Quantcast
Channel: Remote Desktop Services (Terminal Services) forum
Viewing all 27765 articles
Browse latest View live

Event ID 20 — Remote Desktop Services Availability

$
0
0

 Dear All,

I am getting the alert in SCOM2012 regarding the remote desktop service availability on many systems and according to resolution from Microsoft I have check all the things and it is working fine even the remote desktop service is also running so kindly help me out I am also attaching the Microsoft resolution which I have  

The Alert which I received from SCOM2012

Description: Attempt to send connect message to Windows video subsystem failed.
The relevant status code was 0xffffffffd0000001.

Context:
Date and Time:12/20/2012 9:04:53 AM
Log Name:Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Source:Microsoft-Windows-TerminalServices-LocalSessionManager
Event Number:20
Level:1
Logging Computer:Server Name
User:NT
AUTHORITY\SYSTEM
Description:
Attempt to send connect message
to Windows video subsystem failed. The relevant status code was
0xffffffffd0000001.

Event Data:

< DataItem
type="System.XmlData" time="2012-12-20T09:04:54.6755869+05:00"sourceHealthServiceId="D6815E3A-E059-0026-C20D-6982479E1F98">
< UserData>
< EventXML>

 <messageName>

  connect</
messageName>

 <errorCode
>0xd0000001</errorCode
>
 </EventXML
>
 </UserData
>
 </DataItem
>

The solution which I got from Microsoft.

The Remote Desktop Session Host role service relies on the Remote Desktop Services service to be running in order to accept remote connections. Remote Desktop also relies on the Remote Desktop Services service in order to support remote connections for administrative purposes.

Event Details

Product:          Windows Operating System
ID:          20
Source:          Microsoft-Windows-TerminalServices-LocalSessionManager
Version:          6.1
Symbolic Name:          EVENT_LSM_CSRSS_MESSAGESEND_FAILED
Message:          Attempt to send %1 message to Windows video subsystem failed. The relevant status code was %2.

Resolve

Use error code to determine error

When there is a failed attempt to send messages to the Windows video subsystem, the error code can help determine the cause of this error.

Verify

To verify that Remote Desktop Services is available, ensure that the Remote Desktop Services service is started.

To perform this procedure, you must have membership in the local Administrators group, or you must have been delegated the appropriate authority.

To verify that the Remote Desktop Services service is started:

  1. On the computer, open the Services snap-in. To open the Services snap-in, clickStart, point to Administrative Tools, and then clickServices.
  2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then clickYes.
  3. In the Services pane, locate Remote Desktop Services.
  4. Confirm that the Status column for the Remote Desktop Services service displaysStarted.


RDP files signed with rdpsign became corrupted in RDP 8.0

$
0
0

Hi all,

I'm using rdpsign to sign custom RDP files. Everything working fine in Win7 but when I updated RDP client to RDP 8.0 compatible this files became corrupted.

Server 2012 VDI - Can not connect to Pool when RemoteFX adapter is installed.

$
0
0

Hello,

I have an development VDI environment.

I have everything setup 1 server is a Connection Broker, 1 Web Access Server, 1 Gateway Server, 1 License Server, 1 Virtual Host Server and one 3 Virtual machine pool.

I can connect to the pool no problem until, i add the RemoteFX adapter to the Virtual machines. I have enabled it on the Virtual Host Server, and then i shut down the virtual machines in the pool and add the RemoteFX graphics card to the virtual machines, Then i reboot them, I log in directly to each virtual and let it install the new graphics drivers and reboot.

After that when i try to connect the MSTSC connection goes through as it did before except right after it say" determining connection Quality" it just disappears. I see lots of event logs saying the session is connected, but no error messages on any of the machines. If i connect directly to the Virtual machines it connects no problem, but as soon as i try and connect to the pool itself through the connection broker that is when it stops.

I am running on a 1GBps network same subnet as the Virtaul machines and every other server for these test. 


Please help.

