Why hide a port that already demands a key
- Pre-authentication bugs. regreSSHion (CVE-2024-6387) allowed remote code execution in OpenSSH's server on glibc-based Linux without any login. The xz backdoor (CVE-2024-3094) was also triggered before authentication. Neither cared how strong your keys were; both needed a port that answers.
- Constant background noise. Thousands of login attempts a day fill the logs and hide the one line that matters.
- One mistake away. A test account with a password, a forgotten
PasswordAuthentication yesin a drop-in file — on an open port such a slip is found within hours.
A port that drops every packet removes all three at once. The question is how to open it for yourself without a VPN and without a fixed IP address.
How the gate works
RDP-FIDO-GATE installs a small service on the server. It adds its own nftables table — or, where nftables is absent, an iptables chain kept first in INPUT — that drops new connections to the guarded ports. Established connections are accepted, so nothing that is running gets cut.
The service listens on TCP 7440 over TLS and accepts one thing: a signed FIDO2 / WebAuthn confirmation from a key enrolled on this server. After a valid one it adds a rule for the caller's IP address, keeps it for 90 seconds — enough to start ssh — and removes it. Every 30 seconds it checks that its rules are still in place, and after a reboot a guard unit installs them before the network comes up.
The service runs under a systemd sandbox: a short list of capabilities for driving the packet filter, a read-only file system outside its own state directory, a memory limit.
What you need
- A Linux server, x86-64. There are packages for Ubuntu, Debian, Astra Linux, RED OS and ALT Linux, and a tarball with an installer for other distributions.
- TCP port 7440 reachable from where you work. Allow it in the cloud provider's security group; ufw and firewalld are handled by the setup command.
- A FIDO2 security key — or Windows Hello, if you always connect from the same Windows PC. Without keys, the gate can accept 6-digit codes from an authenticator app instead.
- The RDP FIDO client on your own computer: Windows 10 / 11 or Linux.
Set it up
- On the server, download the gate package and install it. It is the only package apt adds: no xrdp and no X libraries come with it. File names for other distributions are in the Linux guide.
- Run
sudo rdpfido-gate setup. It creates the gate's certificate, installs the service and prints a one-time enrollment code (valid for 15 minutes) and the certificate fingerprint. On a server without a desktop it also notes that no RDP server was found — which is fine when SSH is all you want to guard. - On your computer, install the client and add a session on the SSH tab: the server address, your login, the “SSH console” protocol, gate port 7440. Enroll your key with the code from step 2 and touch it.
- Back on the server, run
sudo rdpfido-gate ports add 22. From this moment port 22 is closed to everyone the gate has not let in. The session you are typing in stays open. - To connect, click the session tile and touch the key: the gate opens the port for your address and the console starts
ssh.
# on the server (Ubuntu / Debian)
wget https://new-imobile.com/download/rdp-fido-gate/linux/rdpfido-gate_1.25.2_amd64.deb
sudo apt install ./rdpfido-gate_1.25.2_amd64.deb
sudo rdpfido-gate setup # prints the enrollment code and the fingerprint
# on a Linux workstation, instead of the Windows client
rdpfido add --name web1 --host 203.0.113.10 --user admin
rdpfido enroll web1 6NGQ-MEMG-34M4 --fingerprint 273CE04D...
# on the server again, once the key is enrolled
sudo rdpfido-gate ports add 22
# on the workstation
rdpfido ssh web1 # touch the key -> ssh
Enroll the key before you add port 22: that way you know the key works before SSH closes. The session you are typing in stays open — the gate does not cut established connections. Before you close that session, check from a second terminal that the key lets you in. If it does not, run sudo rdpfido-gate ports remove 22 in the session you still have, or sudo rdpfido-gate unlock on the machine's own console.
Check it from outside
From a machine that has not touched a key:
nc -vz -w 3 203.0.113.10 22 # times out: the port does not answer
nc -vz -w 3 203.0.113.10 7440 # succeeds: the gate is reachable
# on the server
sudo rdpfido-gate status # service, keys, rules, active grants
sudo nft list table inet rdpfido # the rules themselves
Then run rdpfido open web1 (or click the tile), touch the key and repeat the first line within 90 seconds from the same address: now it connects.
More than SSH
The same command guards up to 16 TCP ports that the host itself listens on — a web admin panel, a database port, a monitoring UI: sudo rdpfido-gate ports add 22 8443 5432. One key touch opens all of them for your address for the same 90 seconds.
On a Linux workstation, rdpfido ssh web1 -- -L 8443:127.0.0.1:8443 passes everything after -- to ssh, so tunnels and jump hosts work as usual. In the Windows client the same options go into the session's ssh options field.
What to know before you rely on it
- The key is a factor in front of SSH, not instead of it. sshd still asks for your key or password. Keep its own authentication strong.
- The port opens for an IP address. Someone behind the same NAT address could reach the port during those 90 seconds — and would still face sshd.
- Ports published from Docker containers are not covered. They are forwarded past the host's
INPUTchain. The gate guards ports served by the host itself. - Each release works for one year from its release date. After that the gate still verifies keys but stops opening ports until the package is updated;
sudo rdpfido-gate statusshows the date, andunlockon the console keeps working. - Keep a second way in — the provider's console or IPMI — as with any firewall change.
- Extra ports are a feature of the Linux gate. The gate for Windows guards RDP only. Clients exist for Windows and Linux; there is no macOS client.
- The software is proprietary. The gate and the client are free for up to 10 saved sessions; Pro is a one-time purchase.