RDWEB Access SSO issue with ISA 2006 RADIUS OTP authentication


i have windows 2008 r2 based remote desktop services environment with

a) 2 load-balanced servers hosting both rd gateway , web access servers role

b) 2 clustered rd connections broker servers functioning dedicated farm redirectors

c) 3 rd session host servers in farm. 

a public certificate godaddy used digitally sign applications.  internally when users access rd web access page, prompted once authentication (user@domain.com), , when click on published applications after providing credentials @ rdweb access page, no longer prompted credentials.  in essence single signon works internally.

if users try access rdweb access page internet through isa using radius otp, single signon doesn't work. 

the users prompted credentials 3 times @ locations below

1) isa logon page

2) rdweb access page

3) when clicking published application

the way single signon works if connect windows 7 laptop directly internal network, access rdweb access page, , use same laptop access page internet through isa, , works.  seems cookie loaded on machine after accessing page internally allows single signon work. 

at point, baffled , need help.  thank in advanced solution this.

hi,

did see , follow guide on microsoft technet?
http://technet.microsoft.com/nl-nl/library/cc731249(ws.10).aspx

it explains otp scenario configuration in detail.

additionally, need configuration prevent users bypassing otp using rdp connection straight rdgw , farm.
wrote blog post on here: http://microsoftplatform.blogspot.com/2011/05/force-use-of-rd-webaccess-block-direct.html

 


kind regards,
freek berson
http://www.microsoftplatform.blogspot.com
wortell company website
twitter


Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS