# RDP FIDO 1.23 for Linux

Both halves of RDP FIDO run on Linux (Ubuntu 22.04/24.04, Debian, Astra Linux,
RED OS 7.3, ALT Linux p10+ and other x86-64 distributions with glibc 2.18+):

- **gate `rdpfido-gate`** on the target machine keeps the RDP port (xrdp) closed
  and opens it only to the address that presented an enrolled FIDO2 key - or,
  since 1.23, a one-time code from an authenticator app;
- **client `rdpfido` / `rdpfido-gui`** connects to Windows or Linux gates with a
  FIDO2 USB/NFC key (or the one-time code) and starts FreeRDP;
- **FIDO Stream** (low-latency video, games) works both ways: a Linux machine
  can stream its X11 desktop (`rdpfido-stream-host`, in the gate package) and
  watch a stream from Windows or Linux (`rdpfido-viewer`, in the client package);
  files travel through the stream in both directions, and several participants
  can share one session (one of them in control).

The Windows and Linux editions speak the same protocol: a Windows client
connects to a Linux gate and the other way round.

## Install

```sh
# Ubuntu / Debian / Astra Linux
sudo apt install ./rdpfido-gate_1.23.0_amd64.deb      # target machine
sudo apt install ./rdpfido-client_1.23.0_amd64.deb    # your workstation
# RED OS / RHEL-like
sudo dnf install ./rdpfido-gate-1.23.0-1.x86_64.rpm
sudo dnf install ./rdpfido-client-1.23.0-1.x86_64.rpm
# ALT Linux (apt-rpm)
sudo apt-get install ./rdpfido-gate-1.23.0-alt1.x86_64.rpm
sudo apt-get install ./rdpfido-client-1.23.0-alt1.x86_64.rpm
# anything else
tar xzf rdpfido-1.23.0-linux-x86_64.tar.gz && cd rdpfido-1.23.0-linux-x86_64
sudo ./install.sh gate     # or: client, all
```

Checksums: `SHA256SUMS` in this folder.

## Set up the gate

```sh
sudo rdpfido-gate setup            # add --install-xrdp if xrdp is missing
```

It creates the gate certificate, installs the service and a boot guard that
closes the RDP port before the network comes up, and prints a one-time
enrollment code and the gate's certificate thumbprint. The RDP port closes the
moment the first key (or account) is enrolled.

## Use the client

```sh
rdpfido add --name office --host 10.0.0.5 --user ivan --password
rdpfido enroll office CODE --fingerprint THUMBPRINT   # code and thumbprint from the gate
rdpfido connect office                                # key -> port opens -> FreeRDP
rdpfido stream office                                 # FIDO Stream instead of RDP
```

Or the window: `rdpfido-gui` ("RDP FIDO" in the applications menu).

FIDO Stream on a Linux host captures X11 sessions (log in with an "Xorg"
session; Wayland is not captured yet).

## A key or a one-time code (1.23)

A gate signs people in one way: with a FIDO key (the default) or, for teams
without keys, with a 6-digit code from any authenticator app (Google
Authenticator, Microsoft Authenticator, Aegis, 1Password...).

```sh
sudo rdpfido-gate setup --auth totp     # at setup
sudo rdpfido-gate auth                  # which way now
sudo rdpfido-gate auth totp             # switch (restarts the gate); auth fido to go back
sudo rdpfido-gate totp add "Anna"       # an account made on the gate, QR code in the terminal
sudo rdpfido-gate totp test 3 123456    # check a code from the app
```

Enrollment works as with a key: `rdpfido-gate code`, then `rdpfido enroll`
shows a QR code in the terminal (`rdpfido-gui` in a window) and the first code
from the app confirms it. When connecting, the client asks for the code; a code
is accepted once only. A code opens RDP only - xrdp or Windows still ask for
their password; FIDO Stream is off in this mode (it reaches the desktop without
a password). Clients 1.23 and newer ask for codes.

## The cloud as an option

A gate without a public address can be linked to an RDP FIDO Cloud hub:
`sudo rdpfido-gate cloud link HUB:443 CODE` (the code comes from
`rdpfido-cloud code` on the hub), `cloud status`, `cloud unlink`. Clients then
reach the gate at `<id>.g.<domain>:443` without any port forwarding; RDP goes
through a tunnel ticket (port 3389 stays closed from outside), FIDO Stream
directly or through the hub's relay. A gate that is not linked makes no
outgoing connection at all. The hub `rdpfido-cloud` runs on your own VPS:
`rdpfido-cloud-1.22.0-linux-x86_64.tar.gz` in this folder (binary, relay,
`install.sh`, systemd units, web cabinet; unchanged in 1.23), described in
[README-cloud.ru.md](README-cloud.ru.md) (Russian). The Imobile cloud is a
private service: Imobile links a gate to it by arrangement, and demo access
for connecting is available to get acquainted.

## Updates

Every version works for one year from its release date (1.23.0: until
30 September 2027) and then requires an update: upgrade the packages with
`apt` / `dnf` / `apt-get`. The gate warns 30 days ahead (`rdpfido-gate status`).

Full guide (Russian): [README.ru.md](README.ru.md). Third-party components and
licences: [THIRD-PARTY.txt](THIRD-PARTY.txt).
