From 09e117325915585296d9ce1f6fc557a9960fb63a Mon Sep 17 00:00:00 2001 From: gpotter2 <10530980+gpotter2@users.noreply.github.com> Date: Thu, 8 May 2025 06:45:05 +0200 Subject: [PATCH] Apply suggestions Co-Authored-By: matt335672 <30179339+matt335672@users.noreply.github.com> --- libxrdp/xrdp_iso.c | 45 +++++++++++++++------------------------------ xrdp/xrdp.ini.in | 4 ++-- 2 files changed, 17 insertions(+), 32 deletions(-) diff --git a/libxrdp/xrdp_iso.c b/libxrdp/xrdp_iso.c index f75c3fb7..5e2cae89 100644 --- a/libxrdp/xrdp_iso.c +++ b/libxrdp/xrdp_iso.c @@ -129,40 +129,25 @@ xrdp_iso_negotiate_security(struct xrdp_iso *self) protostr); security_type_mask &= self->requestedProtocol; - /* In VMConnect mode, we support everything. */ - if (client_info->vmconnect && (self->requestedProtocol > PROTOCOL_RDP)) + if (security_type_mask & PROTOCOL_HYBRID_EX) { - if (security_type_mask & PROTOCOL_HYBRID_EX) - { - LOG(LOG_LEVEL_INFO, "Selected HYBRID_EX security"); - self->selectedProtocol = PROTOCOL_HYBRID_EX; - got_protocol = 1; - } - else if (security_type_mask & PROTOCOL_HYBRID) - { - LOG(LOG_LEVEL_INFO, "Selected HYBRID security"); - self->selectedProtocol = PROTOCOL_HYBRID; - got_protocol = 1; - } - else if (security_type_mask & PROTOCOL_SSL) - { - LOG(LOG_LEVEL_INFO, "Selected TLS security"); - self->selectedProtocol = PROTOCOL_SSL; - got_protocol = 1; - } - else - { - /* Impossible */ - LOG(LOG_LEVEL_ERROR, "Impossible case."); - rv = 1; - } + /* Currently supported by VMConnect mode only */ + LOG(LOG_LEVEL_INFO, "Selected HYBRID_EX security"); + self->selectedProtocol = PROTOCOL_HYBRID_EX; + got_protocol = 1; + } + else if (security_type_mask & PROTOCOL_HYBRID) + { + /* Currently supported by VMConnect mode only */ + LOG(LOG_LEVEL_INFO, "Selected HYBRID security"); + self->selectedProtocol = PROTOCOL_HYBRID; + got_protocol = 1; } - /* Is there a match on SSL/TLS? */ else if ((security_type_mask & PROTOCOL_SSL) != 0) { - /* Can we do TLS? (basic check) */ - if (g_file_readable(client_info->certificate) && - g_file_readable(client_info->key_file)) + /* Can we do TLS? (basic check). VMConnect is exempt. */ + if ((g_file_readable(client_info->certificate) && + g_file_readable(client_info->key_file)) || client_info->vmconnect) { LOG(LOG_LEVEL_INFO, "Selected TLS security"); self->selectedProtocol = PROTOCOL_SSL; diff --git a/xrdp/xrdp.ini.in b/xrdp/xrdp.ini.in index 566ca9d0..0e26f96b 100644 --- a/xrdp/xrdp.ini.in +++ b/xrdp/xrdp.ini.in @@ -27,8 +27,8 @@ port=3389 ; prefer use vsock://: above use_vsock=false -; if used inside a Hyper-V VM with vmconnect, turn this on to enable -; wider protocol support. +; if used inside a Hyper-V VM through vmconnect and bound on vsock, +; turn this on to enable wider security protocol support. #vmconnect=true ; Unprivileged User name and group to run the xrdp daemon.