Single-server RDS - how to setup auth by FOREIGN certificates properly?


we have 2012r2 server ad, rds single server , several application roles installed, hosts domain company.local (dc=company,dc=local). domain , forest 2012r2 level. have foreign pki infrastructure use provide certificate-based smart card logon services several other systems. have attempted create trust relations between pki system , company.local domain. did following:

  1. install local ca autoenrollment server certificates;
  2. install smart card drivers server them accessible via rdp;
  3. add foreign pki root ca certificate ntauth , domain policy trusted root ca;
  4. create account desired rights upn matching of certificates issued foreign ca;
  5. import several certificates account associate cert account in company.local domain.

the result pretty weird. when try authorizing rdp client domain, "unknown user or bad password" error, audit logs 0xc000006d/0xc000006a aka unknown domain. worse, error signifies credentials used in form of domain\username, instead of upn of username@suffix, , domain used 1 hosts foreign pki.

what should alter in rds server settings allow credentials in form of upn passed through rdg? suspect rdg gathering network level security data rdp client, grabs domain\username there , directs these credentials rdsh rejected because of unknown domain.

update: enabled "allow user hints" on both sides, set "company\username" hint, supplied pin smart card, , server reports of successful authorization, rdp client says "unknown user" - apparently tries validate user hint, thing that's changed, against local domain (the 1 hosts mentioned pki) of course not know foreign domain accounts. there misconfiguration between rdp server , rdp client occurring.

to clarify, client windows 10 latest updates.

hi,

according article below, nla cross-domain smart card authentication requires trust relationship.

why doesn’t nla work cross-domain smart card authentication?

https://blogs.technet.microsoft.com/the_9z_by_chris_davis/2016/05/02/why-doesnt-nla-work-with-cross-domain-smart-card-authentication/

best regards,

amy


please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS