;
&lt;p&gt;Sergey.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9988275" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#9988142</link><pubDate>Wed, 31 Mar 2010 14:12:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9988142</guid><dc:creator>Sam</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I've got the same question as Mauro with the addition of this:&lt;/p&gt;
&lt;p&gt;Does this replace the requirement to digitally sign applications with a certificate?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9988142" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#9981815</link><pubDate>Fri, 19 Mar 2010 13:05:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9981815</guid><dc:creator>Mauro</dc:creator><description>&lt;p&gt;Hi all,&lt;/p&gt;
&lt;p&gt;I have some questions:&lt;/p&gt;
&lt;p&gt;- Do I have to use an existing specific user account (anyone is suitable?) or is the account created when I type Set-Item...?&lt;/p&gt;
&lt;p&gt;- Do I have to configure some other things on the RD Web Access / RD Connection Broker / RD Session Host for the authentication to work?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9981815" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#9941685</link><pubDate>Mon, 28 Dec 2009 19:49:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9941685</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Q: Should &amp;quot;allow connections only from computers running Remote Desktop with Network Level Authentication&amp;quot; be selected?&lt;/p&gt;
&lt;p&gt;A: You can select it, or you can select &amp;quot;(less secure)&amp;quot;. Both options will work. If you are not using legacy RDP clients (versions 5.x and below), I'd recommend the &amp;quot;(more secure)&amp;quot; option.&lt;/p&gt;
&lt;p&gt;Q: Which certificate should be selected, the default self-signed or the cert that may have been imported?&lt;/p&gt;
&lt;p&gt;A: A self-signed certificate should be good enough for the intranet deployment.&lt;/p&gt;
&lt;p&gt;Q: What about the Security layer and encryption level?&lt;/p&gt;
&lt;p&gt;A: Security layer set to &amp;quot;Negotiate&amp;quot; or &amp;quot;TLS&amp;quot; will work. Set encryption level to either &amp;quot;Client compatible&amp;quot; or &amp;quot;High&amp;quot;.&lt;/p&gt;
&lt;p&gt;Thx,&lt;/p&gt;
&lt;p&gt;Sergey.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9941685" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#9937387</link><pubDate>Wed, 16 Dec 2009 00:04:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9937387</guid><dc:creator>Mike</dc:creator><description>&lt;p&gt;After making the above change, what should the settings be on RDP-Tcp Properties under the general tab? &amp;nbsp;Should &amp;quot;allow connections only from computers running Remote Desktop with Network Level Authentication&amp;quot; be selected? &amp;nbsp;Which certificate should be selected, the default self-signed or the cert that may have been imported? &amp;nbsp;What about the Security layer and encryption level?&lt;/p&gt;
&lt;p&gt;Do RemoteApps still need to be signed with a certificate?&lt;/p&gt;
&lt;p&gt;I cannot information about this feature anywhere else. &amp;nbsp;It would be nice if there was some documentation outlining how this fits into an RDS deployment and how it affects the other settings.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9937387" width="1" height="1"&gt;</description></item><item><title>re: Creating Kerberos Identity for RD Session Host Farms Part I: using the Remote Desktop Services provider for Windows PowerShell</title><link>http://blogs.msdn.com/b/rds/archive/2009/05/20/creating-kerberos-identity-for-rd-session-host-farms-part-i-using-the-remote-desktop-services-provider-for-windows-powershell.aspx#9905722</link><pubDate>Sat, 10 Oct 2009 10:31:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9905722</guid><dc:creator>ecns.smith01@gmail.com</dc:creator><description>&lt;p&gt;There are many hosting companies. Search for the best hosting company on the internet. You will come across a lot of hosting companies. Choose the company which provides the best service on your budget. They offer their service in different packages. Choose a package to suit your needs and sign up for an account. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9905722" width="1" height="1"&gt;</description></item></channel></rss>