Unable to Remotely login into member servers 2008 R2

$
0
0

i have made a server 2008 R2 as a memeber server of 2008 R2 Domain

(All set up are Vertual mechine only It is a Test Lab in our organaization)

When I am trying to login remotely from my desktop (this desktop belongs company network and Domain ---this company network have access in that vertual network)

1.when I am trying to login into local server accont   It is posible

2.when I am trying to login into vertual Domain account .it will not directly login into the server rather that  Fisrt  i am geting local authentication windows after succesvely login into that  only i will get server 2008 login window .So i have to use swtch user then  domain\username ... password   Then able to get  domain account desktop.

Could anybody sugest a solution I done following things also

1.1.created  smsadmin user
2.create  sccm  group
3.added sccm group into administrators group
4.added sccm group into remote desktop users
5.added sccm group into the remote desktop option in memebre server finaly

6.Enabled "allow log on locally policy"

7.Enabled remote desktop desktop users policy  but not working out

Even I tried from vertual domain server to member server  (same Domain/network)  

then also but geting the erro

"logon attempt failed"


shinu


attempting RDP session leaves windows session is un-loginable until restart

$
0
0
Sometimes when I try to use rdesktop from my ubuntu 10.04 system to log into windows XP (sp2) it fails and leaves the windows system impossible to be logged into.

Even when I go back to the windows computer, when I try to log in as the user that has programs running, or trying to start a new user session, the screen says "loading your personal settings", but then after a second it returns to the login page showing all the users.  I have been able to ssh into the windows computer, but cant get back to the desktop until I restart the computer.

Is there anyway to troubleshoot why this happens?  Perhaps something I can check or execute while I am using ssh?

Outlook 2010 is extremely slow on VDI

$
0
0

Hello all,

We are running Windows XP on a virtual environment and we've recently upgraded Outlook from 2003 to 2010. Ever since this upgrade, our Outlook has been extremely slow. When reyplying to all, Outlook freezes and takes about 30 seconds for it to start working again. Even search takes about over a minute and moving messages to folders takes even longer. Outlook is not running on cache mode.

Can someone please help?

Thank you

Remote users are not able to connect to Terminal Server from WAN while administrators are able to

$
0
0

Good evening.

I have setup my Terminal Server and it is activated. I have also created a Firewall rule to allow connections to port 3389 mapped from WAN to the internal IP of my Terminal Server. after trying to connect, I was able to reach the Terminal server using my admin account. I tried a different scenario, trying to log in using a user account but I couldn't, the error message was:

"The connection was denied because the user account is not authorized for remote login."

Any Suggestions?


Hani El Mouallem

RDSH 2012 with 2008R2 Connection broker / Gateway /Web Access

$
0
0

Hello,

We have an environment with a couple of W2K8R2 RDSH servers (no farm) and a separate W2K8R2 Gateway / Web Access / Connection Broker.

Access to the RDSH is only possible through the Gateway.

We want want to add a W2012 RDSH server to this configuration, will this be fully compatible or is it advised to first upgrade the W2K8R2 Gateway / Web Access / Connection Broker?

Regards,

Erik


RemoteApp with no login

$
0
0

Is it possible to have RemoteApp be completely publicly available with no login?  We have a client who because of corporate polices won't accept our ClickOnce application (they don't allow auto-updating applications and since our ClickOnce app does automatically update when a new version is available it is not allowed).  My next thought was to publish the app as a RemoteApp and they just access that (we'd have to manually update the RemoteApp when any new version is available but we can automate that).

Ideally, I want this to not require any login of any type for RemoteApp.  The RemoteApp server will be safely in a DMZ, Firewall rules will only allow connections to the server from our client site over a VPN we will create between the client and ourselves, and our application has its own login method (not AD integrated).  So ideally, I'd like to deploy the RemoteApp where the client's users just launch the RemoteApp, enter the application's credentials and that is it.  No need to enter any domain logins/etc.

I've been playing with this trying to make every setting I can find say "everyone" can access it, but it always still requests a domain login/password.  Is there any way to basically make the RemoteApp "public" and not require login/password at all for RemoteApp?

