Skip to content

Add destination address mappings - #3

Open
SoundGoof wants to merge 1 commit into
masterfrom
destination-mapping
Open

SoundGoof wants to merge 1 commit into
masterfrom
destination-mapping

Conversation

@SoundGoof

Copy link
Copy Markdown
Member

Summary

Add hostname-to-IP destination mappings so clients request an RDP server by FQDN while rdpgw connects to a configured IP address.

Configuration

Server:
  HostSelection: unsigned
  Destinations:
    - Hostname: rdp.example.com
      Address: 192.0.2.42
      Port: 3389

Port defaults to 3389. IPv4 and IPv6 are supported.

Behavior

  • Authorizes connections using the requested FQDN.
  • Dials the configured IP address.
  • Preserves the FQDN for RDP certificate validation.
  • Adds mapped destinations to the effective host list.
  • Remains compatible with legacy Server.Hosts.
  • Normalizes hostname case and trailing DNS dots.
  • Rejects duplicate or malformed mappings during startup.
  • Treats explicit mappings as curated exceptions in HostSelection: any.

Security

  • Enforces dynamic destination policy at channel dial time.
  • Dials validated IPs to prevent DNS rebinding.
  • Applies context-aware DNS and TCP timeouts.
  • Uses staggered fallback across resolved addresses.
  • Preserves resolver cancellation and timeout errors.

Testing

  • make build
  • make test
  • go vet ./cmd/rdpgw/...
  • Focused race tests for resolver and dial fallback paths.
  • git diff --check

@SoundGoof
SoundGoof force-pushed the destination-mapping branch from 8750d42 to 24cb11d Compare August 7, 2026 07:03
@SoundGoof
SoundGoof force-pushed the destination-mapping branch from ff0e8b6 to 24cb11d Compare August 21, 2026 10:41
@SoundGoof
SoundGoof force-pushed the destination-mapping branch from 24cb11d to 9d49442 Compare August 21, 2026 10:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant