RPC over HTTPS for Terminal Services Gateway

View: New views
2 Messages — Rating Filter:   Alert me  

RPC over HTTPS for Terminal Services Gateway

by Andreas Adler :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi there

I am running Squid 3.0 PRE6 as a reverse proxy for many applications and services. RPC over HTTPS for Exchange/OWA is running fine for a long time. Recently I tried to pass the TS Gateway through Squid, but this is giving me a very hard time. TS Gateway is using RPC over HTTPS just like Exchange does, but I always get  an authentication error. Here is what I get:

--
TCP_MISS/401 399 RPC_IN_DATA https://server.domain.com/rpc/rpcproxy.dll? - FIRST_UP_PARENT/server.domain.com text/plain
--

Here is my access rule:
cache_peer server.domain.com parent 443 0 proxy-only no-query originserver front-end-https=on ssl login=PASS sslflags=DONT_VERIFY_PEER

Does anybody run a Terminal Services Gateway (TS Gateway) being proxied through squid?  Could there be something wrong with some NTLM passthrough? I am pretty clueless on this, so any help is very appreciated!

Thanks a lot!
Andreas Adler

Parent Message unknown Re: RPC over HTTPS for Terminal Services Gateway

by Guido Serassio :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi,

At 10.23 24/11/2008, Andreas Adler wrote:

>Hi there
>
>I am running Squid 3.0 PRE6 as a reverse proxy for many applications
>and services. RPC over HTTPS for Exchange/OWA is running fine for a
>long time. Recently I tried to pass the TS Gateway through Squid,
>but this is giving me a very hard time. TS Gateway is using RPC over
>HTTPS just like Exchange does, but I always get  an authentication
>error. Here is what I get:
>
>--
>TCP_MISS/401 399 RPC_IN_DATA
>https://server.domain.com/rpc/rpcproxy.dll? -
>FIRST_UP_PARENT/server.domain.com text/plain
>--
>
>Here is my access rule:
>cache_peer server.domain.com parent 443 0 proxy-only no-query
>originserver front-end-https=on ssl login=PASS sslflags=DONT_VERIFY_PEER
>
>Does anybody run a Terminal Services Gateway (TS Gateway) being
>proxied through squid?  Could there be something wrong with some
>NTLM passthrough? I am pretty clueless on this, so any help is very
>appreciated!

I never tested TS Gateway on Squid, but usually Exchange RPC over
HTTPS works better using Basic authentication over SSL.

Another thing to verify is the Reverse Proxy SSL certificate: using
self signed certificates for Echange RPC over HTTPS, Outlook fails
silently if the CA is not trusted.

Regards

Guido


>Thanks a lot!
>Andreas Adler


-
========================================================
Guido Serassio
Acme Consulting S.r.l. - Microsoft Certified Partner
Via Lucia Savarino, 1           10098 - Rivoli (TO) - ITALY
Tel. : +39.011.9530135  Fax. : +39.011.9781115
Email: guido.serassio@...
WWW: http://www.acmeconsulting.it/