Professional Documents
Culture Documents
You will need to create a new (duplicated from workstation) certificate template,
and modify the template’s settings to incorporate the correct extensions when
enrolling for a new certificate via this template.
As prerequisite for this tutorial, it is assumed that you already have an enterprise
certificate authority, and remote desktop services deployement installed on your
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 1/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
network.
Our first step will be the creation of a new certificate template, modified to enroll
correct certificates for our RDS deployment.
In the certificate templates console, scroll down until you find the ‘Workstation
Authentication’ template. Right click it and select Duplicate Template.
On the General tab of the new template, change the template display name to
RDS Certificate Template and mark the checkbox to publish the certificate in
Active Directory.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 2/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 3/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 4/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 5/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Close the new template now by selecting ok, and close your Certificates
Templates Console.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 6/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
For proof of concept, we will enroll a certificate using this template on our
Remote Desktop Broker Server.
Open a management console by right clicking start, then run, type mmc and press
enter.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 7/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 8/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Now we have the Certificates Store of the local computer open, we will be
requesting a new certificate from within this console to our enterprise CA.
Under Certificates, Personal, right click the certificates folder and select all tasks,
request new certificate.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certific… 9/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Make sure Active Directory Enrollment Policy is highlighted, and click next.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 10/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Select RDS Certificate Template, and click the link to configure additional
information for enrollment.
On the certificate properties window, add a common name for the certificate, this
may be your FQDN of your RDS broker server, subsequently, add alternative dns
names for other roles that u might be hosting on the same server like your RDS
web access, or if you are planning to use this certificate also on the other servers
in your deployment, add the FQDN’s of the other servers as DNS entries.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 11/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
On the General tab, fill in a descriptive name for the certificate that you are
enrolling, after this, select ok to close the certificate properties window.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 12/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Now click the Enroll button to request your certificate to the Enterprise CA.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 13/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
In our Certificate Management Snap-in we can verify that our new certificate is
enrolled and available to us. If it is not displayed at first, then press F5 to refresh
and make it visible.
We now need to export the certificate and the private key to import it again via
our RDS management console.
Right click the certificate, select all tasks and click export.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 15/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 16/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 17/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 18/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 19/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Now that we have the exported certificate ready, we can finish the certificate
installation on our Remote Desktop Management console.
Open Server Manager, and open Remote Desktop Services in the left pane, then
click tasks, and edit deployment properties.
Go to certificates, highlight the role for which u want to deploy your certificate,
and click select existing certificate.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 20/21
22/01/2021 Windows 2012 R2 RDS – Configure RDS Certificates with own Enterprise CA
Select, choose a different certificate, browse for your certificate, enter your
certificate password, and select to allow the certificate to be added to the trusted
root certification authorities store. After that confirm with ok.
Click apply to apply the certificate. After this action, the status will show OK and
the level will be Trusted.
read://https_blog.ronnyvdb.net/?url=https%3A%2F%2Fblog.ronnyvdb.net%2F2019%2F01%2F20%2Fwindows-2012-r2-rds-configure-rds-certifi… 21/21