標籤:windows write
在上一篇中,我們配置好了RemoteApp程式,也可以用戶端中正常開啟運行,但是看到類似下面的視窗時,總覺得不爽,而且會因為認證校正,串連的時間會很長
650) this.width=650;" title="映像 022" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 022" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858312WPV4.jpg" "410" height="300" />
650) this.width=650;" title="映像 025" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 025" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858312KCcg.jpg" "316" height="312" />
引起這個問題原因就是認證問題
分兩部分來處理
一.WEB
1.在CA頒發機構中,右鍵-憑證範本
650) this.width=650;" title="映像 035" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 035" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858313JvWs.jpg" "244" height="100" />
2.在憑證範本制台中,右鍵選WEB伺服器-複製模板
650) this.width=650;" title="映像 027" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 027" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858313hWOm.jpg" "353" height="330" />
3.修改新模板名稱,在安全選項卡中,添加RDS伺服器,注意添加的是電腦對象,許可權為讀取,註冊,自動註冊
650) this.width=650;" title="映像 036" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 036" src="http://img1.51cto.com/attachment/201406/27/3219370_14038583141Qfs.jpg" "387" height="85" />
650) this.width=650;" title="映像 037" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 037" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858314exc0.jpg" "379" height="449" />
回到憑證授權單位,建立要頒發的憑證範本
650) this.width=650;" title="映像 040" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 040" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858315KP1a.jpg" "472" height="312" />
選擇剛才建立的模板
650) this.width=650;" title="映像 041" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 041" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858315c9KI.jpg" "518" height="306" />
4.在RDS伺服器上申請認證
開啟MMC,添加認證(本機電腦)
右鍵個人-所有任務-申請新認證
650) this.width=650;" title="映像 038" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 038" src="http://img1.51cto.com/attachment/201406/27/3219370_14038583164uF5.jpg" "425" height="281" />
選擇AD註冊策略
650) this.width=650;" title="映像 039" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 039" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858316qH3l.jpg" "458" height="312" />
選擇建立的模板,並設定
一般名稱和DNS都填寫RDS伺服器的FQDN
650) this.width=650;" title="映像 032" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 032" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858317sZtY.jpg" "591" height="317" />
650) this.width=650;" title="映像 033" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 033" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858317yYd6.jpg" "502" height="467" />
申請好之後能在個人認證中查看到
650) this.width=650;" title="映像 034" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 034" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858318RmrD.jpg" "653" height="445" />
5.RDS伺服器綁定IIS,開啟IIS,右鍵選擇Default wet site-編輯綁定
650) this.width=650;" title="映像 030" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 030" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858318kcD4.jpg" "438" height="411" />
添加https,認證選擇為新申請的認證
650) this.width=650;" title="映像 031" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 031" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858319IBfe.jpg" "425" height="309" />
6.用戶端測試,不再有那個紅色的認證錯誤了
650) this.width=650;" title="映像 042" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 042" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858319vTGK.jpg" "504" height="366" />
二、RDP串連
1.安裝CA後,會發布一個電腦的認證,按上面步驟直接在RDS伺服器上申請這個機器憑證
2.在RD會話主機伺服器中,配置串連屬性
650) this.width=650;" title="映像 008" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 008" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858320Rxo2.jpg" "450" height="477" />
在認證位置選擇,之前申請的認證,並確定
650) this.width=650;" title="映像 009" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 009" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858320LtKH.jpg" "405" height="458" />
650) this.width=650;" title="映像 010" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 010" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858321uKnh.jpg" "244" height="132" />
3.用戶端測試,可以看到,現在已經是加密串連了,串連狀態條上有一個小鎖已經鎖住
650) this.width=650;" title="映像 043" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; padding-right: 0px" border="0" alt="映像 043" src="http://img1.51cto.com/attachment/201406/27/3219370_1403858321R9mN.jpg" "174" height="244" />