MacOS: Tahoe 26.6.2
RDM MacOS: 2026.2.4.4
We are seeking replacement of Microsoft RD Gateway, and GO Remote Desktop Gateway (https://github.com/bolkedebruin/rdpgw) is one of candidates. During the evaluation, we have succeeded to make rdpgw to support OpenID Connect and PAM/local authentication in different setup. OIDC works great for on demand connection, but PAM/local authentication fits our RD client scenario more. One of requirements to use PAM/local authentication is RD client needs to support basic authentication (via TLS). I checked RDM for possible option to enable/use basic authentication when connecting via rdpgw, but no luck. Would you be kind to elaborate more info?
here's the .rdp file to test basic authentication via rdpgw. It works with Windows app (from App store)
full address:s:10.104.103.111:3389
gatewayhostname:s:test04.lab123.com
gatewayusagemethod:i:1
gatewaycredentialssource:i:4
gatewayprofileusagemethod:i:1
promptcredentialonce:i:0
authentication level:i:2
enablecredsspsupport:i:1
Regards,
Eric
Hi Eric
This will require a bit of investigation on our side I think; I've taken a look today and some things are really not clear to me. Maybe you can answer some of the questions, but I feel it will also require me to make an issue on the rdpgw project itself to get clarification from them.
I'm looking at the PAM/Local authentication docs, this is what you're wanting to use right?
They specifically call out "The default Windows client mstsc does not support basic authentication". But, under "Compatible Clients" for Windows they list RDCMan, mRemoteNG and RoyalTS, which are using mstsc (they embed mstscax.dll, the literal same assembly that mstsc uses). Have you tried this setup from a Windows client, and did it work? If so, which client did you use?
I know we're talking about Mac here and they list Microsoft Remote Desktop (actually Windows App) and you confirmed that works, so clearly Microsoft's Mac client does support basic authentication. But they also list Royal TSX, which embeds FreeRDP the same way RDM does. Their Linux section lists Remmina and KRDC which all use FreeRDP, and it lists FreeRDP directly but with the caveat "with basic auth support". That's interesting because as far as I can tell, FreeRDP does not support basic authentication for talking to a Gateway and the caveat doesn't make any sense. There's no option, flag or "Authorization: Basic" support anywhere in FreeRDP's RDG transport. Their own issue tracker seems to confirm it, with the workaround to use the Microsoft client.
My conclusion right now is:
I'm happy to be proved wrong about this, but the evidence I have here indicates this is accurate. Have you tried other client's than Windows App and RDM? Maybe on other platforms than Mac? Are there any that you can confirm to work?
I understand this doesn't answer your original question, but if this is working already with FreeRDP based clients then I need to understand how it's working, because from the code it appears it cannot. If it doesn't work from FreeRDP and the rdpgw documentation is inaccurate, then the question becomes "can we modify FreeRDP to support this scenario?".
Appreciate your feedback, and please let me know if something isn't clear or you have questions about my response
Kind regards,
Richard Markievicz
Hi Richard,
Thanks for prompt reply. The PAM/Local authentication doc section is not 100% accurate. I've tested mstsc.exe (Windows 10/11 built-in) and RDCMan, and none of them work.
mstsc.exe works with rdpgw+OIDC, but not rdpgw+PAM.
Your feedback is very useful to indicate FeeRDP-derived and mstscax.dll-derived dont support basic auth. Appreciate your support. We will see what we can do.
Regards,
Eric
Hi Eric
I've opened an issue on the rdpgw side to check what they say, and make sure we don't miss a detail. Maybe there is a way but the documentation is just not helpful.
Thanks and kind regards,
Richard Markievicz