[THIN] Win2012 RDS - digitally sign a RemoteApp?

  • From: Michael Leone <oozerdude@xxxxxxxxx>
  • To: thin@xxxxxxxxxxxxx
  • Date: Fri, 18 Oct 2013 13:04:40 -0400

I have set up a couple of  Win2012 servers with RDS - one session
host, one web access host. (these are virtual machines, running on
VMware ESXi 5.1). I have published some apps (following example web
tutorials, I have published WordPad, NotePad, etc as RemoteApps). When
accessing this server with a web browser and log in, and then clicking
on one of these RemoteApps, I get a warning:

A website is trying to run a RemoteApp program. The publisher of this
RemoteApp program can't be identified.

All the tutorials I've found speak of Win2008 R2, and using the
RemoteApp Manager program to digitally sign an app. However, this
apparently doesn't exist anymore in Win 2012, and I haven't been able
to determine what has replaced it. I have found references to 3 GPO
settings I can change, to trust unsigned apps, but nothing on how to
actually sign the app itself.

Can anyone point out where I am going wrong, and what the path to the
right way is? :-) I can probably make those 3 GPO changes, but if
there's another way, I'd prefer that. Each of my Win2012 servers has
our own self-published certificates, if that is what is needed to sign
an app. Or I can create a cert to use to sign the app (we have our own
Linux box, with our own Certificate Authority set up).

Thanks. Soon I will have the (what will be the actual production) app
I will be using. (this is all a proof-of-concept, at the moment. When
it's ready, I will make an actual test environment. Then a production
environment).
************************************************
For Archives, RSS, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link:
//www.freelists.org/list/thin
************************************************

Other related posts: