Security improvements

1) In FIPS mode, Classic RDP security is not allowed at all.
2) In FIPS mode xrdp-keygen creates an empty file
3) Documentation wording improved around the security_level setting
4) Logging improved around the security negotiation
5) Warnings now generated if Classic RDP security is negotiated
This commit is contained in:
matt335672
2025-03-10 20:36:50 +00:00
parent 45ccd2d356
commit 463e500f77
8 changed files with 164 additions and 148 deletions
+4
View File
@@ -31,6 +31,10 @@ If \fBauto\fP is used as \fIoutfile\fP, the default file \fI@sysconfdir@/@syscon
.B test
Generate a test key pair and print information to standard output.
.SH NOTES
On machines with FIPS enabled, this program will generate an empty file,
and a warning. On these machines, xrdp cannot use Classic RDP encryption.
.SH FILES
.TP
.I @sysconfdir@/@sysconfsubdir@/rsakeys.ini