Chapter 11. Connecting to Windows Terminal Servers
11.1. Introduction
This chapter describes how to connect to Windows Terminal Servers via RDP. This makes it possible to
provide ThinLinc users with Windows desktops, but also to publish individual Windows applications to a
ThinLinc desktop, running on Linux or Solaris.
It is also possible to connect to Citrix servers by installing the Citrix ICA Client on the ThinLinc servers.
In this case, the ThinLinc commands tl-wfica and tl-wfcmgr can be used to provide Single Sign-On. For
more information about tl-wfica and tl-wfcmgr, see Chapter 13.
11.2. Single Sign-On
11.2.1. Information
ThinLinc provides Single Sign-On functionality into the Windows Terminal Server using either password
or smart card authentication. It is required that your ThinLinc servers are integrated with your Windows
infrastructure so that user authentication shares the same source on both Windows and ThinLinc.
If requirements mentioned above are met, Single Sign-On works out of the box with one exception
regarding smart card and CredSSP which is documented in the following section.
11.2.2. Smart card
If you want to use smart card Single Sign-On using Windows 2003 you need to install wtstools package
with our ThinLinc GINA. See Section 3.7 for more information.
Windows 2008 (RDP v6) and later does not require the mentioned GINA for using smart card SSO
authentication.
If your Windows Terminal Server is configured to explicitly only allow CredSSP authentication level,
ThinLinc needs to know a provide name for your smart card Crypto Service Provider (CSP). The
provider name is configured per application server group and is added to rdesktop_args configuration
value like the example below. See Section 14.2.4 for more information.
rdesktop_args=-o sc-csp-name="CSP Provider Name",
To obtain the provider name of your Crypto Service Provider (CSP) make sure that your smart card
driver are installed on your Windows Terminal Server. Open regedit and find the following registry key,
HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider. In this container you will find
a list of CSP providers registered with the system, find the matching provider for your smartcard and use
the key name as the CSP Provider Name.
11.3. Connection Modes
This section describes the different connection modes, and lists their limitations.
125
Kommentare zu diesen Handbüchern