The Remote Desktop client supports the use of smartcards (eToken). A typical use case is when a user connects from home (Windows/MacOS/Linux) to their office computer (remote Windows desktop/server). The RDP client ‘forwards’ the local eToken connection to the remote machine so that applications on the remote desktop/server that require eToken authentication can be used.

Prerequisites:

  1. Possession of eToken with UTORauth-issued certificate and a current version of the SafeNet client installed on local and remote Windows hosts.
  2. Support RDC client:
    1. Windows: Built-in RDC client
    2. MacOS: Microsoft Remote Desktop 10 (downloadable from App Store)
    3. Linux: Remmina Client

Desktop Configuration:

  1. Windows
    1. Open Remote Desktop Connection Client, click on show options
    2. Under Local Resources tab, click on “More”
    3. Check the checkbox for Smart cards and save
  2. MacOS
    1. Open Microsoft Remote Desktop 10, add a PC profile
    2. Fill in the PC name (hostname of the remote desktop) and User account (account to access the remote server/desktop)
    3. Under Devices & Audio tab, check the checkbox for Smart cards and save
  3. Linux
    1. Open Remmina Remote Desktop Client
    2. Create a new connection profile for RDP
    3. Under Basic tab, fill in the Server (hostname/IP address of the remote server/desktop), Username and Password (account to access the remote server/desktop)
    4. Under Advanced tab, check the chekbox for Share smartcard and save

Usage:

  • Plug in the eToken on the local desktop
  • Start the Remote Desktop Client (RDC client on Windows, Microsoft Remote Desktop 10 on MacOS, Remmina Remote Desktop Client on Linux)
  • Select the proper profile to connect to remote server

Troubleshooting:

  • To test the availability of the X.509 certificate on the eToken to the remote end, open Safenet Authentication Client on the remote server. You should see the eToken with your name listed there. If not, close the RDC connection, re-plug the eToken, making sure the eToken LED is active, and restart the RDC.