# RDP FIDO 1.22 for Linux

Both halves of RDP FIDO run on Linux (Ubuntu 22.04/24.04, Debian, Astra Linux,
RED OS 7.3, ALT Linux p10+ and other x86-64 distributions with glibc 2.18+):

- **gate `rdpfido-gate`** on the target machine keeps the RDP port (xrdp) closed
  and opens it only to the address that presented an enrolled FIDO2 key;
- **client `rdpfido` / `rdpfido-gui`** connects to Windows or Linux gates with a
  FIDO2 USB/NFC key and starts FreeRDP;
- **FIDO Stream** (low-latency video, games) works both ways: a Linux machine
  can stream its X11 desktop (`rdpfido-stream-host`, in the gate package) and
  watch a stream from Windows or Linux (`rdpfido-viewer`, in the client package);
  since 1.21 files travel through the stream in both directions, since 1.22
  several participants can share one session (one of them in control).

The Windows and Linux editions speak the same protocol: a Windows client
connects to a Linux gate and the other way round.

## Install

```sh
# Ubuntu / Debian / Astra Linux
sudo apt install ./rdpfido-gate_1.22.0_amd64.deb      # target machine
sudo apt install ./rdpfido-client_1.22.0_amd64.deb    # your workstation
# RED OS / RHEL-like
sudo dnf install ./rdpfido-gate-1.22.0-1.x86_64.rpm
sudo dnf install ./rdpfido-client-1.22.0-1.x86_64.rpm
# ALT Linux (apt-rpm)
sudo apt-get install ./rdpfido-gate-1.22.0-alt1.x86_64.rpm
sudo apt-get install ./rdpfido-client-1.22.0-alt1.x86_64.rpm
# anything else
tar xzf rdpfido-1.22.0-linux-x86_64.tar.gz && cd rdpfido-1.22.0-linux-x86_64
sudo ./install.sh gate     # or: client, all
```

Checksums: `SHA256SUMS` in this folder.

## Set up the gate

```sh
sudo rdpfido-gate setup            # add --install-xrdp if xrdp is missing
```

It creates the gate certificate, installs the service and a boot guard that
closes the RDP port before the network comes up, and prints a one-time key
enrollment code and the gate's certificate thumbprint. The RDP port closes the
moment the first key is enrolled.

## Use the client

```sh
rdpfido add --name office --host 10.0.0.5 --user ivan --password
rdpfido enroll office CODE --fingerprint THUMBPRINT   # code and thumbprint from the gate
rdpfido connect office                                # key -> port opens -> FreeRDP
rdpfido stream office                                 # FIDO Stream instead of RDP
```

Or the window: `rdpfido-gui` ("RDP FIDO" in the applications menu).

FIDO Stream on a Linux host captures X11 sessions (log in with an "Xorg"
session; Wayland is not captured yet).

## The cloud as an option (1.22)

A gate without a public address can be linked to an RDP FIDO Cloud hub:
`sudo rdpfido-gate cloud link HUB:443 CODE` (the code comes from
`rdpfido-cloud code` on the hub), `cloud status`, `cloud unlink`. Clients then
reach the gate at `<id>.g.<domain>:443` without any port forwarding; RDP goes
through a tunnel ticket (port 3389 stays closed from outside), FIDO Stream
directly or through the hub's relay. A gate that is not linked makes no
outgoing connection at all. The hub `rdpfido-cloud` runs on your own VPS:
`rdpfido-cloud-1.22.0-linux-x86_64.tar.gz` in this folder (binary, relay,
`install.sh`, systemd units, web cabinet), described in
[README-cloud.ru.md](README-cloud.ru.md) (Russian). Imobile's public hub is
not open yet.

## Updates

Every version works for one year from its release date (1.22.0: until
28 September 2027) and then requires an update: upgrade the packages with
`apt` / `dnf` / `apt-get`. The gate warns 30 days ahead (`rdpfido-gate status`).

Full guide (Russian): [README.ru.md](README.ru.md). Third-party components and
licences: [THIRD-PARTY.txt](THIRD-PARTY.txt).
