{"componentChunkName":"component---src-templates-blog-template-js","path":"/blog/psono-gateway","result":{"data":{"markdownRemark":{"html":"<p>We are excited to announce the release of <strong>Psono Gateway</strong>, a new way for teams to launch secure, browser-based SSH,\nRDP, and VNC sessions directly from connection entries stored in Psono. It brings secrets and remote access together in\none controlled workflow, without requiring users to copy credentials or expose target systems directly to their devices.</p>\n<p>Psono Gateway is available today exclusively for <strong>Psono Enterprise Edition</strong> and requires a valid Enterprise Edition\nlicence. It cannot be used with the Community Edition server.</p>\n<h2>Remote Access from the Password Manager</h2>\n<p>Administrators often need both a credential and a separate tool to connect to a server, workstation, or other protected\nsystem. That creates extra steps and can encourage credentials to be copied into clipboards, terminals, or locally saved\nconnection profiles.</p>\n<p>With Psono Gateway, users can open an SSH, RDP, or VNC connection entry and select <strong>Launch</strong>. Psono resolves the permitted\ncredentials, selects an available Gateway, and opens the session in a browser. The same workflow is available from the\nPsono webclient and the Psono app.</p>\n<p>Psono Gateway is based on <a href=\"https://guacamole.apache.org/\" rel=\"nofollow\">Apache Guacamole</a>, the established\nclientless remote desktop gateway. We integrated Guacamole with Psono's encrypted secret handling, authorization model,\nGateway clusters, and web and mobile clients to provide a purpose-built launch flow for Psono environments.</p>\n<h2>Key Features</h2>\n<ul>\n<li><strong>SSH, RDP, and VNC in the browser:</strong> Connect to Linux servers, Windows systems, and VNC desktops without installing a\ndedicated protocol client on the user's device.</li>\n<li><strong>Flexible authentication:</strong> Use credentials stored directly in a connection entry, reference an Application Password,\nor use an SSH Key with a personal username.</li>\n<li><strong>Encrypted launch handoff:</strong> The client encrypts the connection descriptor with a fresh launch key. The Psono server\nauthorizes and routes the request without decrypting the target credentials.</li>\n<li><strong>Short-lived, one-time launches:</strong> Every session starts with a temporary launch code that is consumed atomically and\ncannot be reused.</li>\n<li><strong>Continuous authorization:</strong> Psono checks access when the session starts and revalidates active launches regularly, so\nrevoked users, sessions, secret permissions, or Gateway access can invalidate a connection.</li>\n<li><strong>Granular Gateway access:</strong> Administrators can make a Gateway cluster available to everyone or restrict it to selected\nusers and groups.</li>\n<li><strong>High availability:</strong> Multiple Gateway instances can join a cluster. Psono selects an active instance for each new\nlaunch, and users can choose between clusters when more than one is available.</li>\n<li><strong>Deployment flexibility:</strong> The container includes the Gateway web application and a bundled <code>guacd</code> daemon for SSH,\nRDP, and VNC. An external <code>guacd</code> can be used when stronger process or network isolation is required.</li>\n</ul>\n<h2>How It Works</h2>\n<figure style=\"margin: 32px 0;\">\n  <img src=\"/images/psono-gateway-network-diagram.svg\" alt=\"Network diagram showing the browser requesting an authorized launch from the Psono Enterprise Server, opening a session through a Psono Gateway cluster, and the Gateway connecting to SSH, RDP, or VNC targets\" width=\"1200\" height=\"720\" style=\"display: block; width: 100%; height: auto;\">\n  <figcaption style=\"margin-top: 10px; text-align: center;\">Psono controls authorization and Gateway selection, while remote protocol traffic flows from the Gateway to systems in the protected network.</figcaption>\n</figure>\n<ol>\n<li>A user launches a saved SSH, RDP, or VNC connection from Psono. The client resolves the connection's configured\nauthentication source and encrypts the minimum required connection details with a new key.</li>\n<li>The Psono Enterprise Server verifies the user's token, read access to the connection entry, and permission to use the\nselected Gateway cluster. It then chooses an active Gateway instance and returns a short-lived one-time launch code.</li>\n<li>The user's browser connects directly to the selected Gateway over HTTPS. The Gateway atomically exchanges the launch\ncode and decrypts the connection details in memory.</li>\n<li>The bundled or external <code>guacd</code> daemon opens the SSH, RDP, or VNC connection from the Gateway's network to the target\nsystem. The Psono server never initiates a connection to the Gateway or the target.</li>\n<li>While the session is active, the Gateway regularly asks the Psono server whether the launch remains authorized. Idle\nand absolute timeouts provide additional session boundaries.</li>\n</ol>\n<p>This separation lets organizations place a Gateway close to protected systems while users only need HTTPS access to\nPsono and the Gateway. Firewall rules can keep SSH, RDP, and VNC services private and permit the Gateway to reach only the\nintended target networks.</p>\n<h2>Built for Controlled Enterprise Access</h2>\n<p>Gateway clusters can represent different locations, security zones, or environments. Administrators can assign users and\ngroups to the appropriate clusters, monitor registered Gateway instances in the Admin Portal, and run multiple instances\nfor availability. When users have access to several clusters, they can select the right route and optionally remember that\nchoice for a connection.</p>\n<p>Direct sign-in to Psono Gateway is intentionally unavailable. Every session must originate from an authorized Psono\nconnection entry. Credentials are decrypted only by the selected Gateway for the launch and are held in memory for the\nremote session rather than being revealed by the Psono server.</p>\n<h2>Getting Started</h2>\n<p>To deploy Psono Gateway, enable the Gateway API on your Psono Enterprise Server, create a cluster in <strong>Gateway Management</strong>,\nconfigure its user or group access, and start one or more Gateway containers where they can reach the intended target\nsystems. Users can then create SSH, RDP, or VNC connection entries and launch them from Psono.</p>\n<p>The complete installation, reverse proxy, firewall, high-availability, and update guidance is available in the\n<a href=\"https://doc.psono.com/admin/installation-optional/install-gateway.html\">Psono Gateway documentation</a>.</p>","frontmatter":{"date":"August 11, 2026","slug":"psono-gateway","title":"Introducing Psono Gateway","description":"Browser-based SSH, RDP, and VNC access for Psono Enterprise Edition","author":"Sascha Pfeiffer","featuredImage":null}}},"pageContext":{"slug":"psono-gateway","lang":"en","langPathPrefix":""}},"staticQueryHashes":["2149092236","3128451518","3192060438"]}