SurePassID Apache Guacamole Remote Access Guide

SurePassID Authentication Server

About the Apache Guacamole Remote Access Guide

This guide explains how to use Apache Guacamole to add SurePassID Phishing-Resistant MFA to Remote Access via SAML2 and OIDC to harden your organization’s remote access security. The purpose of this guide is to provide a reference for system administrators of the SurePassID system.

What is Apache Guacamole?

Apache Guacamole is a clientless remote desktop gateway that allows you to access your computers from anywhere using a web browser. It supports standard protocols like VNC, RDP, and SSH 

Here are some key features:

  • Clientless Access: No need for plugins or client software; you can access your desktops through any HTML5-compatible web browser.

  • Remote Access: You can control access to remote computers or virtual machines via a web browser, making it convenient for remote administration.

  • Open Source: Apache Guacamole is free and open source, licensed under the Apache License, Version 2.0 

  • Cloud Integration: It can be combined with cloud computing for enhanced flexibility and resilience 

  • On-premises Integration: Apache Guacamole works without cloud infrastructure, making it suitable for air-gapped environments to secure network access.

  • Support: Community support for Apache Guacamole is available through public mailing lists, and dedicated commercial support is also available through third-party companies.

How is Guacamole Software Architected?

Guacamole comprises two main parts: guacamole-server, which handles connectivity and RDP protocols, and guacamole-client, which provides the portal UI for users and administrators through a servlet container like Apache Tomcat. The guacamole-client, written in JavaScript, is served to the user's browser by the web server where the product installed.

The system is usually installed on any Linux VM, but it can also be installed on a Windows server in a Docker container or any Java Application Server (JAS) such as JBoss. The system requires a database to store RDP connection info, user profiles, and remote access policies for each user. By default, the guacamole-client authenticates users based on the configured authentication method. For phishing resistant MFA, the guacamole-client is configured to use one of the SurePassID Phishing-Resistant MFA Identity Providers (SAML2 or OIDC, OpenID Connect).

What is the Guacamole Data Flow?

Guacamole consists of multiple components. The web application (guacamole-client) is designed to be simple, with most tasks handled by lower-level components.

Here's a simplified overview of its network flow:

  1. User Connection: Users connect to the Guacamole server using a web browser. E.g. https://rdp.guacamole.surepassid.com. The guacamole-client redirects the user to the installed SurePassID MFA Phishing- Resistant Identity Providers where the user is authenticated, and the identity claims of the user are sent back to the guacamole-client. This is true of admin accounts and non-admin accounts.

  2. User Host Selection List. Based on policy, the guacamole-client presents the user with a list of remote hosts they are allowed to access. The user selects the remote host they would like to access. If the user has only one connection on their account, they rdp into that account and do not see this.

  1. Guacamole Protocol: The guacamole-client communicates with the Guacamole server using the Guacamole protocol using HTTP transport.

  2. Guacamole Proxy (guacd): The guacamole-server server forwards the Guacamole protocol to guacd, the native Guacamole proxy.

  3. Remote Desktop Protocols: guacd translates the Guacamole protocol to the appropriate remote desktop protocol (like RDP or VNC) and connects to the remote desktop server on behalf of the user.

  4. Remote Host: With the proper host credentials, the user is logged into each host. It would be possible to use SurePassID WLM to add traditional authentication on each host. E.g the user uses their YubiKey for phishing resistant MFA to access the guacamole-client and then they could use their YubiKey with OTP for access to each remote host.

  5. What the user sees: After connecting the user will see the connected host in the guacamole-client.

The user can review their sessions in Guacamole anytime, as shown below.

Jump Server Security Considerations

Although every company’s network configuration is different, there are some common practices. To lock down a jump server using Guacamole here are some options:

  1. Guacamole should be the only entry point to get to protected network hosts and act as the jump server. You manage all back-end hosts from Guacamole.

  2. Guacamole can be used as a front end to your jump server. Jump server only allows https traffic from Guacamole server.

Reverse Proxy Considerations

Depending on your network/firewall configuration, you might want to use a reverse proxy like NGINX to limit traffic to Guacamole. If this is the case, you could have NGINX do the phishing-resistant MFA and if successful, send the user to the Guacamole URL.

On-Boarding of Users

  1. Add users with phishing-resistant tokens to SurePassID manually or through automated methods.

  2. Users register their tokens with SurePassID.

  3. The Guacamole administrator adds the user to Guacamole and configures their account information. Optionally the administrator can set user’s password

  4. Users access the Guacamole URL to log in, select hosts, etc.

Supporting Guacamole

To install and configure Apache Guacamole, you will need a team with a mix of skills and expertise to ensure a smooth and successful setup. Here are the key roles and their responsibilities:

  1. System Administrator: This person should have experience with server management, including installing and configuring software on Linux or Windows servers. They will be responsible for setting up the server environment, installing dependencies, and ensuring the server is secure and properly maintained.

  2. Network Administrator: This role involves managing network configurations, including setting up firewalls, opening necessary ports, and ensuring secure remote access. They will also handle any network-related issues that may arise during the installation and configuration of Guacamole.

  3. Database Administrator: If you plan to use a database for user authentication or storing connection configurations, a database administrator will be needed to set up and manage the database. This includes installing and configuring the database software, creating necessary tables, and ensuring data integrity and security.

  4. Security Specialist: This person will ensure that the Guacamole installation is secure. They will implement best security practices, such as setting up strong passwords, enabling two-factor authentication, and regularly reviewing access logs for any suspicious activity.

  5. Web Developer: If you plan to customize the Guacamole interface or integrate it with other web applications, a web developer with experience in HTML, CSS, and JavaScript will be needed. They can help tailor the user interface to meet your specific needs.

  6. Support Staff: After the installation, you will need support staff to handle any issues that users may encounter. This includes troubleshooting connection problems, providing user support, and maintaining documentation.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com