Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

KennyG posted:

The biggest issue is that I deploy remoteapp as part of our line of business that are consumed by people who aren't apart of our AD and do not have local permission to accept our root CA. This causes issues when they ultimately connect to our farm.
I know nothing about remoteapp, but isn't there some kind of external gateway that proxies the requests? Similar to the Access Gateway or Netscaler from Citrix.

Adbot
ADBOT LOVES YOU

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

KS posted:

.local is still a thing, but certificates for .local are rapidly becoming not a thing. CAs are not allowed to issue certs with expirations after Nov 1 2015, and will revoke all .local certs by Oct 1 2016.

Putting the Microsoft TS gateway role in front of your farm with an external URL would solve your problem.
Private, internal CAs can still issue .local certificates. PUBLIC CAs cannot.

  • Locked thread