<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx</link><description>Background Information Windows Vista Credential Delegation policy does not allow a Vista RDP client to send saved credentials to a TS server when the TS server is not authenticated. By default Vista RDP clients use the Kerberos protocol for server authentication.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Jason Conger Blog  &amp;raquo; Blog Archive   &amp;raquo; Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#4151676</link><pubDate>Tue, 31 Jul 2007 21:52:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4151676</guid><dc:creator>Jason Conger Blog  » Blog Archive   » Problems using saved credentials with Vista RDP clients and above</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blogs.msterminalservices.org/conger/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above/"&gt;http://blogs.msterminalservices.org/conger/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#4183669</link><pubDate>Thu, 02 Aug 2007 10:02:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4183669</guid><dc:creator>Olivier Blaise</dc:creator><description>&lt;p&gt;You speak about kerberos for server authentication with saved credentials. &lt;/p&gt;
&lt;p&gt;But does the RDP client support plain kerberos authentication for authenticating the server to the RDP client but also for authenticating the user to the TS ?&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#4209577</link><pubDate>Fri, 03 Aug 2007 21:06:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4209577</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Yes, RDP client supports Kerberos user authentication.&lt;/p&gt;
&lt;p&gt;However, it never uses plain Kerberos protocol. It uses CredSSP instead: &lt;a rel="nofollow" target="_new" href="http://msdn2.microsoft.com/en-us/library/bb204772.aspx"&gt;http://msdn2.microsoft.com/en-us/library/bb204772.aspx&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#4530858</link><pubDate>Thu, 23 Aug 2007 23:36:15 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4530858</guid><dc:creator>Cedric Briscoe</dc:creator><description>&lt;p&gt;I currently use a Certificate for the TS Gateway. But always wondered what to do then teh Session Broker &amp;quot;Farm&amp;quot; serves up TS1 or TS2.&lt;/p&gt;
&lt;p&gt;In addition to the FARM I've pretty much added many computers to the TS RAP. Does each machine need to have it's own Certificate or should they all have a common Certificate?&lt;/p&gt;
&lt;p&gt;If I set up AutoEnrollment on an Enterprise CA (2008) for all domain joined computers and I am remotely connecting to these domain joined computers, should I having the Enterprise Root Certificate installed on my ..... I think I'm answering my own question... that might not be good; what about others logining in....&lt;/p&gt;
&lt;p&gt;How about this: How can I access ALL the domain joined computers using a Cert. (some type of a common Cert) and still allow individuals to access a specific servers by issuing a Cert. for just that Server/Machine?&lt;/p&gt;
&lt;p&gt;I'm still getting aquainted with rolling out a CA, in general.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Cedric Briscoe&lt;/p&gt;
&lt;p&gt;Treetop Publishing, Inc.&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#4546243</link><pubDate>Fri, 24 Aug 2007 21:12:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4546243</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;As a general rule sertificate's subject name must match the name used to connect to this server. So, certificates on computers joined to a farm should have the farm name, while certificates for stand-alone TS servers should have computer name.&lt;/p&gt;
&lt;p&gt;You can use a common certificate for a farm, but you need a separate cert for each stand-alone server.&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#4754424</link><pubDate>Wed, 05 Sep 2007 07:02:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4754424</guid><dc:creator>北京翻译公司</dc:creator><description>&lt;p&gt;Vista will be the biggest failure in Microsoft's history.&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#6457034</link><pubDate>Wed, 21 Nov 2007 19:00:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6457034</guid><dc:creator>Steph Jones</dc:creator><description>&lt;p&gt;It would be nice if they could support existing customers and fix problems with 6.0 - such as the fact that many organisations rely heavily on the domain:s: parameter in RDP files because of being a multi-domain, multi-terminal server site with trusts.&lt;/p&gt;
&lt;p&gt;Such issue was reported back in late 2006!&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#6458805</link><pubDate>Wed, 21 Nov 2007 22:58:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6458805</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Steph,&lt;/p&gt;
&lt;p&gt;With 6.1 client you can use &amp;quot;username&amp;quot; parameter in RDP file for the same purpose. If you only need to specify domain name you can set it like this:&lt;/p&gt;
&lt;p&gt;username:s:&amp;lt;your domain name&amp;gt;\&lt;/p&gt;
&lt;p&gt;This will not work with 6.0 client, though.&lt;/p&gt;
&lt;p&gt;With 6.0 client you can acheive the same result by modifying &amp;nbsp;“HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\UsernameHint” registry key.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Sergey.&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#7880196</link><pubDate>Sun, 24 Feb 2008 20:02:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7880196</guid><dc:creator>Shadow</dc:creator><description>&lt;p&gt;Regarding with Scenario3: I think the issue is the SPN. It is impossible to registering the same SPN to multiple servers. However it is possible to registering the SPN to the user account too. So if the services are running under a Service Account, you can registering the SPN to this Service Account.&lt;/p&gt;
&lt;p&gt;Is there anyway available to configure the Terminal Server service is running under the specified Service Account. Is it tested? Is it supported?&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#7895172</link><pubDate>Mon, 25 Feb 2008 21:38:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7895172</guid><dc:creator>Sergey Kuzin</dc:creator><description>&lt;p&gt;Unfortunately, it is not possible today to configure TS to run under an account other than NETWORK SERVICE (or SYSTEM). Other services and drivers rely on TS to run under this account. We are working on solving this problem (Kerberos authentication in TS farm scenarios) in the next OS release. &lt;/p&gt;
</description></item><item><title>Problems using default credentials with Vista RDP clients with Single Sign-on Enabled</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8444932</link><pubDate>Wed, 30 Apr 2008 23:57:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8444932</guid><dc:creator>Terminal Services Team Blog</dc:creator><description>&lt;p&gt;With Single Sign-on enabled , the current user’s credentials, also known as “default credentials”, are&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8784931</link><pubDate>Mon, 28 Jul 2008 20:17:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8784931</guid><dc:creator>Shan McArthur</dc:creator><description>&lt;p&gt;There needs to be another scenario - connecting to a Windows 2008 server. &amp;nbsp; It seems as though he default security settings in Windows 2008 do not allow a Vista client to connect with saved credentials. &amp;nbsp;This is behavior that has changed from Windows 2003 Server, but it is not documented, nor is the solution commonly known. &amp;nbsp;This blog would benefit from the additional information.&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8784984</link><pubDate>Mon, 28 Jul 2008 20:32:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8784984</guid><dc:creator>Olga</dc:creator><description>&lt;p&gt;Hi Shan,&lt;/p&gt;
&lt;p&gt;Thanks for your feedback. The scenarios in the blog post above assumes that you are connecting to Windows 2008 Server. There could be several reasons why you are not able to connect with saved credentials - do you have SSL certs deployed on the WS08 or do both client and server have access to KDC to do Kerberos Authentication?&lt;/p&gt;
&lt;p&gt;You should check what your GP for set credentials are set to under Computer Configuration -&amp;gt; Administrative Templates -&amp;gt; System -&amp;gt; Credentials Delegation. You can also refer to the similar post on default credentials for more information: &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/ts/archive/2008/04/30/problems-using-default-credentials-with-vista-rdp-clients-with-single-sign-on-enabled.aspx"&gt;http://blogs.msdn.com/ts/archive/2008/04/30/problems-using-default-credentials-with-vista-rdp-clients-with-single-sign-on-enabled.aspx&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>How to implement SSO with a SmartCard and use RDP</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8794249</link><pubDate>Thu, 31 Jul 2008 21:48:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8794249</guid><dc:creator>Nomade</dc:creator><description>&lt;p&gt;We want &amp;nbsp;to implement a SSO solution based on a Smardcard that contents the information for the authentification. But we want also allow RDP session to this Desktop from a SSL VPN solutions using a End Point that will not have the Smartcard drive. How to have the compatibility of the SSO infrastructure with the RDP Session through SSL VPN Session &lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8826309</link><pubDate>Mon, 04 Aug 2008 06:39:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8826309</guid><dc:creator>DeeperThinker</dc:creator><description>&lt;p&gt;Are you using the remote computer name or the computer IP to connect using RDP? &amp;nbsp;I have a Vista client that would connect with saved credentials to one TS but not another. &amp;nbsp;The only difference was computer name vs. computer IP. &amp;nbsp;I changed the problem RDP to the computer name and was able to connect with saved credentials.&lt;/p&gt;
</description></item><item><title>re: How to implement SSO with a SmartCard and use RDP </title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8834499</link><pubDate>Tue, 05 Aug 2008 20:28:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8834499</guid><dc:creator>Olga</dc:creator><description>&lt;p&gt;Hi Nomade,&lt;/p&gt;
&lt;p&gt;SSO is only supported with username and password (domain credentials). SSO it is not possible with smart cards unfortunately.&lt;/p&gt;
</description></item><item><title>re: Problems using saved credentials with Vista RDP clients and above</title><link>http://blogs.msdn.com/rds/archive/2007/07/31/problems-using-saved-credentials-with-vista-rdp-clients-and-above.aspx#8834515</link><pubDate>Tue, 05 Aug 2008 20:37:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8834515</guid><dc:creator>Olga</dc:creator><description>&lt;p&gt;Hi DeepThinker,&lt;/p&gt;
&lt;p&gt;In the example above (and ususally), we use the FQDN of the server to connect (I would imagine it's also easier for the client to type in server name than an IP address). Although connection using IP address should work as well - do you think your DNS may be misconfigured (e.g. have multiple PTR records so reverse lookup is returning different host names?).&lt;/p&gt;
</description></item></channel></rss>