v2.1.8
RemoteAppClient 2.1.8 — signed releases
A release about how RemoteAppClient itself is built and shipped. The Windows executables attached below are code-signed, a server installed with setup.sh identifies its devices again, and one script covers every build. There is no database schema change.
Component versions are not aligned. Server and Windows console: 2.1.7.0. Agent, updater, Lite and the Linux console: 2.1.6.0.
Signed releases
RemoteAgent.exe,RemoteAgent.Updater.exe,RemoteClient.exeandRemoteClient.Lite.exeare signed with an Open Source Developer code-signing certificate and timestamped, so the signature stays valid after the certificate expires. Windows can now verify who published them: Smart App Control accepts a valid signature, and SmartScreen reputation builds up on the certificate instead of starting from zero with every new file.- The signing key lives in the cloud and needs the maintainer present, so CI keeps building unsigned.
build.ps1 -Tagrebuilds the tagged commit, signs it and swaps the assets — which is how these got here.
A fresh server that tells its devices apart
- The server identifies a device by its client certificate, whose name nginx forwards as
X-Client-Dn.deploy/steps/07-nginx.shset that header for the command channel but not for/api/, so a server installed withsetup.shfiled the telemetry of every device under a single device calledunknown, answered VNC password reports with 401, and showed every real machine as reporting only. - Hand-built configurations were not affected. It surfaced when a server was restored onto a new machine.
One build script for every job
.\build.ps1without parameters now explains itself.-Fleetbuilds agent, updater and console signed with the fleet certificate (-Deployreplaces this machine's installation),-Tagmakes the signed release build,-Msisigns the MSI the server generated,-ServerOnlybuilds the server package,-Unsignedis for development.- The server package can be built on Windows:
RemoteServer-linux-x64.tar.gz, ready for the console's Server update tab, packed with explicit Unix file modes — only the apphost andcreatedumpare executable — because a mode guessed by a Windows tool only fails once it reaches the Linux box. - Signing scripts and folders are machine-specific and live in
build.local.psd1next to the script, which git ignores. The public script carries no accounts, certificates or paths. - A build no longer stops this machine's agent services unless it is really about to overwrite them (
-Deploy).
Also
- The server logs executed SQL at Debug instead of Information; the journal had become mostly SQL text.
Upgrading
No schema change, no SQL. The server update is optional — it only quiets the log.
If your server was installed with setup.sh, fix its nginx site configuration even if you do not update anything else:
F=/etc/nginx/sites-available/<your-domain>
awk '/location \/api\/ \{/,/^[[:space:]]*\}[[:space:]]*$/' "$F" | grep -q 'X-Client-Dn' || sudo sed -i '/location \/api\/ {/,/^[[:space:]]*}[[:space:]]*$/ s|^\([[:space:]]*\)proxy_set_header X-Client-Verify \$ssl_client_verify;|&\n\1proxy_set_header X-Client-Dn $ssl_client_s_dn;|' "$F"
sudo nginx -t && sudo systemctl reload nginxDevices sort themselves out within a minute. Then delete the device whose Telemetry tab shows deviceId unknown — it only ever collected other machines' data.
Artifacts
RemoteAgent.exe,RemoteAgent.Updater.exe,RemoteClient.exe,RemoteClient.Lite.exe— Windows x64, self-contained single-file, signedRemoteServer-linux-x64.tar.gz— serverremoteclient_2.1.6_amd64.deb— Linux operator console