Skip to content

Solution for "Failed to secure tcp" timeout #147

Description

@YuZhiYuanDev

Problem Description

When using the RustDesk client, if both key and token are provided, the client will call secure_tcp to attempt establishing an encrypted connection with the server. However, the server does not respond to this request, causing the client to time out.

Relevant code: src/client.rs

if !key.is_empty() && !token.is_empty() {
    // mainly for the security of token
    secure_tcp(&mut socket, &key)
        .await
        .map_err(|e| anyhow!("Failed to secure tcp: {}", e))?;
}

If not logged into the API account, token is empty, so secure_tcp is not triggered and no timeout occurs.
Even in non-logged-in state, encrypted connection is still possible; you could have secure_tcp return directly (skip the actual encryption handshake).


Solutions

1. Use our forked server (recommended)

If you have high requirements for encryption or want to avoid timeout while keeping the client logged in, it is recommended to use the following fork:

This fork optimizes the encryption handshake process, is compatible with scenarios where both key and token are provided, and additionally supports WebSocket connections and disabling UDP functionality.

2. Specify the same key on the server side

When starting hbbs and hbbr, set the same custom key using the -k parameter:

hbbs -r <relay-server-ip[:port]> -k <key>
hbbr -k <key>

This solution is suitable for scenarios with low encryption requirements.

3. Log out of the client before connecting

If the server uses a system-generated key (or a custom key pair), a logged-in client may time out or fail to connect.
Solution: Log out of the client before connecting.

4. Modify the client source code and compile it yourself

Fork the official code, modify secure_tcp to return directly (skip the encryption handshake), then compile via GitHub Actions.
Reference: Official build documentation


Recommendation

  • Solution 1 (using our fork) is highly recommended: No need to modify the client, keep logged-in state, good compatibility, and supports enhanced features like WebSocket and disabling UDP.
  • If encryption requirements are low, choose Solution 2 (specify key on server).
  • If you are okay with logging out, choose Solution 3.
  • If you are willing to compile yourself, choose Solution 4.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions