System requirements
Use this page as a checklist before you install. It covers the machine DartRelay runs on, the database, the Windows hosts you publish from, the network connections between them, and what your users need on their side.
At a glance
| You need | Summary |
|---|---|
| A DartRelay server | One machine running Windows (XP through 11, or Windows Server; 32-bit, 64-bit or ARM64) or Linux x64. |
| A database | Nothing extra for the built-in SQLite, or an existing SQL Server, MySQL or PostgreSQL server. |
| At least one host | A Windows desktop or Windows Server to publish from. Nothing is installed on it. |
| A management account per host | A local administrator account DartRelay can use to check and prepare the host. |
| Network access | Browsers to the DartRelay server on one web port; the DartRelay server to hosts on RDP and file sharing. |
| A licence | A product key to activate, or another installation's licence to share. |
| Browsers | Any current mainstream browser on the user's device. No plug-in or client. |
The DartRelay server
This is the machine you run the installer on. It serves the portal and the console and relays every session. DartRelay installs on:
- Windows XP through Windows 11, 32-bit (x86) or 64-bit (x64)
- Windows Server, 32-bit or 64-bit
- Windows on ARM64
- Linux x64
A client edition of Windows is a supported place to install DartRelay itself. The machines you publish from are a separate requirement, described under Hosts below. The DartRelay server and a host can be the same machine, but in most organisations they are separate.
The installer carries everything DartRelay needs. You do not have to install any runtime, web server or other prerequisite first.
Size
Every open session passes through the DartRelay server, which turns the Windows screen into a picture stream for the browser, so the server's processor and network do most of the work. Plan it as you would a busy web server, and give it more room as the number of people working at the same time grows. This guide does not publish fixed processor, memory or disk figures; for sizing advice, contact support@dartinnovations.com.
Windows-only host features
Several host-preparation features use Windows networking from the DartRelay server: reading a host's readiness over file sharing, installing the Remote Desktop Session Host role without WinRM, listing installed programs from the host's registry, and registering published applications on the host. When DartRelay runs on Linux, readiness checks and role installation use WinRM over HTTPS instead, which needs a WinRM HTTPS listener on each host, and those other features are not available. If you plan to use them, install DartRelay on Windows.
Database
DartRelay keeps everything you configure in one database. You choose which kind in the setup wizard the first time you open the console.
| Database | When to choose it | What you need |
|---|---|---|
| SQLite | One DartRelay server. The simplest choice. | Nothing. The database is a file in the App_Data folder inside the installation folder. |
| SQL Server | You already run SQL Server, or you want several DartRelay servers in a pool. | A server, a database and an account DartRelay can use. |
| MySQL | As above, on MySQL. | As above. |
| PostgreSQL | As above, on PostgreSQL. | As above. |
A pool of several DartRelay servers shares one database. Because SQLite is a file on one server, choose a database server for a pool. See Databases and migration and Running several servers (pools).
Hosts (the machines you publish from)
A host is a Windows machine whose applications or desktop you publish. DartRelay is agentless: nothing is installed on a host.
Which Windows
| Host | What to expect |
|---|---|
| Windows desktop edition (for example Windows 10 or 11 Pro) | Allows one Remote Desktop session at a time. Suitable for one person, or for testing. |
| Windows Server without the Remote Desktop Session Host role | Allows only two connections, intended for administering the server. A desktop published from such a host works for the first two people and then refuses the third. |
| Windows Server with the Remote Desktop Session Host role | Allows many people to work at once. This is the normal choice. DartRelay can detect whether the role is present and install it for you. |
Remote Desktop licensing
With the Session Host role installed, Microsoft requires a Remote Desktop Services client access licence (RDS CAL) for each connecting user or device after a 120-day grace period. DartRelay does not supply these. It does read the host's Remote Desktop licensing state and warns you on the host's page when the grace period is running out or the host cannot obtain a licence. See Adding and preparing hosts.
A management account
For each host you give DartRelay a management account: an account that is a local administrator on that host, such as .\Administrator or a domain account in the host's local Administrators group. DartRelay uses it to:
- check whether the host is ready (Windows edition, Session Host role, restart pending, Remote Desktop licensing);
- list the programs installed on the host, so you can pick from them;
- register the applications you publish in the host's list of allowed remote programs;
- install the Session Host role, if you ask it to.
The account is stored encrypted. It is never used to log people on to sessions.
On each host
- Remote Desktop enabled, listening on its usual port (3389).
- File and printer sharing reachable from the DartRelay server, with the administrative share (
C$) available. - The Remote Registry service reachable, for publishing applications.
