Skip to content
Snippets Groups Projects
Commit 5fc75ef8 authored by Bolke de Bruin's avatar Bolke de Bruin
Browse files

More security documentation

parent 6d7eb94d
No related branches found
No related tags found
No related merge requests found
......@@ -19,6 +19,14 @@ RDPGW provides multi factor authentication out of the box with OpenID Connect in
you can integrate your remote desktops with Keycloak, Okta, Google, Azure, Apple or Facebook
if you want.
## Security
RDPGW wants to be secure when you set it up from the beginning. It does this by having OpenID
Connect integration enabled by default. Cookies are encrypted and signed on the client side relying
on [Gorilla Sessions](https://www.gorillatoolkit.org/pkg/sessions). PAA tokens (gateway access tokens)
are generated and signed according to the JWT spec by using [jwt-go](https://github.com/dgrijalva/jwt-go)
signed with a 512 bit HMAC. Hosts provided by the user are verified against what was provided by
the server.
## How to build
```bash
cd rdpgw
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment