Add params to allow xrdp to be run as non-root
runtime_user and runtime_group are added to the xrdp.ini file so that the service knows how to reduce privilege
This commit is contained in:
@@ -119,6 +119,17 @@ The default port for RDP is \fB3389\fP.
|
||||
Multiple address:port instances must be separated by spaces or commas. Check the .ini file for examples.
|
||||
Specifying interfaces requires said interfaces to be UP before xrdp starts.
|
||||
|
||||
.TP
|
||||
\fBruntime_user\fP=\fIusername\fP
|
||||
.TP
|
||||
\fBruntime_group\fP=\fIgroupname\fP
|
||||
User name and group to run the xrdp daemon under.
|
||||
|
||||
After xrdp starts, it sets its UID and GID to values derived from these
|
||||
settings, so that it's running without system privilege.
|
||||
The \fBruntime_group\fP MUST be set to the same value as
|
||||
\fBSessionSockdirGroup\fP in \fBsesman.ini\fP if you want to run sessions.
|
||||
|
||||
.TP
|
||||
\fBenable_token_login\fP=\fI[true|false]\fP
|
||||
If set to \fB1\fP, \fBtrue\fP or \fByes\fP, \fBxrdp\fP will scan the user name provided by the
|
||||
|
||||
Reference in New Issue
Block a user