Windows 10: Port forwarding Remote Desktop RDP and installing SSL Certificate?

Discus and support Port forwarding Remote Desktop RDP and installing SSL Certificate? in Windows 10 Software and Apps to solve the problem; Is it possible to install an SSL Certificate just for RDP? I have a Windows 11 system I want to safely access over the internet but I cannot find any... Discussion in 'Windows 10 Software and Apps' started by Weston Gately, Nov 16, 2023.

  1. Port forwarding Remote Desktop RDP and installing SSL Certificate?


    Is it possible to install an SSL Certificate just for RDP? I have a Windows 11 system I want to safely access over the internet but I cannot find any information on this topic. Is it not possible? All I see is info on how to do it for RDS Remote Desktop Services but I am just trying to do it for a personal system. I have a domain and an SSL Certificate for said domain. I am able to use RDP using my domain, but I just want it to be secure with SSL.

    :)
     
    Weston Gately, Nov 16, 2023
    #1
  2. Tenforo Active Member

    how to use own SSL certificate for RDP server?

    I have my certificate in both stores - Personal and Remote Desktop. And yes, i have my CA in Trusted Root Certification Authorities too. Even "golden" key is shown in certificate icon.
    Port forwarding Remote Desktop RDP and installing SSL Certificate? 381746d1671806788t-how-use-own-ssl-certificate-rdp-server-2022-12-23_rdp_mmc_new_certificate.png
    wmic /namespace:\\root\cimv2\TerminalServices PATH Win32_TSGeneralSetting Set SSLCertificateSHA1Hash="f4...95" wmic is succesful only when i have key SSLCertificateSHA1Hash=hex:f4...95 already in registry. Before that i got only "Invalid Parameter" error. I cannot restart TermService during RDP connection, but i guest reboot is equivalent.
    Port forwarding Remote Desktop RDP and installing SSL Certificate? 8272t-how-use-own-ssl-certificate-rdp-server-2022-12-23_rdp_cannot_restart_during_rdp_connection.png
    Even with parameter -Force i cannot restart the service, it failed and only other option was reboot machine. Even local login was not possible.
    Port forwarding Remote Desktop RDP and installing SSL Certificate? 381749d1671809127t-how-use-own-ssl-certificate-rdp-server-2022-12-23_rdp_failed_restart.png
    There still must be some detail which i am missing.
     
    Tenforo, Nov 16, 2023
    #2
  3. swec Win User

    how to use own SSL certificate for RDP server?

    It took me some time to try it, but i still didn't succeeded. I did follow succesfully link to the Microsoft web but it not enough.
    Port forwarding Remote Desktop RDP and installing SSL Certificate? 381726d1671799545t-how-use-own-ssl-certificate-rdp-server-2022-12-21_rdp_wmic_succesful.png
    But my virtual machine still provides only its own selfsigned certificate. I am using mostly xfreerdp on Linux, but thumbprint is same with Microsoft Remote Desktop too.
    Port forwarding Remote Desktop RDP and installing SSL Certificate? 381732d1671799903t-how-use-own-ssl-certificate-rdp-server-2022-12-21_rdp_still_selfsigned_cert.png
    Last thing i did tried was import certificate in P12 form (PKCS #12), which is basically combination of signed certificate and CA certificate in one package protected by password (it have same icon with small key) and i tried delete self signed certificate and then reboot. But even deleting didn't help. Windows instead of using only one available certificate just created new self signed certificate. So how i can do it? Does it have any solution? What if that certificate was issued by some of public CA, for example Let's Encrypt?
     
  4. zebal Win User
    how to use own SSL certificate for RDP server?

    I've been struggling with this because even though I followed MS docs exactly and set the registry key what happened is after reboot the registry key was deleted and RDP recreated a new self-signed cert. But there is another solution which worked as charm: Code:
    replace THUMBPRINT portion with your cert thubmprint. I got this from here: security - Windows 10 Pro as RDP Host with SSL Certificate. How? - Server Fault It is important though that you put your certificate into Remote Desktop store and make sure to grant read permissions on private key located in Personal Store to NETWORK SERVICE. Once you grant permissions run the code above in Windows PowerShell then reboot system. If cert is self signed you also need to add certificate to trusted root on host system so that it doesn't ask you to trust it. What I would like learn now is a way to convert this code to be used with Get-CimInstance instead, it seems support for this is limited.
     
    zebal, Nov 16, 2023
    #3
Thema:

Port forwarding Remote Desktop RDP and installing SSL Certificate?

Loading...
  1. Port forwarding Remote Desktop RDP and installing SSL Certificate? - Similar Threads - Port forwarding Remote

  2. Remote desktop on Mac - Windows app RDP port

    in Windows 10 Gaming
    Remote desktop on Mac - Windows app RDP port: Hi, I am interested in accessing my windows 11pro pc remotely on my apple mac using the remote desktop app "Windows APP" on my mac.I have tried this in my LAN, and it worked very well, both with the PC name, the IP, and the IP:3389 . However, when I changed the RDP port in...
  3. Remote desktop on Mac - Windows app RDP port

    in Windows 10 Software and Apps
    Remote desktop on Mac - Windows app RDP port: Hi, I am interested in accessing my windows 11pro pc remotely on my apple mac using the remote desktop app "Windows APP" on my mac.I have tried this in my LAN, and it worked very well, both with the PC name, the IP, and the IP:3389 . However, when I changed the RDP port in...
  4. RDP Self Signed Certificate 3389 Remote Desktop Protocol

    in Windows 10 Gaming
    RDP Self Signed Certificate 3389 Remote Desktop Protocol: Tenable Nessus Scans showing self signed cert used for RDP on port 3389.Done my due diligence - 1. Cert is located in certlm.msc > Remote Desktop2. You can create a custom template and generate a cert to be used for RDP and put in that folder3. Deleting the self signed - it...
  5. RDP Self Signed Certificate 3389 Remote Desktop Protocol

    in Windows 10 Software and Apps
    RDP Self Signed Certificate 3389 Remote Desktop Protocol: Tenable Nessus Scans showing self signed cert used for RDP on port 3389.Done my due diligence - 1. Cert is located in certlm.msc > Remote Desktop2. You can create a custom template and generate a cert to be used for RDP and put in that folder3. Deleting the self signed - it...
  6. Port forwarding Remote Desktop RDP and installing SSL Certificate?

    in Windows 10 Gaming
    Port forwarding Remote Desktop RDP and installing SSL Certificate?: Is it possible to install an SSL Certificate just for RDP? I have a Windows 11 system I want to safely access over the internet but I cannot find any information on this topic. Is it not possible? All I see is info on how to do it for RDS Remote Desktop Services but I am just...
  7. Port forwarding for RDP over internet issue

    in Windows 10 Software and Apps
    Port forwarding for RDP over internet issue: Hi all,I have been trying to setup port forwarding for RDP over internet. After google all the methods still unable to connect. Below are the methods I tried to debug the issue.1. I tried using the canyouseeme.org to check the port number, and it show the port is open. 2. I...
  8. Port forwarding for RDP over internet issue

    in Windows 10 Network and Sharing
    Port forwarding for RDP over internet issue: Hi all,I have been trying to setup port forwarding for RDP over internet. After google all the methods still unable to connect. Below are the methods I tried to debug the issue.1. I tried using the canyouseeme.org to check the port number, and it show the port is open. 2. I...
  9. Microsoft Native Remote Desktop Without IP or Port Forwarding

    in Windows 10 Gaming
    Microsoft Native Remote Desktop Without IP or Port Forwarding: Is there a Microsoft native way to remote into a Windows 10 or 11 machine without knowing the IP or using port forwarding? I thought I saw a feature a while back that used a Microsoft account to enable remote access to your PC if it was on and connected to the internet...
  10. SSL Certificate for Remote Desktop Session Windows 10 Pro

    in AntiVirus, Firewalls and System Security
    SSL Certificate for Remote Desktop Session Windows 10 Pro: Hello, I am attempting to utilize a signed certificate for a FQDN who's DNS records are assigned to my computers IP address. This connection is for a LAN RDS. Below are the steps that I have taken. I generated a CSR in personal certificates folder, uploaded to CA...