Signing RemoteApp afterwards


hi

i trying sign rdp after it's creation remote app manager, implement not available on gui (map particular drives, not every drive rdp session). unfortunately, not work:

>rdpsign /sha1 82bf48cf5be3f8a2275d3c1b7cba18e501802eb3 remote.rdp
unable use certificate specified signing. error code: 0x80090016
rdp file not signed. error code: 0x80090016

here thoughts , things have tried:

  • remoteapp manager signs rdp cert
  • cert private key in local machines store (for troubleshooting copied private key local user store , trusted root store)
  • no spaces in thumbprint, no question mark either
  • logged in administrator
  • cmd administrator

the error means:

nte_bad_keyset 0x80090016 keyset not exist

see msdn.microsoft.com/en-us/library/windows/desktop/dd542646(v=vs.85).aspx

the certificate`s key usage has following configured:

  • digital signature
  • non-repudiation
  • key encipherment (e0)

enhanced key usage:

  • server authentication (1.3.6.1.5.5.7.3.1)
  • client authentication (1.3.6.1.5.5.7.3.2)
  • any purpose (2.5.29.37.0)

application policies:

  • [1]application certificate policy:
    policy identifier=server authentication
  • [2]application certificate policy:
    policy identifier=client authentication
  • [3]application certificate policy:
    policy identifier=any purpose

so cert should right guess

any ideas?

thanks support



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client