<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://192.168.2.20/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SBS 2003</title><link>http://192.168.2.20/forums/7.aspx</link><description /><dc:language /><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Re: TLS/FIPS for Terminal Services and RWW in SBS 2003</title><link>http://192.168.2.20/forums/thread/5857.aspx</link><pubDate>Tue, 19 Feb 2008 00:19:30 GMT</pubDate><guid isPermaLink="false">72050d9c-4f41-4a16-9f70-ebbf2c98a2c7:5857</guid><dc:creator>David Overton</dc:creator><slash:comments>0</slash:comments><comments>http://192.168.2.20/forums/thread/5857.aspx</comments><wfw:commentRss>http://192.168.2.20/forums/commentrss.aspx?SectionID=7&amp;PostID=5857</wfw:commentRss><description>&lt;p&gt;Mark,&lt;/p&gt;
&lt;p&gt;working for Microsoft means that asking the questions is quite easy for me &lt;img src="http://uksbsguy.com/emoticons/emotion-5.gif" alt="Wink 2" /&gt;.&amp;nbsp; Note that the client to the web site is secure and the RDP protcol is not in clear.&amp;nbsp; TLS cannot be used due to the fact that there is a proxy between the client and the server (RWW).&amp;nbsp; Information about security can be found at &lt;a href="http://technet2.microsoft.com/WindowsServer/en/library/a92d8eb9-f53d-4e86-ac9b-29fd6146977b1033.mspx?mfr=true"&gt;http://technet2.microsoft.com/WindowsServer/en/library/a92d8eb9-f53d-4e86-ac9b-29fd6146977b1033.mspx?mfr=true&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you are really, really concerned about security and to avoid spoofing, then VPN into the network 1st.&amp;nbsp; Of, you might find future versions of SBS don&amp;#39;t have this problem [;-]&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;ttfn&lt;/p&gt;
&lt;p&gt;David&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: TLS/FIPS for Terminal Services and RWW in SBS 2003</title><link>http://192.168.2.20/forums/thread/5852.aspx</link><pubDate>Mon, 18 Feb 2008 14:07:25 GMT</pubDate><guid isPermaLink="false">72050d9c-4f41-4a16-9f70-ebbf2c98a2c7:5852</guid><dc:creator>wigital</dc:creator><slash:comments>0</slash:comments><comments>http://192.168.2.20/forums/thread/5852.aspx</comments><wfw:commentRss>http://192.168.2.20/forums/commentrss.aspx?SectionID=7&amp;PostID=5852</wfw:commentRss><description>&lt;p&gt;Thanks David&lt;/p&gt;
&lt;p&gt;Yes.. I did assume the use of TSWEB. I figured Microsoft would re-use code and I knew of no other way to access Terminal Services through the browser.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thanks for taking the time to call Microsoft. The phone call is way more than I expected. I also appreciate the clarity on the response.&lt;/p&gt;
&lt;p&gt;If I understand the implications of your post, even though the logon to RWW is secured using SSL... both the authentication to TS and the TS session that result from using the Connect to Server Desktop link are potentially&amp;nbsp;*quite literally* &lt;strong&gt;unsecured&lt;/strong&gt; (as the wrapper indicates).&amp;nbsp;The&amp;nbsp;question is: does this Proxy session launch some sort of RPC over HTTP type connection outside the context of RWW SSL session? I note (in your reply)&amp;nbsp;that it is invoked using the same worker process but I&amp;#39;m not at all clear if the resulting traffic is still being routed via Port 443 HTTPS and then hitting the Terminal. The client is (after all things) given another logon screen for the Terminal???&lt;/p&gt;
&lt;p&gt;Personally, I&amp;nbsp;will be utilizing a direct RDP connection TLS/FIPS instead of RWW to&amp;nbsp;Connect to Server Desktop. &lt;/p&gt;
&lt;p&gt;Thanks so much for your excellent response. Nice to meet you BTW&lt;/p&gt;
&lt;p&gt;warm regards,&lt;br /&gt;Mark&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: TLS/FIPS for Terminal Services and RWW in SBS 2003</title><link>http://192.168.2.20/forums/thread/5850.aspx</link><pubDate>Sun, 17 Feb 2008 21:25:17 GMT</pubDate><guid isPermaLink="false">72050d9c-4f41-4a16-9f70-ebbf2c98a2c7:5850</guid><dc:creator>David Overton</dc:creator><slash:comments>0</slash:comments><comments>http://192.168.2.20/forums/thread/5850.aspx</comments><wfw:commentRss>http://192.168.2.20/forums/commentrss.aspx?SectionID=7&amp;PostID=5850</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Things are never as simple as they seem.&amp;nbsp; You are assuming that there are not some custom written components at work here, which there are.&amp;nbsp; When I asked internally I was told (para-phrased):&lt;/p&gt;&lt;span style="FONT-SIZE:11pt;COLOR:#1f497d;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;The problem is that the assumption is that we are using tsweb, and we are not.&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;"&gt;&lt;span style="FONT-SIZE:11pt;COLOR:#1f497d;FONT-FAMILY:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;Although&amp;nbsp; from a client perspective they get the RDP control (same as tsweb), behind the scenes its connecting to our RWW proxy code running within the worker process, thus, the client running on the customer’s browser is not actually ever talking to the RDP server on the destination, there is a layer in the middle. It is probable that this was never part of the design goals.&amp;nbsp; This should not an issue in the future.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
&lt;p&gt;The short answer is that SBS &amp;amp; FIPS for the web RDP client do not mix.&lt;/p&gt;
&lt;p&gt;I hope this helps, even if it is not the answer you wanted.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;ttfn&lt;/p&gt;
&lt;p&gt;David&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>TLS/FIPS for Terminal Services and RWW in SBS 2003</title><link>http://192.168.2.20/forums/thread/5830.aspx</link><pubDate>Wed, 13 Feb 2008 16:46:32 GMT</pubDate><guid isPermaLink="false">72050d9c-4f41-4a16-9f70-ebbf2c98a2c7:5830</guid><dc:creator>wigital</dc:creator><slash:comments>0</slash:comments><comments>http://192.168.2.20/forums/thread/5830.aspx</comments><wfw:commentRss>http://192.168.2.20/forums/commentrss.aspx?SectionID=7&amp;PostID=5830</wfw:commentRss><description>&lt;p&gt;Hi David,&lt;br /&gt;&amp;nbsp;&lt;br /&gt;I had a question about connect to Server desktop through the RWW&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Two methods to connect in SBS using Terminal Services for Remote Administration&lt;br /&gt;1 - Terminal Services RDP 3389&lt;br /&gt;2 - connect to Server desktop (which uses tsweb through the Remote Web Workplace)&lt;br /&gt;&amp;nbsp;&lt;br /&gt;In experimenting with SBS Remote Administration I discovered an unusual circumstance in which you CANNOT set the Terminal Services Connection to TLS/FIPS compliant encryption and still access the SBS computer through RWW.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;So to explain:&lt;br /&gt;*I used Terminal Services Configuration&lt;br /&gt;*loaded a certificate&lt;br /&gt;*in the Terminal Services Connection Properties, General TAB:&lt;br /&gt;**Set Security Layer to SSL&lt;br /&gt;**Set Encryption Level to FIPS compliant&lt;br /&gt;&amp;nbsp;&lt;br /&gt;NOW... connecting to the SBS server using RWW connect to Server Desktop does not work&lt;br /&gt;&amp;nbsp;&lt;br /&gt;SOLUTION... in the above walkthrough, change Security Layer to NEGOTIATE. This allowed the RWW session to negotiate it&amp;#39;s own encryption level without affecting connections using Terminal Services Client RDP/RDC on 3389 directly. Remote Desktop Connections can still be made over 3389 and they are secure (you see the little lock symbol). With RDP/RDC, the certificate can be viewed and believe RDC 6.0 negotiates highest possible encryption.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;My question is this:&lt;br /&gt;&amp;nbsp;&lt;br /&gt;When connecting to Server desktop using RWW, the wrapper indicates there is no encryption what-so-ever. (i.e. No LOCK symbol, no certificate can be viewed, etc...) DOES TSWEB THROUGH THE RWW WEBSITE USE A CERTIFICATE AND NOT INDICATE THAT -OR- DOES IT LAUNCH A CONNECTION ON PORT 3389 FROM THE RWW INTERFACE USING TSWEB, AND!!! IS THIS CONNECTION UN-ENCRYPTED?&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Thanks,&lt;br /&gt;wigital&lt;br /&gt;&amp;nbsp;&lt;br /&gt;PS.. made a blog entry on the subject here&lt;br /&gt;&lt;a href="http://wintivity.wigital.net/?p=14"&gt;http://wintivity.wigital.net/?p=14&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;PPS.. thanks for the blog post about &lt;a href="http://wigital.spaces.live.com/"&gt;the live space&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>