RDS Login Accounts

$
0
0

I have a number of questions that I require some advice on.

1. I am running RDS on a Server 2008 R2, when I open the RD Web Access Page and it asks for the username and password credential I enter the credentials for that user, I receive the following error: Server Error in '/RDWEB/Pages' Apllication however if I use the administrator credentials the window continues the Remote Apps window showing the published apps, I then am able to run the app but only under the Administrator Credentials

2. When running the remote app from the shared location with the user credentials the pages opens and show me logging into a session but then logs off without activating the app.

I believe it is a permission problem

Any suggestions

Server 2012 rds workgroup

$
0
0

I do understand the RDS dose not work in Workgroup but please show me trick to make it work , need to use Rds and remoteapp, and per user licensing and manage it with Gui just like 2008 r2, some how to trick it into running with out AD

kiss kiss

Small RD setup via Server 2012 not working with certs from our internal CA

$
0
0
Hi,

I'm having trouble with a small installation of Remote Desktop which is supposed to be accessed from outside our network.  I'm using a Server 2012 system for all RD roles (TS, gateway, web access, and broker, although we shouldn't actually need the latter two).  This is the only 2012 system in the network; we have two DCs, 2008 and 2008 R2, and we have cert root and issuing authorities also on 2008 R2.  Our Internet-based clients trust our root cert and the PKI is working ok for other (non-RD) servers.

Things work fine if the "RD Connection Broker - Enable Single Sign On" certificate is a self-signed cert generated by Server Manager on the 2012 box.  However, if I assign a cert from our issuing CA to that role, it doesn't work.  Interestingly, it works fine if the *other* certs (RD Gateway, RD Web Access, and RD Connection Broker - Publishing) are from our CA.  (Now, when I say "works fine" I mean after ignoring a security warning on the client due to the Broker SSO cert not being trusted.)

The procedure I'm using for the certs is as follows:

1.  Make a cert template based on the "Web Server" 2008 built-in template with some straightforward changes, and make the issuing CA use the template.  Initially I had upped the crypto strength and made several extensions critical, but for troubleshooting I made a template without those changes and it still doesn't work.

2.  Request a new cert via the Certificates snap-in on the 2012 machine, on the local computer account.  Initially I was using a friendly name for the Subject CN and then using a DNS Alternative Name extension to give the 2012 box' external domain name.  To be more sure for testing, I used the external domain for the Subject CN and then also provided DNS Alternative Names for both the external and internal domains (which are subdomains of the same domain).  For crypto provider, we use "RSA,Microsoft Software Key Storage Provider" and disable the others.

Internet connections come in via some tricky DNAT but I don't think this is the problem as it works perfectly from outside with a self-signed cert for Broker SSO.  Only our internal DNS knows about the internal domain.

3.  Manually issue the cert on the CA.  (Our site is small and for security we require manual issuance for all certs.)

4.  Export the cert from the CA via PKCS #7, with the option to include all certs in the cert path, and then import this in the Certificates snap-in on the 2012 machine.

5.  On the 2012 box, export the private key via PKCS #12 and "include all certificates in the certification path if possible".  For troubleshooting I also tried "Export all extended properties" and it didn't fix the issue.  I'm exporting with password protection.

6.  In Server Manager->Remote Desktop Services->Overview, on the Deployment Overview, I pick Tasks->Edit Deployment Properties and use the "Select existing certificate..." button for the desired role on the Certificates page.

If the "RD Connection Broker - Enable Single Sign On" certificate is from our CA via the above procedure, then attempting to log on from the Internet gives an error on the client reading:

"Your computer can't connect to the remote computer because the Remote Desktop Gateway and the remote computer are unable to exchange policies.  This could happen due to the following reasons:
1. The remote computer is not capable of exchanging policies with the Remote Desktop Gateway.
2. The remote computer's configuration does not permit a new connection.
3. The connection between the Remote Desktop Gateway and the remote computer ended.
Contact your network administrator for assistance."

