Certificates
What PluggedDesk does with a server's certificate, the three settings, and what each one does not protect you from.
Why it matters
When you connect, the server shows a certificate. It is how you know that the computer answering is the one you meant, and not something in between that will pass your password along after reading it.
The three settings
The setting is Certificate policy (rdp.security.certificatePolicy), under Security in a connection's
properties. Like every setting it can be made on a folder, a computer or a connection.
| Setting | What PluggedDesk does | Use it when |
|---|---|---|
| strict (the default) | Accepts only a certificate that your computer can verify. Anything else ends the attempt before a credential is sent. | The server has a certificate from an authority your computer trusts. In a Windows domain, that is usually the case. |
| trust-on-first-use | Accepts the certificate the server shows. | The server has a self-signed certificate and you are on a network you trust. |
| prompt-each-session | Accepts the certificate for this one session. | You want to decide each time. |
There is no setting that ignores certificate errors for good. That is by design.
What the second and third settings do not do
PluggedDesk does not yet remember the certificate it accepted. With trust-on-first-use, it accepts whatever certificate the server shows, each time. If that certificate were different tomorrow, PluggedDesk would not notice.
So today these two settings protect you less than their names suggest. They tell PluggedDesk that you have decided to trust the path to this server. Use them on networks where that is a reasonable thing to decide, and prefer strict everywhere else.
Remembering the accepted certificate, and refusing a different one, is planned. This page will say when it is done.
Making strict work
If a server is refused under strict, the cure is a certificate your computer can verify:
- In a domain, give the server a certificate from your own certificate authority. Computers in the domain trust it already.
- Outside a domain, install the server's certificate, or the certificate of whoever issued it, in the Trusted Root Certification Authorities store of your computer.
What you will see
| The tab says | It means |
|---|---|
| Certificate rejected | The policy is strict and the certificate could not be verified. No credential was sent. |
| Connect failed, under strict, with a self-signed certificate | The same, reported one step earlier by the engine on some systems. No credential was sent. |
| Authentication failed | The certificate was accepted, and the server refused the user name or the password. |
After a rejection, the tab offers to accept the certificate for this session, or always for this connection. The second is a saved change to the connection's certificate policy, and the status bar says that it was made.