Welcome to Microsoft Q&A Forum!
Based on your description, I would like to share some useful information to help you.
1. About "Attention unknown remote connection" after Windows updates
This behavior is expected after the April 2026 Windows security updates. Microsoft introduced new safeguards for connections launched from .rdp files to prevent phishing attacks.
If the .rdp file is not digitally signed, the Remote Desktop client displays “Unknown remote connection”, and all device redirection options (drives, clipboard, printers, etc.) are disabled by default, even if they are defined in the .rdp file. Users must explicitly review and re‑enable any required redirections. This does not apply to manual connections launched by typing a host name in MSTSC.
Reference: Understanding security warnings when opening Remote Desktop (RDP) files | Microsoft Learn
2. rdpsign error: “Unable to find the specified certificate”
This error means the certificate thumbprint does not match any usable certificate in the local certificate store on the machine running rdpsign.
To sign an .rdp file, the certificate must:
- Be installed locally (Current User or Local Computer → Personal store)
- Have an associated private key
- Be suitable for digital signing (publisher/code‑signing–style certificate)
- Be referenced using the exact thumbprint with no spaces
Note: The certificate used to sign an .rdp file is a publisher‑signing certificate, not the RDS server’s TLS certificate (unless that certificate is exported and imported locally with its private key).
3. How to Create a Certificate for RDP File Signing
You can use a self-signed certificate for testing or obtain a code signing certificate from a trusted Certificate Authority.
- Create a self-signed certificate
Open PowerShell as Administrator and run:
New-SelfSignedCertificate -CertStoreLocation "Cert:\CurrentUser\My" -Subject "CN=RDPFileSigner" -KeyUsage DigitalSignature
This creates a certificate in your Personal store. You can then use its thumbprint with rdpsign.
- Steps to Sign .RDP File
Find the certificate's thumbprint in certmgr.msc or certlm.msc. Use the command:
rdpsign /sha256 <certificate_thumbprint> <file.rdp>
(Ensure the thumbprint has no spaces.)
If you want to use the RDS server's certificate, ensure it is exported and imported into your local Personal store with the private key.
Reference: rdpsign | Microsoft Learn
I hope this information is helpful and thank you for choosing Microsoft Q&A to raise your concern.
Note: This answer has been translated using a translation tool. Please note that there may be grammatical or semantic errors. Thank you for your understanding. If there is any unclear part of the answer, please leave it in the comments and we will get back to you as soon as possible.