question

gabrielsztejnworcel-3009 avatar image
0 Votes"
gabrielsztejnworcel-3009 asked gabrielsztejnworcel-3009 commented

Separate Remote Desktop Services listeners with separate TLS certificates

Hi,
I know it's possible to have separate RDS listeners on different ports (it can be achieved for example by duplicating the RDP-tcp registry key and assign it with a different name). My question it - is it possible to have different TLS certificates for the different listeners?
Thanks,
Gabriel

remote-desktop-services
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HI gabrielsztejnworcel-3009,

Is your target server installed "remote desktop session host" role?

0 Votes 0 ·

1 Answer

JiaYou-MSFT avatar image
0 Votes"
JiaYou-MSFT answered gabrielsztejnworcel-3009 commented

HI gabrielsztejnworcel-3009,

is it possible to have different TLS certificates for the different listeners?

1.Could you please build the test vm environment and check below method.

server 2019 evaluation download link
https://www.microsoft.com/en-us/evalcenter/evaluate-windows-server-2019

(1)we need to request 2 certificates from internal CA on terminal server and import them to personal certificate store.

(2)duplicate the RDP-tcp registry key and assign it with a different name(like "RDP")like picture1.

(3)We can try to change the other listener port from 3389 to3398 so that we can test different listener certificate for different listener port.

(4)We follow below document to import your listener certificate and create SSLCertificateSHA1Hash register key then configure certificate permission as network service account with read permission. (picture 2- 3)

(5)Finally, we can check the result.


Remote Desktop listener certificate configurations (Method 2: Use registry editor)
https://docs.microsoft.com/en-us/troubleshoot/windows-server/remote/remote-desktop-listener-certificate-configurations

95943-13.png

95944-14.png


95845-15.png



============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


13.png (170.1 KiB)
14.png (163.9 KiB)
15.png (64.1 KiB)
· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks! I will test this later.

0 Votes 0 ·
JiaYou-MSFT avatar image JiaYou-MSFT gabrielsztejnworcel-3009 ·

OK, you are welcome! I hope everything goes well.

0 Votes 0 ·

HI gabrielsztejnworcel-3009,

Is there any progress on your question?

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

0 Votes 0 ·

Hi,
I verified the method above works and accepted the answer.
Thanks!

0 Votes 0 ·
JiaYou-MSFT avatar image JiaYou-MSFT gabrielsztejnworcel-3009 ·

HI
Thanks for your reply, I am glad to hear that this issue has been resolved.

0 Votes 0 ·