Friday, September 03, 2010
Register
Login
Home
Community News
Articles
Videos Library
Downloads
Forums
Blogs
Pierre's Blog
FAQ
Support
Contact
About Us
 
Citrix Tools >
Articles
Articles Section
Follow Me On Twitter !
Articles
Here You'll find all our Articles : Best Practices, HowTo and also our Tools Documentation.
Don't Hesitate to send us your enhancement or support request regarding our Tools with the
FeedBack Center
CitrixTools.Net Articles
Current Articles
|
Archives
|
Search
Wednesday, September 03, 2008
Terminal Services Console Session and the /Admin Switch
By Pierre Marmignon @ 6:01 PM :: 9885 Views ::
0 Comments
::
::
Terminal Server
Laurent Falguiere
, a French Terminal Server MVP, has written an interesting article regarding the Terminal services Console Session and the "/Admin" Switch introduced in RDP Client 6.1 and Windows 2008 Server.
I decided to translate it and publish it in Our English part (as the French part is directly pointing the Laurent's French WebSite).
On Windows 2003, the console session points to the local session (the one accessible when being physically in front of the server, connected directly on it).
This session has a really specific role : it is used by the User connected to the Physical Machine but also to execute and run System Services (which are running under high privileges).
Then if the User running this Console Session is mainly an Administrator allowed to connect to the Server, it is technically possible for Malware or SpyWare to install and run within this context and successfully get higher System Privileges by hacking System Services.
To prevent this security hole and globally increase Security, under Windows 2008 (and Vista), the Console session (also called session 0) is now dedicated to System Services Système and it's not possible anymore to open an Interactive Session using the Session 0.
Applications that were designed to run only within the Console Session should be able to work within another session, but the Main consequence regarding Terminal Services is that the "/console" of the Remote Desktop Client (mstsc), used to connect remotely the the Console Session of the Windows Server 2003 (and also without consuming any TSCal) won't work within a Windows 2008 Environment.
Note from translator : That's also why this switch has been removed from the Remote Desktop Client 6.1
When trying to use the "/Console" switch to connect to a Windows 2008 Server /console You'll get the Following :
When running mstsc /console, the switch is not taken into account and a "standard" Terminal Server session is opened.
If you append the "/Console" switch to the Computer Namer within the Remote DeskTop Client, You'll have an error message specifying that an Unknown parameter has been specified (Same Error Message if written into a .RDP File).
The /Console has then been depriciated and replaced (and Vista or RDC 6.1 Users are already aware of this) by the /admin switch.
And now the new name takes is all sense : as You cannot connect to the "Real Console" Session 0 anymore in Windows Server 2008, the purpose of this new switch is really different and that's why the name was changed.
The /admin switch has then the property to allow Admins to connect up to Two conccurent Remote Admin Sessions. This Two Sessions contains the Local Server Session, which allows to reconnect a locally opened session from any other computer and Vice-Versa (Which was not possible with Windows 2003).
The Old Active Session Limit that allows only Two conccurent Admin Connection on a server still remains, but now a PopUp can allow an Admin to Ask another to close its session or even to force its disconnection, wich is a good news for all admins.
When Connecting onto a Terminal services Enabled Server, Sessions using the /admin switching won't consume any TSCal.
The /admin switch has also the following specificities (when connecting to any Server Type) :
Time Zone is not redirected.
TS Session Broker redirection is Disabled.
Plug and Play Devices Redirection is Disabled.
Default Theme is changed to “Windows Classic”.
Easy Print is disabled.
The Setting “Prevent this user to connect to Terminal Server Computers" is ignored.
Sources
:
Application Compatibility - Session 0 Isolation
Changes to Remote Administration in Windows Server 2008
Share on Twitter
Retweet this Article
Comments
Only registered users may post comments.
Featured Articles
XenDesktop Tuning Tips
by
Pierre Marmignon
Terminal Server & XenApp Tuning Tips
by
Pierre Marmignon
CitrixTools.Net Tools are Slow to Launch
by
Pierre Marmignon
Taking a XenApp Server Offline for Maintenance Purposes
by
Pierre Marmignon
Terminal Services Console Session and the /Admin Switch
by
Pierre Marmignon
Optimizing XenApp / Presentation Server 4.X Universal Printing
by
Pierre Marmignon
Latest Articles
Lockdown Internet Explorer for Web Applications Publishing
by
Pierre Marmignon
Programmatically Purge Logs Files on an Age Basis
by
Pierre Marmignon
Publish an Application that needs a parent process
by
Pierre Marmignon
Programmatically Uninstall Citrix Clients
by
Pierre Marmignon
Getting rid of the Found New Hardware Prompt when using Device HardDisk Cache with Citrix Provisioning Server
by
Pierre Marmignon
Archives
August 2009 (6)
June 2009 (2)
May 2009 (6)
February 2009 (4)
November 2008 (2)
September 2008 (4)
July 2008 (1)
June 2008 (1)
Citrix pour les Nuls
Citrix pour les Nuls
Move
Close
DefaultPrnFlags Tool 1
DefaultPrnFlags Tool 1
DefaultPrnFlags Tool 3
DefaultPrnFlags Tool 3
DefaultPrnFlags Tool 4
DefaultPrnFlags Tool 4
DefaultPrnFlags Tool 6
DefaultPrnFlags Tool 6
Support Center
Support Center
Move
Close
Make a Suggestion
Suggestions are requests for changes in design or behavior of software. You can see that the software is working as designed, but you'd like better or different functionality.