- To install the Session Host role from DartRelay: the "Remote Scheduled Tasks Management (RPC)" firewall rule group enabled. It is off by default; enable it once on the host or by Group Policy:
Enable-NetFirewallRule -Group '@FirewallAPI.dll,-33252'
- The people who will sign in allowed to use Remote Desktop. A server newly joined to a domain lets only administrators sign in through Remote Desktop. When DartRelay installs the Session Host role it offers to add the domain's users to the host's Remote Desktop Users group for you. Users from other domains need their own group added.
Network ports
The table lists every connection DartRelay makes or receives. Only the first row needs to be reachable from outside your network.
| From | To | Port | Used for |
|---|---|---|---|
| Users' browsers | DartRelay server | The web port you choose during installation (HTTPS once you add a certificate) | The portal, the console and every session. Sessions use a secure WebSocket on the same port, so any proxy or load balancer in between must pass WebSocket upgrades. |
| The internet (Let's Encrypt) | DartRelay server | TCP 80 | Only if you use the built-in Let's Encrypt certificate. Port 80 must be reachable when the certificate is first issued and at every renewal. Leaving it open with a redirect is the simplest approach. |
| DartRelay server | Hosts | TCP 3389 | Remote Desktop sessions. |
| DartRelay server | Hosts | TCP 445 | File sharing: readiness checks, listing installed programs, publishing applications, role installation. |
| DartRelay server | Hosts | TCP 135 and dynamic RPC ports | Installing the Session Host role through Task Scheduler. |
| DartRelay server | Hosts | TCP 5986 (optional) | WinRM over HTTPS, used when the routes above are not available, and always when DartRelay runs on Linux. |
| DartRelay server | Domain controllers | Standard Active Directory ports (LDAP 389, or LDAPS 636 if you choose it) | Signing people in with directory accounts, looking up users and groups. |
| DartRelay server | Database server | The database's own port | Only for SQL Server, MySQL or PostgreSQL. |
| DartRelay server | Mail server | Your SMTP port | Email: one-time codes, password reset, administrator notifications. Optional. |
| DartRelay server | Dart Innovations' activation service | HTTPS | Activating the licence with a product key and refreshing it when it is renewed. |
| Another DartRelay installation | The installation holding the licence | That installation's web port | Only when sharing one licence between installations. |
Users' devices and browsers
Your users need only a current version of a mainstream browser, such as Microsoft Edge, Google Chrome, Mozilla Firefox or Safari. There is nothing to install: no client, no plug-in and no VPN. The browser must be able to reach the portal address. Some browser features behave differently between browsers; for example, opening a session full screen always needs one click from the user, in every browser. See Automatic launch and single-application portals.
Certificates and addresses
For anything other than a quick trial on your own network, give DartRelay a proper address (such as apps.example.com) and an HTTPS certificate, so sign-in details and sessions are encrypted. You can upload your own certificate or have DartRelay obtain and renew one from Let's Encrypt. See Endpoints and certificates.
Directory (optional)
If people will sign in with Active Directory accounts, the DartRelay server should normally be joined to the domain. From version 2.0 DartRelay can also sign people in from other domains, including domains that do not trust the server's own; those need a service account in that domain. See Active Directory and multiple domains.
Some features need rights delegated to the account the DartRelay service runs as. For example, letting people reset their own Active Directory password needs the Reset password right (and Write lockoutTime to unlock accounts) on the users' organisational units. See Password policy and self-service reset.
Relay Pass New in 2.1
Relay Pass logs people on to Windows with a short-lived certificate instead of a password. It needs Active Directory Certificate Services, a certificate template for logon, and an enrollment agent certificate on the DartRelay server. The requirements and the readiness checks are on Relay Pass (passwordless Windows logon).
Licence
You need a DartRelay product key to activate a new installation, or an enrolment token from another installation that shares its licence with you. An installation with no valid licence refuses to launch anything, so activate it before you invite users. See Licensing and Relay Seats and Sharing one licence between installations.
Before-you-install checklist
- A machine for DartRelay, running a supported operating system, that you can sign in to as an administrator.
- A decision on the database: SQLite, or the details of your SQL Server, MySQL or PostgreSQL server.
- A free web port on that machine for the portal and console.
- At least one host, with Remote Desktop enabled and a local administrator account for DartRelay to use.
- Firewall rules allowing the DartRelay server to reach the hosts on the ports above.
- Your product key.
- Optionally: a hostname and a certificate, a mail server, and your Active Directory details.
Related pages
Installing DartRelay
Run the installer and choose how the server is licensed.
Adding and preparing hosts
Management accounts, readiness and the Session Host role.
Endpoints and certificates
Ports, addresses and HTTPS.
Databases and migration
Choosing and changing the database.
