diff --git a/docs/man/sesman.ini.5.in b/docs/man/sesman.ini.5.in index b60ac0a1..caebd2cd 100644 --- a/docs/man/sesman.ini.5.in +++ b/docs/man/sesman.ini.5.in @@ -371,9 +371,14 @@ transitions between confinement domains. .TP \fBSessionSockdirGroup\fR=\fIgroup\fR -Sets the group owner of the directories containing session sockets. This -MUST be the same as runtime_group in xrdp.ini, or xrdp will not -be able to connect to any sessions. +Sets the group owner of the directories containing session sockets. + +For normal operation with sesman, set this to 'root' for maximum security. + +If you are using xrdp to connect to VNC sessions with X server +sockets or chansrv sockets in the local sockets dir, set this to +the runtime_group in xrdp.ini. If you do not do this, xrdp will not +be able to connect to your sessions. .SH "X11 SERVER" Following parameters can be used in the \fB[Xvnc]\fR and diff --git a/docs/man/xrdp.ini.5.in b/docs/man/xrdp.ini.5.in index 048aaa9f..cd6f8c42 100644 --- a/docs/man/xrdp.ini.5.in +++ b/docs/man/xrdp.ini.5.in @@ -415,6 +415,10 @@ Either the first or second form of this setting is recommended. Replace required if \fBxrdp\fR is unable to determine the session uid from the other values in the connection block. +If you use this setting, you must also set SessionSockdirGroup in +\fBsesman.ini\fR to be the same as runtime_group in this file. This is +necessary to give \fBxrdp\fR the privilege to connect to \fBxrdp\-chansrv\fR. + .TP \fBkeycode_set\fR=\fI\fR [Xorg only] Asks for the specified keycode set to be used by the X server. diff --git a/sesman/sesman.ini.in b/sesman/sesman.ini.in index e950570f..23e70a72 100644 --- a/sesman/sesman.ini.in +++ b/sesman/sesman.ini.in @@ -48,8 +48,14 @@ RestrictInboundClipboard=none #XorgNoNewPrivileges=true ; Specify the group which is to have read access to the directory where ; local sockets for the session are created. -; This MUST be the same as runtime_group in xrdp.ini, or xrdp will not -; be able to connect to your sessions. +; This should take one of the following values:- +; 1) For normal operation with sesman, set this to 'root' for +; maximum security +; 2) If you are using xrdp to connect to VNC sessions with X server +; sockets or chansrv sockets in the local sockets dir, set this to +; the runtime_group in xrdp.ini. If you do not do this, xrdp will not +; be able to connect to your sessions. +SessionSockdirGroup=root #SessionSockdirGroup=xrdp diff --git a/tools/chkpriv/xrdp-chkpriv.in b/tools/chkpriv/xrdp-chkpriv.in index 32580ce4..ed8c2285 100644 --- a/tools/chkpriv/xrdp-chkpriv.in +++ b/tools/chkpriv/xrdp-chkpriv.in @@ -28,32 +28,37 @@ DROPPRIV=@pkglibexecdir@/xrdp-droppriv # Helper functions to print colored tag like "[ OK ]" -print_ok() -{ - if [ -t 1 ]; then +if [ -t 1 ]; then + print_ok() + { printf "\033[1m[ \033[1;32mOK\033[0m ]\033[0m " - else - printf "[ OK ] " - fi -} + } -print_warn() -{ - if [ -t 1 ]; then + print_warn() + { printf "\033[1m[ \033[1;33mWARN\033[0m ]\033[0m " - else - printf "[ WARN ] " - fi -} + } -print_ng() -{ - if [ -t 1 ]; then + print_ng() + { printf "\033[1m[ \033[1;31mNG\033[0m ]\033[0m " - else + } +else + print_ok() + { + printf "[ OK ] " + } + + print_warn() + { + printf "[ WARN ] " + } + + print_ng() + { printf "[ NG ] " - fi -} + } +fi # ----------------------------------------------------------------------------- # G E T I N I V A L U E @@ -155,9 +160,16 @@ else fi # Groups agree between sesman and xrdp? -if [ "$runtime_user" = "$SessionSockdirGroup" ]; then +if [ -z "$SessionSockdirGroup" ] || [ "$SessionSockdirGroup" = "root" ]; then + print_ok + echo "sesman.ini is configured for secure connections to sesman sessions." + +elif [ "$SessionSockdirGroup" = "$runtime_group" ]; then print_ok echo "xrdp.ini and sesman.ini agree on group ownership" + print_warn + echo "consider setting SessionSockdirGroup = root for maximum security" + else print_ng echo "xrdp.ini and sesman.ini do not agree on group ownership" @@ -214,7 +226,7 @@ fi # privileges. On Debian for example, we might be using the 'ssl-cert' # group to obtain access to /etc/ssl/private/ssl-cert-snakeoil.key for file in "$certificate" "$key_file"; do - if ! [ -e $file ]; then + if ! [ -e "$file" ]; then print_ng echo "$file does not exist" errors=$(( errors + 1 )) diff --git a/xrdp/xrdp.ini.in b/xrdp/xrdp.ini.in index 512bf3ec..e7ea9823 100644 --- a/xrdp/xrdp.ini.in +++ b/xrdp/xrdp.ini.in @@ -307,6 +307,9 @@ password=ask ; display number of the session, and (if applicable) 'u' with the numeric ; UID of the session. ; +; You will also need to change the value of SessionSockdirGroup in +; sesman.ini to allow xrdp to reach the chansrv instance +; ; If 'username' or 'pamusername' is set, you probably don't need to use ; the two parameter variant with 'u'. #chansrvport=DISPLAY(n)