Click here to make a suggestion
Product List
A Venir
Citrix DefaultPrnFlags Tool
Idees d'Outil
Modded Web Interface 4.6
Modded Web Interface 5.0
Modded Web Interface 5.1
Tool Suggestion
Upcoming Tools
Web Interface Important Message Manager
Web Interface Logs Parser
XenApp App Export Manager
XenApp App Manager
XenApp App Visibility Manager
XenApp Application Maintenance Manager
XenApp Cloning Service Configuration Plugin
XenApp Cloning Tool
XenApp Fast Publishing
XenApp Load Evaluators Manager
XenApp Policies Export Manager
XenApp Reporter
XenApp Seamless Flags Configurator
XenApp Servers Logon Manager
XenApp Sessions Cleaner
XenApp Sessions Monitor
XenApp Specific Launcher
XenApp UPD Tuner
Search All Feedback
What's New
[7/12/2010]
XenApp Policies Export Manager
»
Bug importation limit bande passante en %
[4/6/2010]
XenApp Cloning Tool
»
Does not modify WSID in MF20.dsn
[11/20/2009]
Tool Suggestion
»
Tool for exporting Installations manager information
[10/9/2009]
XenApp App Export Manager
»
Is there a file specification for the export file?
[9/28/2009]
XenApp App Manager
»
Adding Novell NDS/edir groups to applications
More Feedback
Highest Rated
[2]
XenApp App Manager
»
Import / Export App Feature
[2]
XenApp App Manager
»
Adding Novell NDS/edir groups to applications
[1]
XenApp App Export Manager
»
Is there a file specification for the export file?
[1]
Tool Suggestion
»
Tool for exporting Installations manager information
[1]
XenApp Cloning Tool
»
Does not modify WSID in MF20.dsn
More Feedback
Recently Implemented
[1/23/2009]
A Venir
»
Outil d'installation de CPS
[10/31/2008]
XenApp App Export Manager
»
"" In Application Location or Working Directory Not Imported Properly
[9/16/2008]
XenApp App Manager
»
Manage Server Button Greyed Out
[8/19/2008]
XenApp App Export Manager
»
Import / Export
[8/3/2008]
Web Interface Important Message Manager
»
Dutch language
More Feedback
Recently Commented
[9/28/2009]
XenApp App Manager
»
Adding Novell NDS/edir groups to applications
[1/24/2009]
Idees d'Outil
»
Regrouper tous les outils en une seule console
[11/12/2008]
Citrix DefaultPrnFlags Tool
»
use on a XEN Server Pool
[8/30/2008]
XenApp App Export Manager
»
App Name Truncated
[7/21/2008]
XenApp App Manager
»
Exception 0x80040258 Raised at StartUp
More Feedback
Statistics
Feedback in the last 30 days:-
Feedback Submitted:
0
Feedback Resolved:
0
Average Time Open (Days):
-1
Feedback for all time:-
Feedback Submitted:
31
Feedback Resolved:
17
Average Time Open (Days):
2
UPDTuner 1
UPDTuner 1
UPDTuner 2
UPDTuner 2
UPDTuner 3
UPDTuner 3
UPDTuner 4
UPDTuner 4
UPDTuner 5
UPDTuner 5
UPDTuner 6
UPDTuner 6
UPDTuner 7
UPDTuner 7
UPDTuner 8
UPDTuner 8
Netscaler - Synoptic 1
Netscaler - Synoptic 1
Citrix Support
Citrix Support
Move
Close
Netscaler - Synoptic 2
Netscaler - Synoptic 2
Fast Publishing 1
Fast Publishing 1
Fast Publishing 2
Fast Publishing 2
Fast Publishing 3
Fast Publishing 3
Fast Publishing 4
Fast Publishing 4
Fast Publishing 5
Fast Publishing 5
Fast Publishing 6
Fast Publishing 6
Fast Publishing 7
Fast Publishing 7
Fast Publishing 8
Fast Publishing 8
Launcher1
Launcher1
Launcher2
Launcher2
Launcher3
Launcher3
Launcher4
Launcher4
Launcher5
Launcher5
Launcher6
Launcher6
AMCLogon1
AMCLogon1
LEManager1
LEManager1
LogonManager1
LogonManager1
Citrix Community
Citrix Community
Move
Close
Brian Madden
Brian Madden
Move
Close
MaintLE1
MaintLE1
The Shonk Project
The Shonk Project
Move
Close
DotNetCfgXML1
DotNetCfgXML1
PasswordsGPO1
PasswordsGPO1
DABCC
DABCC
Move
Close
VisionApp
VisionApp
Move
Close
Sepago Blogs
Sepago Blogs
Move
Close
Doctor Citrix
Doctor Citrix
Move
Close
Jim Moyle's Blog
Jim Moyle's Blog
Move
Close
XenApp Blog
XenApp Blog
Move
Close
SysInt
SysInt
Move
Close
Ervik.As
Ervik.As
Move
Close
The Site Doctor
The Site Doctor
Move
Close
Microsoft Support
Microsoft Support
Move
Close
JHouse
JHouse
Move
Close
CtxQLaunch1
CtxQLaunch1
CtxQLaunch2
CtxQLaunch2
CtxQLaunch3
CtxQLaunch3
CtxQLaunch4
CtxQLaunch4
CTXPRNTOOL1
CTXPRNTOOL1
CTXPRNTOOL3
CTXPRNTOOL3
CTXPRNTOOL4
CTXPRNTOOL4
CTXPRNTOOL5
CTXPRNTOOL5
CTXPRNTOOL6
CTXPRNTOOL6
CTXPRNTOOL7
CTXPRNTOOL7
CTXPRNTOOL8
CTXPRNTOOL8
AGEECust1
AGEECust1
AGEECust2
AGEECust2
AGEECust3
AGEECust3
Copyright 2010 by
Pierre Marmignon
Privacy Statement
|
Terms Of Use
Partners
Sponsors