rdpsign impossible de trouver le certificat spécifié

Frédéric STOCK ([email protected]) 100 Points de réputation
2026-04-15T07:42:55.4566667+00:00

Bonjour,

depuis ce matin, suite maj windows, lors de connexion RDS, il est indiqué :

"attention connexion distante inconnue" et demande de cocher les options notamment de redirection qui viennent écraser celles définies dans me .RDP.

Aussi, je souhaitais signer le .RDP, mais lorsque j'utilise le hash d'un certificat présent sur mon PC (certificat du serveur RDS sur lequel je veux me connecter) via la commande rdpsign, j'obtiens l'erreur:

"impossible de trouver le certificat spécifié".

Faut-il utilise un certificat spécifique pour signer le .RDP ?

Si oui comment le créer ?

Merci.

Cdlt.

Fred.

Windows pour les entreprises | Windows Server | Expérience utilisateur | Clients de bureau à distance

Réponse acceptée par l’auteur de la question
Daphne Huynh (WICLOUD CORPORATION) 1,570 Points de réputation Personnel externe Microsoft Modérateur
2026-04-16T02:50:43.29+00:00

Welcome to Microsoft Q&A Forum! 

Based on your description, I would like to share some useful information to help you.

1. About "Attention unknown remote connection" after Windows updates

This behavior is expected after the April 2026 Windows security updates. Microsoft introduced new safeguards for connections launched from .rdp files to prevent phishing attacks.

If the .rdp file is not digitally signed, the Remote Desktop client displays “Unknown remote connection”, and all device redirection options (drives, clipboard, printers, etc.) are disabled by default, even if they are defined in the .rdp file. Users must explicitly review and re‑enable any required redirections. This does not apply to manual connections launched by typing a host name in MSTSC.

Reference: Understanding security warnings when opening Remote Desktop (RDP) files | Microsoft Learn

2. rdpsign error: “Unable to find the specified certificate”

This error means the certificate thumbprint does not match any usable certificate in the local certificate store on the machine running rdpsign.

To sign an .rdp file, the certificate must:

  • Be installed locally (Current User or Local Computer → Personal store)
  • Have an associated private key
  • Be suitable for digital signing (publisher/code‑signing–style certificate)
  • Be referenced using the exact thumbprint with no spaces

Note: The certificate used to sign an .rdp file is a publisher‑signing certificate, not the RDS server’s TLS certificate (unless that certificate is exported and imported locally with its private key).

3. How to Create a Certificate for RDP File Signing

You can use a self-signed certificate for testing or obtain a code signing certificate from a trusted Certificate Authority.

  • Create a self-signed certificate

Open PowerShell as Administrator and run:

New-SelfSignedCertificate -CertStoreLocation "Cert:\CurrentUser\My" -Subject "CN=RDPFileSigner" -KeyUsage DigitalSignature

This creates a certificate in your Personal store. You can then use its thumbprint with rdpsign.

  • Steps to Sign .RDP File

Find the certificate's thumbprint in certmgr.msc or certlm.msc. Use the command:

rdpsign /sha256 <certificate_thumbprint> <file.rdp>

(Ensure the thumbprint has no spaces.)

If you want to use the RDS server's certificate, ensure it is exported and imported into your local Personal store with the private key.

Reference: rdpsign | Microsoft Learn

I hope this information is helpful and thank you for choosing Microsoft Q&A to raise your concern. 

Note: This answer has been translated using a translation tool. Please note that there may be grammatical or semantic errors. Thank you for your understanding. If there is any unclear part of the answer, please leave it in the comments and we will get back to you as soon as possible. 

Cette réponse a-t-elle été utile ?

0 commentaires Aucun commentaire

0 réponses supplémentaires

Votre réponse

Les réponses peuvent être marquées comme « Acceptées » par l’auteur de la question et « Recommandées » par les modérateurs, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur.