can RDM support RDP basic authentication to RDP Gateway?

can RDM support RDP basic authentication to RDP Gateway?

avatar

MacOS: Tahoe 26.6.2
RDM MacOS: 2026.2.4.4

We are seeking replacement of Microsoft RD Gateway, and GO Remote Desktop Gateway (https://github.com/bolkedebruin/rdpgw) is one of candidates. During the evaluation, we have succeeded to make rdpgw to support OpenID Connect and PAM/local authentication in different setup. OIDC works great for on demand connection, but PAM/local authentication fits our RD client scenario more. One of requirements to use PAM/local authentication is RD client needs to support basic authentication (via TLS). I checked RDM for possible option to enable/use basic authentication when connecting via rdpgw, but no luck. Would you be kind to elaborate more info?

here's the .rdp file to test basic authentication via rdpgw. It works with Windows app (from App store)

full address:s:10.104.103.111:3389
gatewayhostname:s:test04.lab123.com
gatewayusagemethod:i:1
gatewaycredentialssource:i:4
gatewayprofileusagemethod:i:1
promptcredentialonce:i:0
authentication level:i:2
enablecredsspsupport:i:1

Regards,
Eric

All Comments (3)

avatar

Hi Eric

This will require a bit of investigation on our side I think; I've taken a look today and some things are really not clear to me. Maybe you can answer some of the questions, but I feel it will also require me to make an issue on the rdpgw project itself to get clarification from them.

I'm looking at the PAM/Local authentication docs, this is what you're wanting to use right?

They specifically call out "The default Windows client mstsc does not support basic authentication". But, under "Compatible Clients" for Windows they list RDCMan, mRemoteNG and RoyalTS, which are using mstsc (they embed mstscax.dll, the literal same assembly that mstsc uses). Have you tried this setup from a Windows client, and did it work? If so, which client did you use?

I know we're talking about Mac here and they list Microsoft Remote Desktop (actually Windows App) and you confirmed that works, so clearly Microsoft's Mac client does support basic authentication. But they also list Royal TSX, which embeds FreeRDP the same way RDM does. Their Linux section lists Remmina and KRDC which all use FreeRDP, and it lists FreeRDP directly but with the caveat "with basic auth support". That's interesting because as far as I can tell, FreeRDP does not support basic authentication for talking to a Gateway and the caveat doesn't make any sense. There's no option, flag or "Authorization: Basic" support anywhere in FreeRDP's RDG transport. Their own issue tracker seems to confirm it, with the workaround to use the Microsoft client.

My conclusion right now is:

  • The only clients genuinely doing HTTP Basic to an RD Gateway are the Microsoft ones: Windows App / MS Remote Desktop for macOS / iOS / Android. Which matches your report.
  • Every FreeRDP-derived client in that list: Remmina, KRDC, Royal TSX, and RDM negotiates NTLM/Kerberos and will fail against a Basic-only rdpgw.
  • The mstscax.dll-derived Windows entries can't work either, by rdpgw's own admission about mstsc.


I'm happy to be proved wrong about this, but the evidence I have here indicates this is accurate. Have you tried other client's than Windows App and RDM? Maybe on other platforms than Mac? Are there any that you can confirm to work?

I understand this doesn't answer your original question, but if this is working already with FreeRDP based clients then I need to understand how it's working, because from the code it appears it cannot. If it doesn't work from FreeRDP and the rdpgw documentation is inaccurate, then the question becomes "can we modify FreeRDP to support this scenario?".

Appreciate your feedback, and please let me know if something isn't clear or you have questions about my response

Kind regards,

Richard Markievicz

avatar

Hi Richard,

Thanks for prompt reply. The PAM/Local authentication doc section is not 100% accurate. I've tested mstsc.exe (Windows 10/11 built-in) and RDCMan, and none of them work.
mstsc.exe works with rdpgw+OIDC, but not rdpgw+PAM.

Your feedback is very useful to indicate FeeRDP-derived and mstscax.dll-derived dont support basic auth. Appreciate your support. We will see what we can do.

Regards,
Eric

avatar

Hi Eric

I've opened an issue on the rdpgw side to check what they say, and make sure we don't miss a detail. Maybe there is a way but the documentation is just not helpful.

Thanks and kind regards,

Richard Markievicz