Skip to content

Generate unique Keychain-backed RDP credentials per baseline - #5

Merged
rkttu merged 2 commits into
mainfrom
copilot/generate-unique-rdp-credential
Sep 4, 2026
Merged

rkttu merged 2 commits into
mainfrom
copilot/generate-unique-rdp-credential

Conversation

Copilot AI commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Baseline images previously shared a source-coded administrator password. This change generates a unique credential per build and requires legacy baselines to be rebuilt.

  • Credential lifecycle

    • Generate a cryptographically secure, shell-safe password.
    • Store it in macOS Keychain under a baseline-specific UUID.
    • Delete credentials when baselines are replaced, destroyed, or fail to build.
  • Metadata and migration

    • Add an explicit metadata schema version and credential identifier.
    • Keep plaintext passwords out of metadata.json.
    • Reject legacy baselines and baselines missing their Keychain credential.
  • Provisioning and RDP

    • Pass the password to unattended setup through an encoded PowerShell command.
    • Retrieve it from Keychain for the embedded FreeRDP session.
    • Preserve loopback-only RDP forwarding.
    • Remove temporary deployment media and the guest unattended file after provisioning.
  • Test utilities

    • Remove hard-coded credentials from C RDP utilities.
    • Inject test credentials through MSBX_RDP_USERNAME and MSBX_RDP_PASSWORD.

Copilot AI linked an issue Sep 4, 2026 that may be closed by this pull request
9 tasks
Co-authored-by: rkttu <1297346+rkttu@users.noreply.github.com>
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Copilot AI changed the title [WIP] Generate a unique RDP credential for each baseline image build Generate unique Keychain-backed RDP credentials per baseline Sep 4, 2026
Copilot AI requested a review from rkttu September 4, 2026 06:31
@rkttu
rkttu marked this pull request as ready for review September 4, 2026 06:45
Copilot AI lite review requested due to automatic review settings September 4, 2026 06:45
@rkttu
rkttu merged commit 09b59c9 into main Sep 4, 2026
1 of 2 checks passed
@rkttu
rkttu deleted the copilot/generate-unique-rdp-credential branch September 4, 2026 06:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

There are at least two verified correctness/security issues in the updated run/provisioning flow that should be addressed before merging.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR replaces the repository-wide fixed Windows Sandbox RDP password with per-baseline, cryptographically generated credentials stored in macOS Keychain, and threads that credential through unattended provisioning and the embedded FreeRDP session while updating test tooling to accept injected credentials.

Changes:

  • Generate a per-baseline password, store it in Keychain under a baseline-specific UUID, and persist only schemaVersion + credentialID in metadata.json.
  • Pass the per-baseline password into the unattended setup flow and ensure provisioning artifacts are removed.
  • Update embedded RDP view + C FreeRDP test utilities to accept credentials (via Swift wiring / MSBX_RDP_USERNAME + MSBX_RDP_PASSWORD for test tools).
File summaries
File Description
src/MacSandbox/Views/SandboxView.swift Passes the runtime Keychain-backed password into the embedded RDP view.
src/MacSandbox/Views/RDPHostView.swift Makes the embedded RDP view require an explicit password (no longer sourced from a constant).
src/MacSandbox/MacSandboxApp.swift Injects test-tool credentials from environment variables and wires them into CFreeRDP utilities.
src/MacSandbox/Core/UnattendBuilder.swift Accepts per-baseline password and applies it during FirstLogonCommands; removes unattend.xml afterward.
src/MacSandbox/Core/SandboxRunner.swift Validates baseline schema + Keychain credential presence; loads/clears password for embedded RDP.
src/MacSandbox/Core/SandboxModels.swift Adds metadata schema versioning and a Keychain credential identifier.
src/MacSandbox/Core/SandboxConfig.swift Removes the fixed password constant; keeps only the account name.
src/MacSandbox/Core/RDPSession.swift Narrows responsibility to local port selection for embedded RDP.
src/MacSandbox/Core/BaselineCredentialStore.swift Implements Keychain-backed credential generation/save/load/delete.
src/MacSandbox/Core/BaselineBuilder.swift Generates/saves credentials per build, updates metadata, and deletes credentials on failure/rebuild.
src/MacSandbox/Core/BaselineAdmin.swift Deletes the Keychain credential when destroying the baseline.
src/CFreeRDP/rdp_filetest.c Removes hard-coded credentials; accepts injected username/password.
src/CFreeRDP/rdp_cliptest.c Removes hard-coded credentials; accepts injected username/password.
src/CFreeRDP/rdp_capture.c Removes hard-coded credentials; accepts injected username/password.
src/CFreeRDP/include/CFreeRDP.h Updates headers to match new credential-injected function signatures.
Package.swift Links the Security framework for Keychain access.
ARCHITECTURE.md Updates documentation to reflect Keychain-backed per-baseline RDP credentials.
Review details
  • Files reviewed: 17/17 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +91 to +94
defer {
rdpPassword = ""
isRunning = false
}
Comment on lines +133 to 136
<Order>11</Order>
<CommandLine>reg add "HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa" /v LimitBlankPasswordUse /t REG_DWORD /d 0 /f</CommandLine>
<Description>allow blank password over RDP</Description>
<Description>configure RDP password policy</Description>
</SynchronousCommand>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Generate a unique RDP credential for each baseline image build

4 participants