I commented under issue #4337 but since that is closed I suspect that will go unnoticed.
When attempting to connect to a connection that has worked in the past using remmina, I now suddenly got a generic "Could not establish RDP connection" error message.
In order to dig a little deeper and hopefully get a better error message I decided to install freerdp from the repository and attempt to connect using xfreerdp. This also failed. I even tried adding the nightly build repo and use that, and build from source, but that also failed. The message I'm getting currently (using nightly build) is this:
[20:43:11:219] [22406:22407] [INFO][com.freerdp.core.gateway.rdg] - RD Gateway does not support HTTP transport.
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.rpc] - error! Status Code: 401
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - HTTP/1.1 401 Unauthorized
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - Content-Type: text/plain
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - Server: Microsoft-IIS/7.5
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - WWW-Authenticate: Negotiate
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - WWW-Authenticate: NTLM
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - WWW-Authenticate: Basic
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - X-Powered-By: ASP.NET
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - Date: Sun, 05 Aug 2018 18:43:11 GMT
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.http] - Content-Length: 13
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core] - freerdp_set_last_error ERRCONNECT_AUTHENTICATION_FAILED [0x00020009]
[20:43:11:426] [22406:22407] [ERROR][com.freerdp.core.gateway.tsg] - tsg_check failure
Any ideas?
Worth mentioning that I have no issues connecting using mstsc from windows.
Commandline please? Looks like you use the wrong gateway parameters, try /gt: options
Thanks,
I tried several mutations of the command line, /gt did not seem to do anything.
I was however able to connect when using both the /gd and the /d parameter. I had first used them only as part of the /u and /gu parameter (DOMAIN\user). Setting them explicitly seems to work.
So now I'm able to connect through xfreerdp. That still leaves my issues with Remmina, but I assume this is the wrong place to report that
Glad to hear. Well, then closing as resolved.
@akallabeth Sorry to comment on this closed issue.
I'm trying to fix this problem in Remmina, but I cannot even connect with xfreerdp.
xfreerdp /g:GWHOST /gd:GEDOMAIN /gu:GWUSER /gp:GWPASSWD /v:DSTHOST
[18:18:42:391] [364:365] [INFO][com.freerdp.client.common.cmdline] - loading channelEx cliprdr
[18:18:42:391] [364:365] [INFO][com.freerdp.client.x11] - No user name set. - Using login name: tmow
[18:18:42:423] [364:365] [INFO][com.freerdp.client.x11] - Property 452 does not exist
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.rpc] - error! Status Code: 401
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.http] - HTTP/1.1 401 Unauthorized
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.http] - Content-Type: text/plain
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.http] - Server: Microsoft-IIS/7.5
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.http] - WWW-Authenticate: Basic
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.http] - WWW-Authenticate: Negotiate
