Security improvements

1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
This commit is contained in:
matt335672
2025-03-10 20:36:50 +00:00
parent 45ccd2d356
commit 463e500f77
8 changed files with 164 additions and 148 deletions
+4
View File
@@ -31,6 +31,10 @@ If \fBauto\fP is used as \fIoutfile\fP, the default file \fI@sysconfdir@/@syscon
.B test
Generate a test key pair and print information to standard output.
.SH NOTES
On machines with FIPS enabled, this program will generate an empty file,
and a warning. On these machines, xrdp cannot use Classic RDP encryption.
.SH FILES
.TP
.I @sysconfdir@/@sysconfsubdir@/rsakeys.ini
+7 -5
View File
@@ -62,10 +62,10 @@ See section \fBCHANNELS\fP below for more fine grained options.
.TP
\fBcrypt_level\fP=\fI[low|medium|high|fips]\fP
.\" <http://blogs.msdn.com/b/openspecification/archive/2011/12/08/encryption-negotiation-in-rdp-connection.aspx>
Regulate encryption level of Standard RDP Security.
Regulate encryption level of Classic RDP Security.
This parameter is effective only if \fBsecurity_layer\fP is set to \fBrdp\fP or \fBnegotiate\fP.
Encryption in Standard RDP Security is controlled by two settings: \fIEncryption Level\fP
Encryption in Classic RDP Security is controlled by two settings: \fIEncryption Level\fP
and \fIEncryption Method\fP. The only supported \fIEncryption Method\fP are \fB40BIT_ENCRYPTION\fP
and \fB128BIT_ENCRYPTION\fP. \fB56BIT_ENCRYPTION\fP is not supported.
This option controls the \fIEncryption Level\fP:
@@ -86,7 +86,8 @@ the server's maximum key strength (sever compatible).
.TP
.B fips
All data sent between the client and server is protected using Federal Information
Processing Standard 140-1 validated encryption methods.
Processing Standard 140-1 validated encryption methods. Note that FIPS 140-1 is
no longer considered secure.
.I This level is required for Windows clients (mstsc.exe) if the client's group policy
.I enforces FIPS-compliance mode.
.RE
@@ -174,8 +175,9 @@ verification, and server authentication) are implemented by TLS.
.TP
.B rdp
Standard RDP Security, which is not safe from man-in-the-middle attack, is used. The encryption level
of Standard RDP Security is controlled by \fBcrypt_level\fP.
Classic RDP Security is used. The encryption level
of Classic RDP Security is controlled by \fBcrypt_level\fP.
Use this setting for testing only.
.TP
.B negotiate