zoukankan      html  css  js  c++  java
  • Configure custom SSL certificate for RDP on Windows Server 2012 in Remote Administration mode

    Q:

    So the release of Windows Server 2012 has removed a lot of the old Remote Desktop related configuration utilities. In particular, there is no more Remote Desktop Session Host Configuration utility that gave you access to the RDP-Tcp properties dialog that let you configure a custom certificate for the RDSH to use. In its place is a nice new consolidated GUI that is part of the overall "edit deployment properties" workflow in the new Server Manager. The catch is that you only get access to that workflow if you have the Remote Desktop Services role installed (as far as I can tell).

    This seems like a bit of an oversight on Microsoft's part. How can we configure a custom SSL certificate for RDP on Windows Server 2012 when it's running in the default Remote Administration mode without needlessly installing the Remote Desktop Services role?

    Important: you need open a CMD by "Run as administrator" then perform the wmic command.

    A:

    38 down vote accepted

    It turns out that much of the configuration data for RDSH is stored in the Win32_TSGeneralSetting class in WMI in the rootcimv2TerminalServices namespace. The configured certificate for a given connection is referenced by the Thumbprint value of that certificate on a property called SSLCertificateSHA1Hash.

    In order to get the thumbprint value

    1. Open the properties dialog for your certificate and select the Details tab
    2. Scroll down to the Thumbprint field and copy the space delimited hex string into something like Notepad
    3. Remove all the spaces from the string. You'll also want to watch out for and remove a non-ascii character that sometimes gets copied just before the first character in the string. It's not visible in Notepad.
    4. This is the value you need to set in WMI. It should look something like this: 1ea1fd5b25b8c327be2c4e4852263efdb4d16af4.

    Now that you have the thumbprint value, here's a one-liner you can use to set the value using wmic:

    wmic /namespace:\rootcimv2TerminalServices PATH Win32_TSGeneralSetting Set SSLCertificateSHA1Hash="THUMBPRINT"
    

    Or if PowerShell is your thing, you can use this instead:

    $path = (Get-WmiObject -class "Win32_TSGeneralSetting" -Namespace rootcimv2	erminalservices -Filter "TerminalName='RDP-tcp'").__path
    Set-WmiInstance -Path $path -argument @{SSLCertificateSHA1Hash="THUMBPRINT"}
    

    It occurs to me that this solution would probably work on Windows 8 systems as well. I haven't played with it much myself yet though.

    Note: the certificate must be in the 'Personal' Certificate Store for the Computer account.

  • 相关阅读:
    关于Android架构那些事
    关于投资那些事
    关于单例模式的N种实现方式
    关于如何避免Android中Bitmap引起的OutOfMemoryError
    关于Java设计模式的一些概况
    阿里云服务器使用记录:服务器运行的网页无法访问
    毕业设计进度:3月22日
    前端框架:bootstrap多个模态框跳转使用时发生的页面左移问题
    毕业设计进度:3月20日
    毕业设计进度:3月19日
  • 原文地址:https://www.cnblogs.com/oskb/p/4800955.html
Copyright © 2011-2022 走看看