[18:18:44:833] [364:365] [ERROR][com.freerdp.core.gateway.http] - WWW-Authenticate: NTLM
[18:18:44:834] [364:365] [ERROR][com.freerdp.core.gateway.http] - X-Powered-By: ASP.NET
[18:18:44:834] [364:365] [ERROR][com.freerdp.core.gateway.http] - Date: Tue, 04 Sep 2018 16:18:44 GMT
[18:18:44:834] [364:365] [ERROR][com.freerdp.core.gateway.http] - Content-Length: 13
[18:18:44:834] [364:365] [ERROR][com.freerdp.core] - freerdp_set_last_error ERRCONNECT_AUTHENTICATION_FAILED [0x00020009]
[18:18:44:834] [364:365] [ERROR][com.freerdp.core.gateway.tsg] - tsg_check failure
This is FreeRDP version 2.0.0-dev4 (25e2ab1c0)
Build configuration: BUILD_TESTING=OFF BUILTIN_CHANNELS=ON HAVE_AIO_H=1 HAVE_EXECINFO_H=1 HAVE_FCNTL_H=1 HAVE_INTTYPES_H=1 HAVE_JOURNALD_H=TRUE HAVE_MATH_C99_LONG_DOUBLE=1 HAVE_POLL_H=1 HAVE_PTHREAD_MUTEX_TIMEDLOCK=ON HAVE_PTHREAD_MUTEX_TIMEDLOCK_LIB=1 HAVE_PTHREAD_MUTEX_TIMEDLOCK_SYMBOL= HAVE_SYSLOG_H=1 HAVE_SYS_EVENTFD_H=1 HAVE_SYS_FILIO_H= HAVE_SYS_MODEM_H= HAVE_SYS_SELECT_H=1 HAVE_SYS_SOCKIO_H= HAVE_SYS_STRTIO_H= HAVE_SYS_TIMERFD_H=1 HAVE_TM_GMTOFF=1 HAVE_UNISTD_H=1 HAVE_XI_TOUCH_CLASS=1 WITH_ALSA=ON WITH_CCACHE=ON WITH_CHANNELS=ON WITH_CLANG_PROFILING=off WITH_CLIENT=ON WITH_CLIENT_AVAILABLE=1 WITH_CLIENT_CHANNELS=ON WITH_CLIENT_CHANNELS_AVAILABLE=1 WITH_CLIENT_COMMON=ON WITH_CLIENT_INTERFACE=OFF WITH_CUPS=on WITH_DEBUG_ALL=OFF WITH_DEBUG_CAPABILITIES=OFF WITH_DEBUG_CERTIFICATE=OFF WITH_DEBUG_CHANNELS=OFF WITH_DEBUG_CLIPRDR=OFF WITH_DEBUG_DVC=OFF WITH_DEBUG_KBD=OFF WITH_DEBUG_LICENSE=OFF WITH_DEBUG_MUTEX=OFF WITH_DEBUG_NEGO=OFF WITH_DEBUG_NLA=OFF WITH_DEBUG_NTLM=OFF WITH_DEBUG_RAIL=OFF WITH_DEBUG_RDP=OFF WITH_DEBUG_RDPDR=OFF WITH_DEBUG_RDPEI=OFF WITH_DEBUG_REDIR=OFF WITH_DEBUG_RFX=OFF WITH_DEBUG_RINGBUFFER=OFF WITH_DEBUG_SCARD=OFF WITH_DEBUG_SND=OFF WITH_DEBUG_SVC=OFF WITH_DEBUG_SYMBOLS=OFF WITH_DEBUG_THREADS=OFF WITH_DEBUG_TIMEZONE=OFF WITH_DEBUG_TRANSPORT=OFF WITH_DEBUG_TSG=OFF WITH_DEBUG_TSMF=OFF WITH_DEBUG_WND=OFF WITH_DEBUG_X11=OFF WITH_DEBUG_X11_CLIPRDR=OFF WITH_DEBUG_X11_LOCAL_MOVESIZE=OFF WITH_DEBUG_XV=OFF WITH_DIRECTFB=OFF WITH_DSP_EXPERIMENTAL=OFF WITH_DSP_FFMPEG=OFF WITH_EVENTFD_READ_WRITE=1 WITH_FAAC=OFF WITH_FAAD2=OFF WITH_FFMPEG=TRUE WITH_FFMPEG=TRUE WITH_GFX_H264=ON WITH_GPROF=OFF WITH_GSM=OFF WITH_GSSAPI=OFF WITH_GSTREAMER_0_10=OFF WITH_GSTREAMER_1_0=ON WITH_ICU=OFF WITH_IPP=OFF WITH_JPEG=OFF WITH_LAME=OFF WITH_LIBRARY_VERSIONING=ON WITH_LIBSYSTEMD=ON WITH_MACAUDIO=OFF WITH_MACAUDIO=OFF WITH_MACAUDIO_AVAILABLE=0 WITH_MANPAGES=yes WITH_MBEDTLS=OFF WITH_OPENH264=OFF WITH_OPENSLES=OFF WITH_OPENSSL=ON WITH_OSS=ON WITH_PCSC=OFF WITH_PROFILER=OFF WITH_PULSE=on WITH_SAMPLE=OFF WITH_SANITIZE_ADDRESS=OFF WITH_SANITIZE_ADDRESS_AVAILABLE=1 WITH_SANITIZE_LEAK=OFF WITH_SANITIZE_MEMORY=OFF WITH_SANITIZE_MEMORY_AVAILABLE=1 WITH_SANITIZE_THREAD=OFF WITH_SANITIZE_THREAD_AVAILABLE=1 WITH_SERVER=OFF WITH_SERVER_INTERFACE=ON WITH_SMARTCARD_INSPECT=OFF WITH_SSE2=ON WITH_THIRD_PARTY=OFF WITH_VALGRIND_MEMCHECK=OFF WITH_VALGRIND_MEMCHECK_AVAILABLE=1 WITH_WAYLAND=off WITH_X11=ON WITH_X264=OFF WITH_XCURSOR=ON WITH_XEXT=ON WITH_XFIXES=ON WITH_XI=ON WITH_XINERAMA=ON WITH_XKBFILE=ON WITH_XRANDR=ON WITH_XRENDER=ON WITH_XSHM=ON WITH_XV=ON WITH_ZLIB=ON
Build type: Debug
CFLAGS: -fPIC -Wall -Wno-unused-result -Wno-unused-but-set-variable -Wno-deprecated-declarations -fvisibility=hidden -Wimplicit-function-declaration -Wredundant-decls -g
Compiler: GNU, 8.1.1
Target architecture: x64
What else I can provide to debug?
@antenore does specifying /gt:
@akallabeth I've tried with rpc and it didn't help, but I haven't tried with http yet, should I?
@antenore might. Depends on your setup. If not I'll have a look at it
@akallabeth no, with http it doesn't
If you can help yes, I'll appreciate it, also because I don't know that much where to look. The error message it's quite generic, so it's hard to understand where is the problem.
Don't hesitate to ping me for any tests and if you need access to that gateway let me know, I'll see with the owner, but it should be feasible (maybe drop me an email in that case).
Thanks!!!!
[21:28:54:622] [17510:17511] [INFO][com.freerdp.client.common.cmdline] - loading channelEx cliprdr
[21:28:54:622] [17510:17511] [INFO][com.freerdp.client.x11] - No user name set. - Using login name: tmow
[21:28:54:656] [17510:17511] [INFO][com.freerdp.client.x11] - Property 452 does not exist
[21:28:55:881] [17510:17511] [INFO][com.freerdp.core.gateway.rdg] - RD Gateway does not support HTTP transport.
[21:28:55:881] [17510:17511] [ERROR][com.freerdp.core.nego] - Protocol Security Negotiation Failure
[21:28:55:881] [17510:17511] [ERROR][com.freerdp.core] - freerdp_set_last_error ERRCONNECT_SECURITY_NEGO_CONNECT_FAILED [0x0002000C]
[21:28:55:881] [17510:17511] [ERROR][com.freerdp.core.connection] - Error: protocol security negotiation or connection failure
@antenore ok, looks like you have a configuration still not working :/
Well, then... Could you post the output with log-level debug or is it possible to connect with a demo account to the system?
@antenore Just a small question, your command line only contains user, domain and password for the gateway, is the host reachable without authentication?
@akallabeth I'm asking to share the user with you.
I think the host is not reachable.
We have a couple of issues opened for the same error, so I've asked a test account on an RD gateway (no need to access directhly the server).
One of them provided me an RD gateway with user and password to test, but no access to the final destination (we don't have an account) and I think it's probably behind a firewall.
@akallabeth I've added you to the Remmina member on GitLab and created a snippet that only us (the members) can see, with those server/user/password to test.
@antenore ok, checking. really interested in what is going wrong.
@antenore Ok, have at least the place it fails.
The outgoing tls connection can not be authenticated (the incoming seems to work fine though)
@akallabeth I see the certificate is multi-domain (with * in the hostname), may be an issue somehow?
No, we use openssl validation and/or pinning. It fails after the tls connection is established and the ntlm tokens are exchanged
@antenore Are you sure the setup works? Connecting with mstsc yields the same error (authentication failed on gateway)
@akallabeth it's what the dude who gave us this gw have told me. I'm going to ask.
He have tested with mstsc and it works. He highlighted that we don't have access to the final windows server, but only on the RDP gateway. If needed he can give us the rights for that server as well.
@antenore looks like a tough one, could not find anything wrong with the message sequence, might be some byte / lenght is off, but couldn't spot that so far :/
@akallabeth I see... If I can do anything let me know, and obviously no rush (as usual)
@antenore Currently working on #4843 maybe I'll accidentally fix it while refactoring :)
Ah! Really cool !
@antenore Just a little question, during debugging the server announces NTLM, Basic and Negociate authentication method support.
We currently only try NTLM, is this allowed by the server?
@akallabeth I'll ask. In the meanwhile I've tried with another GW server and I was able to connect to it with Remmina.
On our side the Gateway Transport Type was not fully implemented, and now it works as expected.
I'll come back to you with the answer to your question. Thanks!
Hey @akallabeth a good news, the issues seems to be solved, you can close this.
Regarding the reason why it works, we really don't have any clues...
Thanks a lot for your support!
This worked for me:
xfreerdp /gt:http /sec:tls /v:server.company.com /u:me@company \
/p:'NLMw&h5i23f' /g:gateway.company.com /cert-ignore \
/auto-reconnect-max-retries:0 /log-level:info &>> ~/xfreerdp.log &
We use a Microsoft Windows Active-Directory setup with RDP Gateway over https (/gt:http), so it makes sense to use TLS security.
This worked for me:
xfreerdp /gt:http /sec:tls /v:server.company.com /u:me@company \ /p:'NLMw&h5i23f' /g:gateway.company.com /cert-ignore \ /auto-reconnect-max-retries:0 /log-level:info &>> ~/xfreerdp.log &We use a Microsoft Windows Active-Directory setup with RDP Gateway over
https(/gt:http), so it makes sense to useTLSsecurity.
@seanw2020 Please make sure that's not your real world password getting leaked.