Skip to content

v2.1.8

Choose a tag to compare

@github-actions github-actions released this 16 Sep 15:35
· 6 commits to master since this release
80d5633

RemoteAppClient 2.1.8 — signed releases

A release about how RemoteAppClient itself is built and shipped. The Windows executables attached below are code-signed, a server installed with setup.sh identifies its devices again, and one script covers every build. There is no database schema change.

Component versions are not aligned. Server and Windows console: 2.1.7.0. Agent, updater, Lite and the Linux console: 2.1.6.0.

Signed releases

  • RemoteAgent.exe, RemoteAgent.Updater.exe, RemoteClient.exe and RemoteClient.Lite.exe are signed with an Open Source Developer code-signing certificate and timestamped, so the signature stays valid after the certificate expires. Windows can now verify who published them: Smart App Control accepts a valid signature, and SmartScreen reputation builds up on the certificate instead of starting from zero with every new file.
  • The signing key lives in the cloud and needs the maintainer present, so CI keeps building unsigned. build.ps1 -Tag rebuilds the tagged commit, signs it and swaps the assets — which is how these got here.

A fresh server that tells its devices apart

  • The server identifies a device by its client certificate, whose name nginx forwards as X-Client-Dn. deploy/steps/07-nginx.sh set that header for the command channel but not for /api/, so a server installed with setup.sh filed the telemetry of every device under a single device called unknown, answered VNC password reports with 401, and showed every real machine as reporting only.
  • Hand-built configurations were not affected. It surfaced when a server was restored onto a new machine.

One build script for every job

  • .\build.ps1 without parameters now explains itself. -Fleet builds agent, updater and console signed with the fleet certificate (-Deploy replaces this machine's installation), -Tag makes the signed release build, -Msi signs the MSI the server generated, -ServerOnly builds the server package, -Unsigned is for development.
  • The server package can be built on Windows: RemoteServer-linux-x64.tar.gz, ready for the console's Server update tab, packed with explicit Unix file modes — only the apphost and createdump are executable — because a mode guessed by a Windows tool only fails once it reaches the Linux box.
  • Signing scripts and folders are machine-specific and live in build.local.psd1 next to the script, which git ignores. The public script carries no accounts, certificates or paths.
  • A build no longer stops this machine's agent services unless it is really about to overwrite them (-Deploy).

Also

  • The server logs executed SQL at Debug instead of Information; the journal had become mostly SQL text.

Upgrading

No schema change, no SQL. The server update is optional — it only quiets the log.

If your server was installed with setup.sh, fix its nginx site configuration even if you do not update anything else:

F=/etc/nginx/sites-available/<your-domain>
awk '/location \/api\/ \{/,/^[[:space:]]*\}[[:space:]]*$/' "$F" | grep -q 'X-Client-Dn' || sudo sed -i '/location \/api\/ {/,/^[[:space:]]*}[[:space:]]*$/ s|^\([[:space:]]*\)proxy_set_header X-Client-Verify \$ssl_client_verify;|&\n\1proxy_set_header X-Client-Dn $ssl_client_s_dn;|' "$F"
sudo nginx -t && sudo systemctl reload nginx

Devices sort themselves out within a minute. Then delete the device whose Telemetry tab shows deviceId unknown — it only ever collected other machines' data.

Artifacts

  • RemoteAgent.exe, RemoteAgent.Updater.exe, RemoteClient.exe, RemoteClient.Lite.exe — Windows x64, self-contained single-file, signed
  • RemoteServer-linux-x64.tar.gz — server
  • remoteclient_2.1.6_amd64.deb — Linux operator console