RDP FIDO · demo

Try RDP FIDO on our demo machines

Two Windows machines and one Linux machine that you can reach through RDP FIDO — by RDP or by FIDO Stream. See how the RDP port stays shut for everyone and opens only for the person who confirmed a key, and only for 90 seconds.

THE DEMO RUNS ON VERY WEAK MACHINES, WITHOUT A PASSWORD AND WITHOUT A HARDWARE KEY.

This is a stand, not workstations: 2 cores and 2 GB of memory for Windows, 1 core and 1 GB for Linux, no GPU. Do not judge speed by them — judge how access is opened and closed. On a real machine keep the password and use a hardware key.

In the browser — nothing to install

Open the web demo and click a machine's tile: its screen comes over FIDO Stream at once, with no password, no key and no client. You see how many people are connected, and anyone can take control or just watch. The web demo shows server streaming only — in the full product only the holder of a registered key gets in.

Open the web demo

The demo machines

User demo, empty password. The address is both the RDP server and the FIDO gate, port 443. The enrollment code is standing: an enrollment does not use it up.

MachineSystemAddress (server and gate, port 443)Enrollment codeGate thumbprint (SHA-256)
DEMO-WIN1Windows Server 2019 (Russian UI), 2 vCPU / 2 GB74db7e31aced311bab1e27e7007da7f1.rdp-demo.new-imobile.comPE6X-3DHZ-YC9UBD73DA2E…C68972
DEMO-WIN2Windows Server 2019 (Russian UI), 2 vCPU / 2 GBa9bdc9d20c8ea825fd0203a53f881b11.rdp-demo.new-imobile.comN43B-FCDQ-68FP6FEBBEAA…50EC13
demo-linuxUbuntu 24.04, XFCE, xrdp, 1 vCPU / 1 GB88e2976577f8cd09672ecc04ba1f809b.rdp-demo.new-imobile.comHYXD-XE78-D53M1DEC6D3C…8349E5

The client pins the gate's thumbprint by itself when you enroll a key; compare it with the full value if you like.

Full thumbprints
  • DEMO-WIN1: BD73DA2E61E7897BD0957D5711A49A9884C98140C5F1ED8FC3E670BF97C68972
  • DEMO-WIN2: 6FEBBEAABE61C339E00423ADB37F6C89CA2D5734EE575CCA80F7E35BE950EC13
  • demo-linux: 1DEC6D3C417A3751E9B6D61ADDD193741BB76885F7A188945D56B278F78349E5

These addresses work through the private Imobile cloud and are open to everyone: connect with the RDP FIDO client from any network, nothing to configure. RDP runs over TCP 443 and gets through everywhere. FIDO Stream needs direct UDP — from networks with strict NAT or a corporate firewall the stream may not connect, while RDP still works. The web demo above needs no client.

Ask a question

Try it with the RDP FIDO client

  1. Install the client — RdpFido-Setup.exe (choose “client”), the client MSI or the Linux packages. Version 1.22 or newer is required: older clients do not pass through the cloud.
  2. Enroll a key — the “Key…” button → the address from the table, port 443, the code from the table, any key name, “Store the key in: This computer (Windows Hello)” → “Enroll” → Windows asks for your PIN. On Linux: rdpfido enroll <address>:443 <code> or “Enroll key” in rdpfido-gui; a software authenticator works too.
  3. Add a session — “Add” → RDP server = the same address, port 3389, user demo, empty password; FIDO gate = the same address, port 443; protocol RDP or FIDO Stream. “Test” shows the machine's name.
  4. Connect — double-click the tile → Windows Hello PIN → a 90-second access window: press “Connect” in the mstsc publisher warning and OK in the credential prompt (the password is empty). Too slow? Just connect again. The desktop appears in 10–20 seconds.
  5. FIDO Stream — the same tile with the “FIDO Stream” protocol shows the machine's console over UDP. A weak VM encodes in software, so expect few frames per second.

Rules of the stand

  • Keys live 24 hours from enrollment, then the gate deletes them — enroll again with the same code.
  • Keep nothing on these machines. The demo user's folders are wiped every day, and a machine may be recreated from its template at any moment.
  • One user per machine. If someone is already connected, you either take over the session or see theirs — it is a demo.
  • Very weak VMs without a GPU: streaming is slow here; FIDO Stream shows the mechanics, not the speed.
  • The RDP window after confirmation is 90 seconds, including the mstsc dialogs.

What is closed

Each demo machine is filtered by the hypervisor's firewall, not the guest's: everything is dropped in both directions except the gate's link to the cloud hub and the FIDO Stream relay. The machines have no DNS, no web access and no updates, cannot reach the internet or our local network, and cannot spoof an address. Inside, as on any machine with RDP FIDO, the RDP port is closed and opens only for the address that confirmed a key, for 90 seconds.

The cloud is for the demo — your setup is up to you

The demo runs through the private Imobile cloud. The product itself works directly (the client connects to the gate on your machine) and with your own cloud server rdpfido-cloud, for gates behind NAT without port forwarding.

Your own rdpfido-cloud server →