Prefer SessionSockdirGroup to be set to 'root'
With recent changes to the SCP interface, the xrdp process no longer needs read access to the user sockdir when sesman is in use.
This commit is contained in:
@@ -371,9 +371,14 @@ transitions between confinement domains.
|
||||
|
||||
.TP
|
||||
\fBSessionSockdirGroup\fR=\fIgroup\fR
|
||||
Sets the group owner of the directories containing session sockets. This
|
||||
MUST be the same as runtime_group in xrdp.ini, or xrdp will not
|
||||
be able to connect to any sessions.
|
||||
Sets the group owner of the directories containing session sockets.
|
||||
|
||||
For normal operation with sesman, set this to 'root' for maximum security.
|
||||
|
||||
If you are using xrdp to connect to VNC sessions with X server
|
||||
sockets or chansrv sockets in the local sockets dir, set this to
|
||||
the runtime_group in xrdp.ini. If you do not do this, xrdp will not
|
||||
be able to connect to your sessions.
|
||||
|
||||
.SH "X11 SERVER"
|
||||
Following parameters can be used in the \fB[Xvnc]\fR and
|
||||
|
||||
@@ -415,6 +415,10 @@ Either the first or second form of this setting is recommended. Replace
|
||||
required if \fBxrdp\fR is unable to determine the session uid from the
|
||||
other values in the connection block.
|
||||
|
||||
If you use this setting, you must also set SessionSockdirGroup in
|
||||
\fBsesman.ini\fR to be the same as runtime_group in this file. This is
|
||||
necessary to give \fBxrdp\fR the privilege to connect to \fBxrdp\-chansrv\fR.
|
||||
|
||||
.TP
|
||||
\fBkeycode_set\fR=\fI<string>\fR
|
||||
[Xorg only] Asks for the specified keycode set to be used by the X server.
|
||||
|
||||
Reference in New Issue
Block a user