Commit graph

2 commits

Author SHA1 Message Date
1f111b78f3 Add rdp-test.sh for diagnosing the RDP auth failure
xfreerdp gives far more specific error output than GNOME Connections'
generic "Authentication failed: connection failed" message. Run on
the travel laptop, writes output to rdp-test-output.txt in this same
repo so it can just be committed/pushed back rather than pasted.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 21:54:59 +03:00
ef28afb9b8 Split into setup-local.sh + setup-remote.sh, add RDP configuration
Renames bootstrap.sh to setup-local.sh to match its actual scope (the
travel laptop only) and adds setup-remote.sh for the machine you
Remote-SSH/RDP into, since that's a different machine's one-time setup
and was already living outside setup-local.sh's reach (same reasoning
as the existing Tailscale-SSH prerequisite).

setup-remote.sh configures GNOME's system-level RDP (works from a cold
GDM login screen, not just an existing session) restricted to the
tailscale interface via a ufw rule, a self-signed TLS cert, and RDP
credentials that are deliberately separate from the account password
and never cached - only prompted if unset. Shares step-tracking helpers
with setup-local.sh via a new lib.sh rather than duplicating them.

Tested the branching logic (credentials-already-set, RDP-already-
enabled, ufw-already-active-with-rule, ufw-inactive-confirm/decline)
against realistic stubbed command output. Caught and fixed a real bug
in the process: the inactive/active ufw check used a bare `grep -qi
active`, which also matches the substring inside "inactive" - it was
silently skipping the enable-confirmation gate and going straight to
adding a firewall rule on a firewall that was never turned on. Fixed
by anchoring the match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-26 21:25:19 +03:00