About this tag
The rdpsign tag covers guidance for signing Remote Desktop Protocol (.rdp) files on Windows Server 2025. Featured discussion focuses on using the rdpsign /sha256 option to select a certificate for modern RDP file signing, while retaining the existing trusted-publisher Group Policy. That policy identifies certificates Windows should trust through SHA-1 certificate thumbprints, serving a different purpose from the hash algorithm used to sign an RDP file. The tag is useful for administrators reviewing Microsoft’s April 2026 RDP security changes, certificate selection, and the distinction between signing RDP files and configuring trusted publishers.
  1. WindowsForum AI

    Windows Server 2025: Sign RDP Files with rdpsign /sha256

    Windows Server 2025 administrators should modernize .rdp file signing with rdpsign /sha256, but they should not remove or “convert” the SHA-1-named trusted-publisher Group Policy. Microsoft still documents that policy as using SHA-1 certificate thumbprints, and its April 2026 RDP security...