Configuring Remote Desktop Features

Table Of Contents
Table 524. RDS Security Group Policy Settings
Setting Description
Server Authentication Certificate Template
Use this policy setting to specify the name of the certificate
template that determines which certificate is automatically selected
to authenticate an RDS host.
A certificate is needed to authenticate an RDS host when SSL (TLS
1.0) is used to secure communication between a client and an RDS
host during RDP connections.
If you enable this policy setting, you need to specify a certificate
template name. Only certificates created by using the specified
certificate template will be considered when a certificate to
authenticate the RDS host is automatically selected. Automatic
certificate selection only occurs when a specific certificate has not
been selected.
If no certificate can be found that was created with the specified
certificate template, the RDS host will issue a certificate enrollment
request and will use the current certificate until the request is
completed. If more than one certificate is found that was created
with the specified certificate template, the certificate that will expire
latest and that matches the current name of the RDS host will be
selected.
If you disable or do not configure this policy setting, a self-signed
certificate will be used by default to authenticate the RDS host. You
can select a specific certificate to be used to authenticate the RDS
host on the General tab of the Remote Desktop Session Host
Configuration tool.
Note If you select a specific certificate to be used to authenticate
the RDS host, that certificate will take precedence over this policy
setting.
Set client connection encryption level
Specifies whether to require the use of a specific encryption level to
secure communications between clients and RDS hosts during
Remote Desktop Protocol (RDP) connections.
If you enable this setting, all communications between clients and
RDS hosts during remote connections must use the encryption
method specified in this setting. By default, the encryption level is
set to High. The following encryption methods are available:
n
High. The High setting encrypts data sent from the client to the
server and from the server to the client by using strong 128-bit
encryption. Use this encryption level in environments that
contain only 128-bit clients (for example, clients that run
Remote Desktop Connection). Clients that do not support this
encryption level cannot connect to RDS host servers.
n
Client Compatible. The Client Compatible setting encrypts
data sent between the client and the server at the maximum
key strength supported by the client. Use this encryption level in
environments that include clients that do not support 128-bit
encryption.
n
Low. The Low setting encrypts only data sent from the client to
the server using 56-bit encryption.
Configuring Remote Desktop Features in Horizon 7
VMware, Inc. 191