Skip to content
English

RDP graphical connections

Remote connections to a Windows desktop, finished in the browser. The backend completes the handshake and injects the credential first, and only then does the channel become pure forwarding, so the frontend never touches a credential in the clear. This page covers creating the asset, choosing the security mode, how the display size and clipboard work, and how files get in.

A target host running the remote desktop service (port 3389 by default) that the graphics proxy can reach.

Choose RDP as the protocol when creating the asset, which fills in port 3389, then enter the host. The login secret is either a credential dedicated to this asset, or a shared credential in the library that matches the protocol. RDP carries two fields of its own:

  • Security mode: automatic negotiation, NLA (network level authentication, recommended), or TLS.
  • Verify certificate: turning it off shows a warning that leaving the server certificate unverified opens the way to a man in the middle.

While the transmission security policy is set to strict refusal, an asset without certificate verification is refused; see Transmission security policy for how to set it.

The connection starts with the container size as it was actually measured, waiting for that measurement rather than filling in a fixed default. A change in window size sends a new size and negotiates again.

  • Send Ctrl+Alt+Del, which Windows needs for sign-in and for unlocking a locked session.
  • Paste to the remote, and fetch the remote clipboard.
  • Upload a file.

The bidirectional clipboard is governed by the two policy keys “paste the clipboard into the asset” and “copy the clipboard out of the asset”, enforced on the connection parameters of the graphics proxy. A policy change leaves sessions in progress alone, and the interface says a reconnection puts it into effect.

Uploads go through drive redirection: each connection has its own temporary path, and once an upload finishes a drive named Shared appears under “This PC” on the remote, holding the file. This upload path shares its audit trail with VNC file transfer.

  • Recording: graphical sessions are recorded in a native format and play back on the session detail page in the graphical player.
  • Clipboard content is kept with the session, direction, content, and time, and is stored under envelope encryption.
  • An upload leaves a file transfer record with the filename, size, and channel.
  • When the connection is made, the five data transfer capabilities in effect for that session are written into the record.
  • The screen carries a watermark of the username and the date.