My test client is Windows 7 SP1, if memory serves with an update manually installed to upgrade to RDP8.

The logs on the client show nothing unusual.  In the System log on the Server 2012 box I get two errors:

ID 36874
An [sic] TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server.  The SSL connection request has failed.

followed by:

ID 36888
A fatal alert was generated and sent to the remote endpoint.  This may result in termination of the connection.  The TLS protocol defined fatal error code is 40.  The Windows SChannel error state is 1205.

I found some advice that this error may be the result of the cert not being a CNG cert.  The CA is 2008 R2, the domain has always been at least 2008 functional level (was originally 2008 and recently schema updated for 2008 R2), and only 2008 R2 CAs have ever been used on it.  I have furthermore verified by dumping the cert store that under CERT_KEY_PROV_INFO_PROP_ID, ProviderType and KeySpec are both zero, which in my understanding means this is a CNG cert.

To reiterate, the problem does *not* happen if I replace the "RD Connection Broker - Enable Single Sign On" certificate with a self-signed cert created by Server Manager.

The test cert I'm trying to use for RD Connection Broker SSO has the following info:

Version=V3
Signature algorithm=sha512RSA
Signature hash algorithm=sha512
Issuer=our issuing authority
Valid to=two weeks today (it's just for testing)
Subject=external.domain.com
Public key=RSA (2048 Bits)
Template=Test - Delete Please(1.3.6.1.4.1.311.21.8.5198179.16696210.7229373.7348787.5553704.31.11896299.7938212)
    Major Version Number=100
    Minor Version Number=2
Enhanced Key Usage=Server Authentication (1.3.6.1.5.5.7.3.1)
Key Usage=Digital Signature, Non-Repudiation [turned this on as a test], Key Encipherment, Data Encipherment (f0)
Application Policies=
    [1]Application Certificate Policy:
        Policy Identifier=Server Authentication
Subject Alternative Name=
    DNS Name=external.domain.com
    DNS Name=thebox.internal.domain.com

Forgive me if I'm missing something obvious - I'm not a full-time netadmin and I'm new to RD and PKI.  I hope someone can shed some light on this troublesome mystery.

Thank you,
Kevin

2012 RDS: Non-Administrators can not access VDI pool

$
0
0

I am currently setting up server 2012 VDI using 2 servers. A connection broker, web access, licenseing server and a VM Host server. I have followed the wizards, created my master image, created the collection, and setup group policy to add the group I want to give RDS access to Allow log on through terminal services & Remote Desktop Users group. 

When I connect using my admin account everything works, it connects to the connection broker and then forwards to one of the running VMs.

When I connect using a non-admin account I am prompted with: The connection was denied because the user account is not authorized for remote login. I also get the following in the event log:

TerminalServices-SessionBroker

RD Connection Broker failed to process the connection request for user ***\****.
Failed to find Resource Plugin OR an end point for the user.
Error: Access is denied. 

TerminalService-SessionBroker-Client

Remote Desktop Connection Broker Client failed while getting redirection packet from Connection Broker.
User : ***\**** 
Error: Element not found. 


--

Remote Desktop Connection Broker Client failed to redirect the user ***\**** 
Error: NULL

I searched the internet high and low and I can not figure this out. I have even put the the non-admin users in the remote desktop users on the server just to see what would happen, same results if trying to connect to the pool. But I am able to connect directly to the server. I am also able to directly connect to a VM in the pool using a non-admin account. 

Any help would be appreciated. 


How to have remote desktop leave USB connections alone?

$
0
0
When I establish an RDP remote desktop connection to my windows XP sp2 workstation, one of my applications that is running on the workstation loses the USB connection.  Is there a way to configure Remote Desktop to not interrupt USB connections running on the "server"?

Optimising RDP Connection Times

$
0
0

Hi all,

I've been struggling with this one for a while now but I think I've now exhausted google and this forum so it time to ask.

