Move SCP to a Unix Domain Socket
The TCP socket implementation of sesman has a number of limitations, namely that it is affected by firewalls, and also that determining the user on the other end requires a full authentication process. The advantage of the TCP socket is that sesman and xrdp can be run on separate machines. This is however not supported by the xorgxrdp backend (shared memory), and is insecure, in that passwords are sent in-the-clear, and the connection is susceptible to MitM attacks. This architecture has been deprecated in release notes since xrdp v0.9.17, and although it will continue to be supported in any further releases in the x0.9.x series, it will not be supported in the next major version.
This commit is contained in:
+8
-5
@@ -47,16 +47,19 @@ sig_sesman_reload_cfg(void)
|
||||
}
|
||||
|
||||
/* Deal with significant config changes */
|
||||
if (g_strcmp(g_cfg->listen_address, cfg->listen_address) != 0 ||
|
||||
g_strcmp(g_cfg->listen_port, cfg->listen_port) != 0)
|
||||
if (g_strcmp(g_cfg->listen_port, cfg->listen_port) != 0)
|
||||
{
|
||||
LOG(LOG_LEVEL_INFO, "sesman listen address changed to %s:%s",
|
||||
cfg->listen_address, cfg->listen_port);
|
||||
LOG(LOG_LEVEL_INFO, "sesman listen port changed to %s",
|
||||
cfg->listen_port);
|
||||
|
||||
/* We have to delete the old port before listening to the new one
|
||||
* in case they overlap in scope */
|
||||
sesman_delete_listening_transport();
|
||||
sesman_create_listening_transport(cfg);
|
||||
if (sesman_create_listening_transport(cfg) == 0)
|
||||
{
|
||||
LOG(LOG_LEVEL_INFO, "Sesman now listening on %s",
|
||||
g_cfg->listen_port);
|
||||
}
|
||||
}
|
||||
|
||||
/* free old config data */
|
||||
|
||||
Reference in New Issue
Block a user