Docs/Getting started/System requirements
DartRelay 2.1 documentation
Getting started

System requirements

Use this page as a checklist before you install. It covers the machine DartRelay runs on, the database, the Windows hosts you publish from, the network connections between them, and what your users need on their side.

At a glance

You needSummary
A DartRelay serverOne machine running Windows (XP through 11, or Windows Server; 32-bit, 64-bit or ARM64) or Linux x64.
A databaseNothing extra for the built-in SQLite, or an existing SQL Server, MySQL or PostgreSQL server.
At least one hostA Windows desktop or Windows Server to publish from. Nothing is installed on it.
A management account per hostA local administrator account DartRelay can use to check and prepare the host.
Network accessBrowsers to the DartRelay server on one web port; the DartRelay server to hosts on RDP and file sharing.
A licenceA product key to activate, or another installation's licence to share.
BrowsersAny current mainstream browser on the user's device. No plug-in or client.

The DartRelay server

This is the machine you run the installer on. It serves the portal and the console and relays every session. DartRelay installs on:

A client edition of Windows is a supported place to install DartRelay itself. The machines you publish from are a separate requirement, described under Hosts below. The DartRelay server and a host can be the same machine, but in most organisations they are separate.

The installer carries everything DartRelay needs. You do not have to install any runtime, web server or other prerequisite first.

Size

Every open session passes through the DartRelay server, which turns the Windows screen into a picture stream for the browser, so the server's processor and network do most of the work. Plan it as you would a busy web server, and give it more room as the number of people working at the same time grows. This guide does not publish fixed processor, memory or disk figures; for sizing advice, contact support@dartinnovations.com.

Windows-only host features

Several host-preparation features use Windows networking from the DartRelay server: reading a host's readiness over file sharing, installing the Remote Desktop Session Host role without WinRM, listing installed programs from the host's registry, and registering published applications on the host. When DartRelay runs on Linux, readiness checks and role installation use WinRM over HTTPS instead, which needs a WinRM HTTPS listener on each host, and those other features are not available. If you plan to use them, install DartRelay on Windows.

Database

DartRelay keeps everything you configure in one database. You choose which kind in the setup wizard the first time you open the console.

DatabaseWhen to choose itWhat you need
SQLiteOne DartRelay server. The simplest choice.Nothing. The database is a file in the App_Data folder inside the installation folder.
SQL ServerYou already run SQL Server, or you want several DartRelay servers in a pool.A server, a database and an account DartRelay can use.
MySQLAs above, on MySQL.As above.
PostgreSQLAs above, on PostgreSQL.As above.

A pool of several DartRelay servers shares one database. Because SQLite is a file on one server, choose a database server for a pool. See Databases and migration and Running several servers (pools).

Hosts (the machines you publish from)

A host is a Windows machine whose applications or desktop you publish. DartRelay is agentless: nothing is installed on a host.

Which Windows

HostWhat to expect
Windows desktop edition (for example Windows 10 or 11 Pro)Allows one Remote Desktop session at a time. Suitable for one person, or for testing.
Windows Server without the Remote Desktop Session Host roleAllows only two connections, intended for administering the server. A desktop published from such a host works for the first two people and then refuses the third.
Windows Server with the Remote Desktop Session Host roleAllows many people to work at once. This is the normal choice. DartRelay can detect whether the role is present and install it for you.

Remote Desktop licensing

With the Session Host role installed, Microsoft requires a Remote Desktop Services client access licence (RDS CAL) for each connecting user or device after a 120-day grace period. DartRelay does not supply these. It does read the host's Remote Desktop licensing state and warns you on the host's page when the grace period is running out or the host cannot obtain a licence. See Adding and preparing hosts.

A management account

For each host you give DartRelay a management account: an account that is a local administrator on that host, such as .\Administrator or a domain account in the host's local Administrators group. DartRelay uses it to:

The account is stored encrypted. It is never used to log people on to sessions.

On each host

Enable-NetFirewallRule -Group '@FirewallAPI.dll,-33252'

Network ports

The table lists every connection DartRelay makes or receives. Only the first row needs to be reachable from outside your network.

FromToPortUsed for
Users' browsersDartRelay serverThe web port you choose during installation (HTTPS once you add a certificate)The portal, the console and every session. Sessions use a secure WebSocket on the same port, so any proxy or load balancer in between must pass WebSocket upgrades.
The internet (Let's Encrypt)DartRelay serverTCP 80Only if you use the built-in Let's Encrypt certificate. Port 80 must be reachable when the certificate is first issued and at every renewal. Leaving it open with a redirect is the simplest approach.
DartRelay serverHostsTCP 3389Remote Desktop sessions.
DartRelay serverHostsTCP 445File sharing: readiness checks, listing installed programs, publishing applications, role installation.
DartRelay serverHostsTCP 135 and dynamic RPC portsInstalling the Session Host role through Task Scheduler.
DartRelay serverHostsTCP 5986 (optional)WinRM over HTTPS, used when the routes above are not available, and always when DartRelay runs on Linux.
DartRelay serverDomain controllersStandard Active Directory ports (LDAP 389, or LDAPS 636 if you choose it)Signing people in with directory accounts, looking up users and groups.
DartRelay serverDatabase serverThe database's own portOnly for SQL Server, MySQL or PostgreSQL.
DartRelay serverMail serverYour SMTP portEmail: one-time codes, password reset, administrator notifications. Optional.
DartRelay serverDart Innovations' activation serviceHTTPSActivating the licence with a product key and refreshing it when it is renewed.
Another DartRelay installationThe installation holding the licenceThat installation's web portOnly when sharing one licence between installations.

Users' devices and browsers

Your users need only a current version of a mainstream browser, such as Microsoft Edge, Google Chrome, Mozilla Firefox or Safari. There is nothing to install: no client, no plug-in and no VPN. The browser must be able to reach the portal address. Some browser features behave differently between browsers; for example, opening a session full screen always needs one click from the user, in every browser. See Automatic launch and single-application portals.

Certificates and addresses

For anything other than a quick trial on your own network, give DartRelay a proper address (such as apps.example.com) and an HTTPS certificate, so sign-in details and sessions are encrypted. You can upload your own certificate or have DartRelay obtain and renew one from Let's Encrypt. See Endpoints and certificates.

Directory (optional)

If people will sign in with Active Directory accounts, the DartRelay server should normally be joined to the domain. From version 2.0 DartRelay can also sign people in from other domains, including domains that do not trust the server's own; those need a service account in that domain. See Active Directory and multiple domains.

Some features need rights delegated to the account the DartRelay service runs as. For example, letting people reset their own Active Directory password needs the Reset password right (and Write lockoutTime to unlock accounts) on the users' organisational units. See Password policy and self-service reset.

Relay Pass New in 2.1

Relay Pass logs people on to Windows with a short-lived certificate instead of a password. It needs Active Directory Certificate Services, a certificate template for logon, and an enrollment agent certificate on the DartRelay server. The requirements and the readiness checks are on Relay Pass (passwordless Windows logon).

Licence

You need a DartRelay product key to activate a new installation, or an enrolment token from another installation that shares its licence with you. An installation with no valid licence refuses to launch anything, so activate it before you invite users. See Licensing and Relay Seats and Sharing one licence between installations.

Before-you-install checklist

  1. A machine for DartRelay, running a supported operating system, that you can sign in to as an administrator.
  2. A decision on the database: SQLite, or the details of your SQL Server, MySQL or PostgreSQL server.
  3. A free web port on that machine for the portal and console.
  4. At least one host, with Remote Desktop enabled and a local administrator account for DartRelay to use.
  5. Firewall rules allowing the DartRelay server to reach the hosts on the ports above.
  6. Your product key.
  7. Optionally: a hostname and a certificate, a mail server, and your Active Directory details.
Still stuck? Email support@dartinnovations.com with what you were doing, what you expected and what you saw. A screenshot helps.