Add params to allow xrdp to be run as non-root

runtime_user and runtime_group are added to the xrdp.ini file
so that the service knows how to reduce privilege
This commit is contained in:
matt335672
2024-02-26 15:45:04 +00:00
parent 1d927add29
commit 17a56567d2
7 changed files with 83 additions and 48 deletions
+11
View File
@@ -119,6 +119,17 @@ The default port for RDP is \fB3389\fP.
Multiple address:port instances must be separated by spaces or commas. Check the .ini file for examples.
Specifying interfaces requires said interfaces to be UP before xrdp starts.
.TP
\fBruntime_user\fP=\fIusername\fP
.TP
\fBruntime_group\fP=\fIgroupname\fP
User name and group to run the xrdp daemon under.
After xrdp starts, it sets its UID and GID to values derived from these
settings, so that it's running without system privilege.
The \fBruntime_group\fP MUST be set to the same value as
\fBSessionSockdirGroup\fP in \fBsesman.ini\fP if you want to run sessions.
.TP
\fBenable_token_login\fP=\fI[true|false]\fP
If set to \fB1\fP, \fBtrue\fP or \fByes\fP, \fBxrdp\fP will scan the user name provided by the