Guides · RDP-FIDO-GATE

How to stop retyping the sudo password in SSH sessions

Long random sudo passwords are good practice and miserable to type. The common shortcuts trade the protection away. This guide compares them and shows a console that answers the prompt for you while the password stays encrypted on your own PC.

Updated

The shortcuts and their price

ShortcutConveniencePrice
NOPASSWD in sudoersNo prompt at allWhoever gets your shell gets root; the second barrier is gone
sudo -S with a piped password, sshpass, expect scriptsWorks unattendedThe password sits in a script, in the shell history or in the process list
A longer timestamp_timeoutFewer prompts per sessionA longer window in which an unattended terminal is root
Copy from a password managerThe password stays strong and uniqueTwo window switches per prompt; the clipboard holds the password
A console that answers the promptOne click, or noneThe password is stored on your PC, so how it is stored matters

How prompt answering works

The SSH console of the RDP FIDO client keeps password records. A record holds a name, the password and the text of the prompt it answers — for example [sudo] password. When the terminal prints a password prompt that contains that text, a small tile offers the matching record; one click types the password and Enter.

Tick “Type it by itself” and the record answers its prompt without the click — but not more often than once in 15 seconds, so a wrong password is never typed three times in a row.

The same mechanism answers the login password prompt and Enter passphrase for key….

Where the password lives

Set it up

  1. Install the RDP FIDO client on Windows 10 or 11. The console uses the OpenSSH client that ships with Windows, so your keys and ~/.ssh/config keep working.
  2. On the SSH tab add a session: the server address, your login, the “SSH console” protocol. A gate is optional — without one it is a plain SSH console.
  3. Open the session, go to the “Passwords” tab and add a record: the sudo password and the prompt text [sudo] password.
  4. Run any sudo command. The tile appears; click it — or tick “Type it by itself” in the record.

To try the console before adding a server, run RdpFidoClient.exe console with no arguments: it opens on a local shell.

The commands you type every day

The “Commands” tab holds the other thing admins retype: journalctl -u nginx -n 100 --no-pager, docker compose pull && docker compose up -d, a multi-line check script. A click runs a command; “Insert” types it without Enter, so you can add arguments. Commands belong to one server or to all of them.

When not to store it

RDP-FIDO-GATE

RDP-FIDO-GATE keeps SSH and other admin ports closed and opens them for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. Its client includes an SSH console with saved passwords, saved commands and an AI assistant that works with Claude or with your own local model. The Free edition covers 10 saved sessions.

Frequently asked questions

Does this work with PuTTY?

No. The console is its own terminal on top of the system OpenSSH client, so OpenSSH keys, ssh-agent and ~/.ssh/config are used. PuTTY sessions and .ppk keys are not imported.

Can the AI assistant in the console see my sudo password?

No. The program types the password, the terminal does not echo it, and it is not part of the text sent to the model.

What if the stored password is wrong?

A record that types itself answers its prompt no more than once in 15 seconds, so sudo's three attempts are not burned in a row. Edit the record and try again.

Does it work on Linux?

Yes: rdpfido console SESSION opens the same console. Passwords are kept in the desktop keyring; without a keyring they are not saved.

Is it free?

The console is part of the client, including the free edition with up to 10 saved sessions.

Related guides