ISS RDP Site still showing insecure after cert issued

Al Grant 1 Reputation point
2023-01-28T19:18:31.6233333+00:00

I have gone and got a certificate for *.contoso.com and [contoso.com] . I have installed it against the default website on windows server IIS.

I am now browsing (using the same server) to https://dc1.internal.contoso.com/RDWeb/Pages/en-US/login.aspx and are still getting a message before the site loads that it is insecure.

If I look at the details of this message in the browser it says cerificate is not valid. The issuer is LetsEncrypt R3, and it is issued to *.contoso.com.

What am I doing wrong?

Internet Information Services
.NET
.NET
Microsoft Technologies based on the .NET software framework.
3,362 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,234 questions
{count} votes

2 answers

Sort by: Most helpful
  1. TP 75,296 Reputation points
    2023-01-28T19:40:43.8633333+00:00

    Hi,

    A wildcard certificate only covers one level of subdomains. For example, a *.contoso.com certificate would cover remote.contoso.com, apps.contoso.com, gateway.contoso.com, etc., but would not cover remote.internal.contoso.com or myapp.internal.contoso.com because those are at different level.

    So what you need to do is have your server FQDN be directly under contoso.com OR get another wildcard certificate for *.internal.contoso.com.

    If the above was helpful, please click Accept Answer. If something isn't clear please ask in a comment.

    Thanks.

    -TP

    1 person found this answer helpful.

  2. guig3 0 Reputation points
    2023-02-09T17:53:12.59+00:00

    Thanks a lot, this answer helped me too

    0 comments No comments