0:06
Hello everyone. Welcome back to my
0:08
channel. In my previous videos, I
0:11
already showed you how to install
0:12
Devolutions Server and how to configure
0:15
it, how to use RDM to connect to it, and
0:18
also how to use the session recording
0:21
feature. We will go further. We are
0:24
going to make our certificate to be
0:27
trusted by this machine and we can use
0:32
advanced features such as open in
0:37
So, open in browser is one of advanced
0:40
features without installing any RDM.
0:42
Just using a browser, you should be able
0:44
to remote access to your server. I think
0:47
this is very helpful, useful features.
0:49
If you publish your RDM to the public
0:52
internet and you should be able to use
0:55
it in anywhere without installing this
0:58
sick client RDM. Now, let's jump into
1:07
So, if you open your web portal of your
1:10
Devolutions Server, then you should be
1:12
able to see this certificate is not
1:16
The reason why it's not valid is because
1:19
it's not in the trusted CA repository on
1:24
your machine. So, we have to add it in
1:28
So, let's go here. So, you will see a
1:31
certificate. The certificate is signed
1:41
which I already exported before, so we
1:44
Once you exported it, go to your
1:52
You can see this CA local certificate is
1:54
not trusted. So, that's the problem here
1:57
because it's not trusted, we can use it
2:00
on our gateway as we have to use HTTP on
2:04
our gateway, which you can see
2:07
our devolution's gateway.
2:13
We're not using HTTPS because it's not
2:15
trusted, we also cannot use
2:23
open browser this feature. Well, it will
2:26
say connection app finish. Verify your
2:30
Couldn't connect to a server. We're
2:32
going to fix all those, very simple.
2:35
Since we are here, we're going to
2:37
install certificate. We're going to
2:38
install to local machine.
2:40
We're going to install, we're going to
2:43
we can automatically select certificate
2:44
store based on the type of certificate.
2:47
Since it's a we can choose trusted CA.
2:50
We can put in here. Okay.
2:55
The import was successful.
3:06
Since now we have imported the our
3:09
certificate and then we going to go to
3:12
our IIS to take a look IIS settings for
3:16
this website. You can use in a server
3:24
tools to go to the last side
3:30
You should be able to see server
3:37
all kind of certificates
3:39
um we need to see the website which
3:42
certificate we are using.
3:44
Um you can see the SSL settings.
3:47
But that's not what we're going to do,
3:48
we're going to do add the binding by
3:50
right click on your default website, you
3:54
can see they supported port 80 and port
3:57
43, which is HTTP and HTTPS.
4:01
I'm going to edit HTTP because that's
4:03
what we're going to do. So, from here
4:05
you can see we are using
4:08
Devolutions Server as a self-signed
4:13
Actually, we're going to using this one.
4:16
Actually, we're going to using this one
4:19
after the end name we going to use to
4:22
access our website. So, we're going to
4:24
view this one and then you can see
4:26
there's no error, it's trusted
4:29
uh here. So, we can okay,
4:33
And uh we're going to restart our IIS,
4:38
After that, we're going to go back here.
4:41
We're going to refresh.
4:43
So, from refresh you can see it shows
4:45
not secure. Uh your connection to this
4:48
site isn't secure. But if we go deep and
4:51
we say, "This site has a valid
4:53
certificate issued by a trust
4:56
authority." So, we already have a valid
4:58
certificate just because of some
5:00
uh component connections on this
5:02
website, it's still not using HTTPS and
5:05
they're using HTTP. For example, we are
5:11
Devolutions Gateway. We have this HTTP
5:14
connection. So, what we can do, we can
5:17
change it to HTTPS here. And we can test
5:22
Wow, it works. Save it. Now let
5:25
exclamation mark is gone. We are getting
5:28
this nice green hello icon. Perfect.
5:31
Let's examine what we're going to do.
5:33
The next step we're going to test our
5:40
You can right click here because we
5:45
VPN Gateway using devolution gateway and
5:49
using our lab gateway which is on the
5:51
same machine. You can check health which
5:55
Save it just in case it might change
5:58
some and now we can open in browser.
6:03
Nice. So, in this way we can directly
6:08
using our web browser to remote access
6:12
to your Windows server.
6:15
They're using Island RDP protocol.
6:18
Island RDP is lost based component to do
6:23
the remote session. They are not using
6:25
Guacamole. Server is using that lots of
6:28
many other pen solution using Guacamole
6:30
but this is using Island RDP which you
6:34
can find the UI from here.
6:37
Close the session after we did this and
6:41
also you will see this little red dot
6:45
this session also been recorded.
6:52
Let's close this session.
6:56
So, once you go to recording
6:58
you can see this session.
7:01
It's still saving. It going to take a
7:02
couple minutes for this session to be
7:05
fully saved on the local. Once you're
7:07
done, you can play the recording.
7:11
So, that's the old recording we had it
7:15
which is works well. You can see
7:18
and this is a new one. Let's see if we
7:20
can play with it. No.
7:22
It seems it still shows live because the
7:27
Uh it won't be able to let you play
7:29
until a couple minutes passed. The whole
7:34
open your remote session
7:37
through your browser without having RTM.
7:45
Now, let's go back to the Linux server.
7:48
So, we can uh from Windows server to
7:51
Linux. From here, right click, you can
7:53
see the open in browser. This menu is
7:56
grayed out. The reason why is because we
8:00
haven't configured the gateway for it
8:02
yet. So, we do that we using
8:10
And they automatically choose a default
8:12
gateway for you. Update that.
8:16
Once you did that, you can
8:19
easily get this option open in browser.
8:23
Okay, now we need to do authentication.
8:26
We haven't the same authentication code.
8:31
Perfect. It's working well.
8:38
Right now, you don't see the the red dot
8:41
on Linux because we haven't enabled
8:52
And right click, property.
8:55
This is simplified view. Let's get a
8:58
full view, session recording.
9:01
Of course, we can do the
9:05
And the recording going to be the
9:06
remote. We going to using the gateway
9:09
mode, it going to be same as session.
9:12
Now, let's try opening browser again.
9:19
Now, we got this nice dot here.
9:23
That means it's recorded. We can close
9:28
and see the recording. It shows live.
9:31
So, this is for self-signed certificate.
9:35
But if you want to use
9:38
your own say, you're going to install a
9:41
certificate service. In the next
9:43
session, I will show you how to install
9:45
your own certificate service on your
9:48
list machine. That is just for you to
9:51
deploy your own CA server and you can
9:55
use it in other machines for joining
10:03
In this case, we're going to install
10:08
role for this server.
10:12
We're going to choose AD certificate
10:27
We're going to install certificate in
10:28
role and web service.
10:41
It will take a while, so I'm going to
10:44
Once it's done, we will continue.
10:48
So, the certificate service has been
10:50
installed. Now, we need to do some
10:51
configuration. You will see exclamation
10:54
mark here. So, let's post deployment
10:59
Let's configure that.
11:05
So, let's finish CA setup first.
11:10
This is our root CA. Create a new
11:36
We can enable certificate enrollment web
11:50
Use in the building application pool.
12:00
This video shows you how to make
12:03
yourself signed certificate to be trust
12:09
And then how to configure open in
12:12
browser this feature in your target
12:16
either Linux or either Windows. At the
12:19
same time, make sure the session
12:21
recording works well with this open in
12:25
browser feature. I hope you learn
12:26
something from this video and give me
12:29
some love if you like this video. Also,
12:32
subscribe my channel to support me.
12:34
Thank you for your watching. See you in