rdp.md (11544B)
1 --- 2 title: "RDP" 3 description: "export RDP=sdl-freerdp" 4 category: linux-it 5 tags: ["linux-it", "adcs"] 6 tools: [] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Linux/RDP CheatSheet.md" 10 --- 11 # macOS: native SDL client (recommended) 12 export RDP=sdl-freerdp 13 14 # Linux examples: 15 # export RDP=xfreerdp3 16 # export RDP=xfreerdp 17 18 export TARGET='10.10.10.10' 19 export DOMAIN='DOMAIN' 20 export USER='username' 21 ``` 22 23 > [!tip]+ Secure baseline 24 > 1. `/from-stdin:force` prompts before connecting, keeping the password out of shell history and process arguments. 25 > 2. `/cert:tofu` trusts a certificate on the first connection, then rejects an unexpected change. 26 > 3. `+dynamic-resolution` keeps the session usable when the client window is resized. 27 28 ```bash 29 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" \ 30 /from-stdin:force /cert:tofu +dynamic-resolution 31 ``` 32 33 --- 34 35 ## // CONNECTION_&_AUTHENTICATION 36 37 ### 1. Identity formats 38 39 | Identity type | Example | 40 |---|---| 41 | Local account | `/u:Administrator` | 42 | Domain account | `/d:DOMAIN /u:username` | 43 | Down-level domain name | `/u:'DOMAIN\username'` | 44 | User principal name | `/u:'user@domain.example'` | 45 46 ```bash 47 # Local account 48 "$RDP" /v:"$TARGET" /u:Administrator /from-stdin:force /cert:tofu 49 50 # Domain account 51 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force /cert:tofu 52 53 # UPN 54 "$RDP" /v:"$TARGET" /u:'user@domain.example' /from-stdin:force /cert:tofu 55 ``` 56 57 > [!warning]+ Avoid inline passwords `fas:TriangleExclamation` 58 > `/p:<password>` is supported, but the password can end up in shell history, terminal scrollback, process listings, screenshots, and copied commands. Use `/from-stdin:force` unless a disposable authorised lab requires otherwise. 59 60 ### 2. Kerberos and smart-card authentication 61 62 ```bash 63 # Use an existing Kerberos ticket cache 64 kinit 'user@DOMAIN.EXAMPLE' 65 "$RDP" /v:"$TARGET" /u:'user@DOMAIN.EXAMPLE' \ 66 /sec:nla /kerberos:cache:"$KRB5CCNAME" /cert:tofu 67 68 # Smart-card logon (the reader/card must be available locally) 69 "$RDP" /v:"$TARGET" /smartcard-logon /sec:nla /cert:tofu 70 ``` 71 72 > [!info]+ Authentication notes 73 > 1. `/sec:nla` explicitly requires Network Level Authentication and disables weaker alternatives. 74 > 2. Kerberos depends on DNS, realm configuration, and clock alignment; inspect the ticket with `klist` before troubleshooting RDP itself. 75 > 3. Smart-card logon activates the local reader; it is distinct from `/smartcard`, which redirects a smart card into an already authenticated remote session. 76 77 ### 3. Pass-the-hash — authorised lab/admin use only 78 79 ```bash 80 export NT_HASH='0123456789ABCDEF0123456789ABCDEF' 81 "$RDP" /v:"$TARGET" /u:Administrator /pth:"$NT_HASH" \ 82 +restricted-admin /cert:tofu 83 ``` 84 85 > [!danger]+ Credential material `fas:Skull` 86 > A hash is credential material. Use this only with explicit authority, do not save it in the note, and clear the variable with `unset NT_HASH` when finished. Restricted Admin mode must be permitted by the target policy. 87 88 --- 89 90 ## // TRANSPORT_&_CERTIFICATE_SECURITY 91 92 | Goal | Option | When to use it | 93 |---|---|---| 94 | Secure default | `/cert:tofu` | First connection to a known target; detects later certificate changes | 95 | Pin known certificate | `/cert:fingerprint:sha256:<hex>` | You have a verified SHA-256 fingerprint from a trusted channel | 96 | Fail on mismatch | `/cert:deny` | Strict environments that should never prompt | 97 | Require NLA | `/sec:nla` | Normal domain or local-account RDP | 98 | TLS without NLA | `/sec:tls` | Only when the target intentionally does not require NLA | 99 | Legacy RDP security | `/sec:rdp` | Legacy, authorised compatibility testing only | 100 101 ```bash 102 # Pin a certificate fingerprint received through a trusted channel 103 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force \ 104 /cert:fingerprint:sha256:<hex_fingerprint> 105 106 # Require NLA and TLS 1.2 or newer where the target requires an explicit floor 107 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \ 108 /sec:nla /tls:enforce:1.2 /cert:tofu 109 ``` 110 111 > [!danger]+ Never make this the default `fas:TriangleExclamation` 112 > `/cert:ignore` disables certificate validation and makes a rogue or intercepted server much harder to detect. Use it only in a disposable, explicitly authorised lab when certificate validation is the subject of the test. 113 114 --- 115 116 ## // DISPLAY_&_PERFORMANCE 117 118 ### 1. Display and window controls 119 120 ```bash 121 # Fullscreen; Ctrl+Alt+Enter toggles back to a window 122 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu +f 123 124 # Fixed initial size, then allow resize-driven updates 125 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \ 126 /size:1600x1000 +dynamic-resolution 127 128 # Use 80% of display height or scale the rendered desktop 129 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /size:80%h 130 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /scale:140 131 132 # Multiple displays or selected display IDs (list IDs with /list:monitor) 133 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /multimon 134 "$RDP" /list:monitor 135 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /monitors:0,1 136 ``` 137 138 ### 2. Low-bandwidth profile 139 140 ```bash 141 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \ 142 /cert:tofu /network:modem /compression-level:2 \ 143 -wallpaper -themes -menu-anims -fonts /gdi:sw 144 ``` 145 146 ### 3. High-quality workstation profile 147 148 ```bash 149 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \ 150 /cert:tofu +f +dynamic-resolution /gdi:hw \ 151 /gfx:progressive:on,AVC444:on /network:lan 152 ``` 153 154 > [!tip]+ Performance tuning `fas:Lightbulb` 155 > 1. Start with `/network:auto` or `/network:lan`; move toward `/network:modem` only when the connection is genuinely constrained. 156 > 2. Disable wallpaper, themes, animations, and smooth fonts before compromising authentication or certificate checks. 157 > 3. If hardware rendering misbehaves, use `/gdi:sw` as a compatibility fallback. 158 159 --- 160 161 ## // LOCAL_RESOURCE_REDIRECTION 162 163 ### 1. Clipboard and drives 164 165 ```bash 166 # Disable clipboard redirection for sensitive sessions 167 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu -clipboard 168 169 # Redirect one selected directory as a named remote share 170 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \ 171 /drive:Share,"$PWD" 172 173 # Redirect the home directory or every mounted filesystem 174 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu +home-drive 175 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu +drives 176 177 # Permit hot-plugged removable drives 178 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /drive:hotplug,* 179 ``` 180 181 ### 2. Audio, printers, smart cards, and USB 182 183 ```bash 184 # Audio output and microphone input 185 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /sound /microphone 186 187 # Redirect a printer or smart card into the session 188 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /printer 189 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /smartcard 190 191 # Redirect a USB device by vendor and product ID 192 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu /usb:id:1234:5678 193 ``` 194 195 > [!warning]+ Data-boundary check `fas:TriangleExclamation` 196 > Clipboard, drive, USB, printer, microphone, and smart-card redirection expand the trust boundary between your machine and the remote host. Enable only the one feature you need and disable it for untrusted or assessment targets. 197 198 --- 199 200 ## // GATEWAYS_PROXY_&_REMOTEAPP 201 202 ```bash 203 # RD Gateway; omit /p: values so FreeRDP prompts for required credentials 204 export GATEWAY='rdgateway.example.com' 205 export GW_USER='gateway-user' 206 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \ 207 /gateway:g:"$GATEWAY",u:"$GW_USER",d:"$DOMAIN",usage-method:detect \ 208 /cert:tofu 209 210 # HTTP or SOCKS5 proxy 211 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \ 212 /proxy:http://proxy.example.com:8080 213 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \ 214 /proxy:socks5://127.0.0.1:1080 215 216 # A gateway also honours an HTTPS proxy set in the environment 217 export https_proxy='http://proxy.example.com:3128' 218 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force \ 219 /gateway:g:"$GATEWAY" /cert:tofu 220 221 # RemoteApp example 222 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \ 223 /app:program:'||notepad',name:'Notepad' 224 ``` 225 226 > [!info]+ Gateway credentials 227 > A gateway can use credentials different from the target. Keep gateway passwords out of the command line too; FreeRDP prompts when the relevant `/p:` value is omitted. 228 229 --- 230 231 ## // SESSION_CONTROL_&_TROUBLESHOOTING 232 233 | Symptom or task | Command / response | 234 |---|---| 235 | Confirm the installed version | `"$RDP" /version` | 236 | Inspect locally supported options | `"$RDP" /help` | 237 | Find available display IDs | `"$RDP" /list:monitor` | 238 | Test authentication without opening a desktop | Add `+auth-only` | 239 | Reconnect after a transient drop | Add `+auto-reconnect /auto-reconnect-max-retries:10` | 240 | Keep an authorised session awake | Add `/prevent-session-lock:300` | 241 | Release keyboard/mouse grab | Press `Right Ctrl` | 242 | Toggle fullscreen | Press `Ctrl+Alt+Enter` | 243 | Minimise the session | Press `Ctrl+Alt+M` | 244 245 ```bash 246 # Verify credentials and transport without starting the GUI desktop 247 "$RDP" /v:"$TARGET" /d:"$DOMAIN" /u:"$USER" /from-stdin:force \ 248 /cert:tofu +auth-only 249 250 # Reconnect a flaky authorised session, up to ten times 251 "$RDP" /v:"$TARGET" /u:"$USER" /from-stdin:force /cert:tofu \ 252 +auto-reconnect /auto-reconnect-max-retries:10 253 ``` 254 255 > [!failure]+ Common fixes `fas:CircleXmark` 256 > 1. **`$DISPLAY` error on macOS:** use `sdl-freerdp`, or install and start XQuartz before using `xfreerdp`. 257 > 2. **Certificate changed:** stop and verify the server identity through a trusted channel; do not switch to `/cert:ignore` just to connect. 258 > 3. **NLA / Kerberos failure:** verify DNS, target time, realm configuration, and the ticket cache with `klist`. 259 > 4. **Option rejected:** your package may differ from this reference; use `"$RDP" /help` and update the client. 260 261 --- 262 263 ## // MACOS_INSTALL `fas:Apple` 264 265 ```bash 266 # Homebrew installs FreeRDP 3.30.0, including sdl-freerdp and xfreerdp 267 brew update 268 brew install freerdp 269 270 # Only required when using the X11 client (xfreerdp) 271 brew install --cask xquartz 272 open -a XQuartz 273 274 # Verify both available clients 275 sdl-freerdp /version 276 xfreerdp /version 277 ``` 278 279 > [!success]+ macOS client choice 280 > Use `sdl-freerdp` by default on macOS. The Homebrew formula builds the SDL client, while its `xfreerdp` client requires a running X11 server and otherwise produces a `$DISPLAY` error. 281 282 --- 283 284 ## // LESSONS_LEARNED `fas:Lightbulb` 285 286 1. Set the client, target, domain, and user once; then every recipe remains copy-ready across macOS and Linux. 287 2. Prefer `/from-stdin:force` and `/cert:tofu`; a convenient command should not weaken credential or server authentication. 288 3. Treat clipboard, drive, device, audio, and smart-card redirection as deliberate data-sharing decisions. 289 4. Use `+auth-only` to separate authentication and certificate failures from GUI/display problems. 290 5. FreeRDP packages differ by platform; `"$RDP" /help` is the local source of truth. 291 292 --- 293 294 ## // REFERENCES `fas:BookOpen` 295 296 1. [FreeRDP project](https://www.freerdp.com/) 297 2. [FreeRDP 3.30.0 release](https://github.com/FreeRDP/FreeRDP/releases/tag/3.30.0) 298 3. [FreeRDP macOS installation guidance](https://github.com/FreeRDP/FreeRDP/wiki/Prebuilds) 299 4. [Homebrew `freerdp` formula](https://formulae.brew.sh/formula/freerdp) 300 5. [Homebrew formula source — enabled X11 and SDL clients](https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/f/freerdp.rb) 301 302 #Cheatsheet #CommandReference #RDP #FreeRDP #RemoteAccess #Windows