From d5a968adfef8fa63d95d2823305824ca6a69ca12 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C5=81ukasz=20Koz=C5=82owski?= Date: Mon, 8 Aug 2022 23:03:23 +0200 Subject: [PATCH] Add "RDP connection fail" section to desktop access troubleshooting docs (#13059) --- docs/pages/desktop-access/troubleshooting.mdx | 33 ++++++++++++++----- 1 file changed, 25 insertions(+), 8 deletions(-) diff --git a/docs/pages/desktop-access/troubleshooting.mdx b/docs/pages/desktop-access/troubleshooting.mdx index 131b4835c76..4e941f09d46 100644 --- a/docs/pages/desktop-access/troubleshooting.mdx +++ b/docs/pages/desktop-access/troubleshooting.mdx @@ -7,7 +7,7 @@ Common issues and resolution steps. ## Auto-login does not work -### Smart Card Service Not Running +### Smart card service not running You connect to a Windows host from the Teleport UI, land on the Windows login screen and nothing happens. @@ -32,7 +32,7 @@ If the "Smart Card" service is not running, open PowerShell and run `gpupdate.exe /force`. This forces a Group Policy sync and should pick up the service changes. -### Smart Card Certificate Not Trusted +### Smart card certificate not trusted You connect to a Windows host from the Teleport UI, land on the Windows login screen and see an error message: **"The smartcard certificate used for @@ -74,9 +74,9 @@ the new CA. ## New session "hangs" -### Host Unreachable +### Host unreachable -You click `CONNECT` on a Windows host from the Teleport UI, a new tab opens but +You click `CONNECT` on a Windows host from the Teleport UI, and a new tab opens, but nothing is displayed other than the top bar. After a while, an error is displayed about a failed connection. @@ -95,7 +95,7 @@ from the Linux server that runs `windows_desktop_service`. If the host is online but not reachable, there is some other networking barrier in the way, specific to your infrastructure. -### Hostname Does Not Resolve +### Hostname does not resolve Connections to Windows Desktops hang during connection establishment, or the Teleport debug logs show errors of the form @@ -111,9 +111,26 @@ Ensure that your firewalls allow inbound DNS traffic on port `53` from the instance(s) running Teleport's Windows Desktop Service to the LDAP server (Active Directory Domain Controller). +### RDP connection failed + +You click `CONNECT` on a Windows host from the Teleport UI, a new tab opens but +nothing is displayed other than the top bar. You see an error that refers to a +failed RDP connection. You may also see errors similar to: + +```text +Rdp(Io(Os { code: 54, kind: ConnectionReset, message: "Connection reset by peer" })) +``` + +**Solution:** Configure a certificate for RDP connections + +This means that the desktop does not support secure cipher suites for TLS +connections. + +Make sure that you [configure a certificate for RDP connections](./getting-started.mdx#step-47-configure-a-certificate-for-rdp-connections). + ## Teleport fails to start -### Incorrect Domain +### Incorrect domain Teleport fails to start with an error similar to: @@ -128,7 +145,7 @@ LDAP Result Code 10 "Referral": 0000202B: RefErr: DSID-0310082F, data 0, 1 acces This means that your domain name is likely wrong. Double-check the `domain` field in the `ldap` section of `windows_desktop_service`. -### Domain Controller Unreachable +### Domain controller unreachable Teleport fails to start with an error similar to: @@ -143,7 +160,7 @@ This means that your Domain Controller is down or unreachable. Double-check the correct, check that the Domain Controller is up and reachable from the server that runs `windows_desktop_service`. -### Cannot Initialize LDAP over TLS +### Cannot initialize LDAP over TLS Teleport fails to connect to LDAP on startup. You may see errors similar to: