Prefer SessionSockdirGroup to be set to 'root'

With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
This commit is contained in:
matt335672
2025-06-21 16:26:48 +01:00
parent d0a876ed47
commit 8bcb14f79d
5 changed files with 57 additions and 27 deletions
+8 -3
View File
@@ -371,9 +371,14 @@ transitions between confinement domains.
.TP
\fBSessionSockdirGroup\fR=\fIgroup\fR
Sets the group owner of the directories containing session sockets. This
MUST be the same as runtime_group in xrdp.ini, or xrdp will not
be able to connect to any sessions.
Sets the group owner of the directories containing session sockets.
For normal operation with sesman, set this to 'root' for maximum security.
If you are using xrdp to connect to VNC sessions with X server
sockets or chansrv sockets in the local sockets dir, set this to
the runtime_group in xrdp.ini. If you do not do this, xrdp will not
be able to connect to your sessions.
.SH "X11 SERVER"
Following parameters can be used in the \fB[Xvnc]\fR and