I'll give an overview of the setup first.  Basically I have (at present) 2 x 2008 Terminal Servers running on physical hardware and 2 x Session Brokers running virtually.  The 2 session brokers are running in a cluster and each running a instance of RDweb.

Internally there is a certificate server running on the domain and both the web pages for RDweb, the Remote Apps and the Session brokers are using certificates.  In addition to this the client (Windows 7 Pro) has the thumbprint of the certificate placed in the registry to get rid of all the anoying messages.

Everything seems to working as it should but not as fast as I would expect, 2003 was much quicker at connecting than this.

The problem I have is this:

On the Windows 7 client an RDP file is automatically run by some kiosk software at workstation unlock.  From starting the connection to a disconnected session being available takes around 17s.

If I run the same RDP file in the standard environment (Windows XP SP2) it takes around 5 secs to perform the same operation.

Where can I start looking to reduce this time on the Windows 7 device?  5 secs in the Windows XP environment is a lot better but ideally it would be somewhere round 1-2secs.

Many Thanks


VM User Not Recieving Full Profile and Providing Temp Profile

$
0
0

I have a user having trouble with his roaming profile. All other users haven't got a the same issue just the one user. His issue is as follows:

When the user is logged in he changes his desktop background and has files on his desktop. When the user logs off he gets a blank desktop and some files are missing along with the default printer being relocated to Microsoft XPS.

I've looked into the GP and it states the maximum size for a roaming profile is 15GB the users is 60MB. It is also set to do not cache roaming profiles. The users profile is pointing towards \\<share>\<Drive$>\<UserProfileName> in AD which is the correct location of his profile.

The user has two profiles saved in this location on is <user> and the other is <user.v2>.

Any ideas?

Thanks

How many users (or machines) are allowed before requiring the purchase of remote desktop CALs?

$
0
0

We have a windows server 2008 R2 machine. How many "free" licenses are we allowed before we are required to purchase the RD CALs? I was informed that it was 2 but would like to get some confirmation. The connecting machines are running windows 7 and pretty soon we will be outside the grace period.

The licensing mode for the Remote Desktop Session Host server is currently not configured.

Windows Server 2008 RDP audio packet throughput

$
0
0

I created Client/Server software that samples the audio input line on the Server side, and plays the audio wave data on the client side.    The audio sounds great when the client and server software are physically running on two separate machines.  However, when I run the server software on Windows Server 2008 R2 and then Remote Desktop into the Windows Server 2008 R2 and run the client software, the audio is choppy.  I'm taking advantage of the RDP audio feature in Windows Server 2008 R2 and I know that the RDP audio traffic is limited in bandwidth.  I am more concerned about response time than I am bandwidth.  Is there a way to bypass limits set on RDP audio traffic? I have maximize the audio experience by “Enabling” the “Limit audio playback quality” and setting “Audio Quality” to “High” on the server side and setting the “audioqualitymode:i:2” on the client side.

Terminal Server 2008 & Win 7 printing problems

$
0
0

We are usingTerminalServer 2008withour .NET application.
Whenthe user printsthematrixprinterconnectedto aWindowsXP the printing is good(LocalPrinterattachedto the machineandtakeRemote Accesslocal resourcesprinter)but whenthe user printssomethingfrom a machine withWindows 7printinggoes wrong,the charactersare widerand can not be read
.

We are using Printers Epson TM U590 P with LPT1 port.

Any suggestions?

"System Administrator does not allow the use of saved credentials...." RDP clients and 2008 RDS

$
0
0

I have just setup a new 2008 R2 Remote Desktop server.   I am trying to setup RDP clients to save the password and credentials for connecting to the server.  However when I try to do this on client computers, I get a message "Your system administrator does not allow the use of saved credentials to logon to the remote computer x.x.x.x because its identity is not fully verified."

I have done some internet searching on this issue, but mostly they talk about changing policy settings on the client.  Is there a setting on the server that I can change, to allow users to save their credentials in the RDP client?  Thanks for any advice.

Viewing all 27765 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>