# RDP FIDO 1.20 for Linux

Both halves of RDP FIDO run on Linux (Ubuntu 22.04/24.04, Debian, Astra Linux,
RED OS 7.3 and other x86-64 distributions with glibc 2.18+):

- **gate `rdpfido-gate`** on the target machine keeps the RDP port (xrdp) closed
  and opens it only to the address that presented an enrolled FIDO2 key;
- **client `rdpfido` / `rdpfido-gui`** connects to Windows or Linux gates with a
  FIDO2 USB/NFC key and starts FreeRDP;
- **FIDO Stream** (low-latency video, games) works both ways: a Linux machine
  can stream its X11 desktop (`rdpfido-stream-host`, in the gate package) and
  watch a stream from Windows or Linux (`rdpfido-viewer`, in the client package).

The Windows and Linux editions speak the same protocol: a Windows client
connects to a Linux gate and the other way round.

## Install

```sh
# Ubuntu / Debian / Astra Linux
sudo apt install ./rdpfido-gate_1.20.0_amd64.deb      # target machine
sudo apt install ./rdpfido-client_1.20.0_amd64.deb    # your workstation
# RED OS / RHEL-like
sudo dnf install ./rdpfido-gate-1.20.0-1.x86_64.rpm
sudo dnf install ./rdpfido-client-1.20.0-1.x86_64.rpm
# anything else
tar xzf rdpfido-1.20.0-linux-x86_64.tar.gz && cd rdpfido-1.20.0-linux-x86_64
sudo ./install.sh gate     # or: client, all
```

Checksums: `SHA256SUMS` in this folder.

## Set up the gate

```sh
sudo rdpfido-gate setup            # add --install-xrdp if xrdp is missing
```

It creates the gate certificate, installs the service and a boot guard that
closes the RDP port before the network comes up, and prints a one-time key
enrollment code and the gate's certificate thumbprint. The RDP port closes the
moment the first key is enrolled.

## Use the client

```sh
rdpfido add --name office --host 10.0.0.5 --user ivan --password
rdpfido enroll office CODE --fingerprint THUMBPRINT   # code and thumbprint from the gate
rdpfido connect office                                # key -> port opens -> FreeRDP
rdpfido stream office                                 # FIDO Stream instead of RDP
```

Or the window: `rdpfido-gui` ("RDP FIDO" in the applications menu).

FIDO Stream on a Linux host captures X11 sessions (log in with an "Xorg"
session; Wayland is not captured yet).

## Updates

Every version works for one year from its release date (1.20.0: until
27 September 2027) and then requires an update: upgrade the packages with
`apt` / `dnf`. The gate warns 30 days ahead (`rdpfido-gate status`).

Full guide (Russian): [README.ru.md](README.ru.md). Third-party components and
licences: [THIRD-PARTY.txt](THIRD-PARTY.txt).
