Prefer SessionSockdirGroup to be set to 'root'

With recent changes to the SCP interface, the xrdp process no longer
needs read access to the user sockdir when sesman is in use.
This commit is contained in:
matt335672
2025-06-21 16:26:48 +01:00
parent d0a876ed47
commit 8bcb14f79d
5 changed files with 57 additions and 27 deletions
+8 -3
View File
@@ -371,9 +371,14 @@ transitions between confinement domains.
.TP .TP
\fBSessionSockdirGroup\fR=\fIgroup\fR \fBSessionSockdirGroup\fR=\fIgroup\fR
Sets the group owner of the directories containing session sockets. This Sets the group owner of the directories containing session sockets.
MUST be the same as runtime_group in xrdp.ini, or xrdp will not
be able to connect to any sessions. For normal operation with sesman, set this to 'root' for maximum security.
If you are using xrdp to connect to VNC sessions with X server
sockets or chansrv sockets in the local sockets dir, set this to
the runtime_group in xrdp.ini. If you do not do this, xrdp will not
be able to connect to your sessions.
.SH "X11 SERVER" .SH "X11 SERVER"
Following parameters can be used in the \fB[Xvnc]\fR and Following parameters can be used in the \fB[Xvnc]\fR and
+4
View File
@@ -415,6 +415,10 @@ Either the first or second form of this setting is recommended. Replace
required if \fBxrdp\fR is unable to determine the session uid from the required if \fBxrdp\fR is unable to determine the session uid from the
other values in the connection block. other values in the connection block.
If you use this setting, you must also set SessionSockdirGroup in
\fBsesman.ini\fR to be the same as runtime_group in this file. This is
necessary to give \fBxrdp\fR the privilege to connect to \fBxrdp\-chansrv\fR.
.TP .TP
\fBkeycode_set\fR=\fI<string>\fR \fBkeycode_set\fR=\fI<string>\fR
[Xorg only] Asks for the specified keycode set to be used by the X server. [Xorg only] Asks for the specified keycode set to be used by the X server.
+8 -2
View File
@@ -48,8 +48,14 @@ RestrictInboundClipboard=none
#XorgNoNewPrivileges=true #XorgNoNewPrivileges=true
; Specify the group which is to have read access to the directory where ; Specify the group which is to have read access to the directory where
; local sockets for the session are created. ; local sockets for the session are created.
; This MUST be the same as runtime_group in xrdp.ini, or xrdp will not ; This should take one of the following values:-
; be able to connect to your sessions. ; 1) For normal operation with sesman, set this to 'root' for
; maximum security
; 2) If you are using xrdp to connect to VNC sessions with X server
; sockets or chansrv sockets in the local sockets dir, set this to
; the runtime_group in xrdp.ini. If you do not do this, xrdp will not
; be able to connect to your sessions.
SessionSockdirGroup=root
#SessionSockdirGroup=xrdp #SessionSockdirGroup=xrdp
+34 -22
View File
@@ -28,32 +28,37 @@ DROPPRIV=@pkglibexecdir@/xrdp-droppriv
# Helper functions to print colored tag like "[ OK ]" # Helper functions to print colored tag like "[ OK ]"
print_ok() if [ -t 1 ]; then
{ print_ok()
if [ -t 1 ]; then {
printf "\033[1m[ \033[1;32mOK\033[0m ]\033[0m " printf "\033[1m[ \033[1;32mOK\033[0m ]\033[0m "
else }
printf "[ OK ] "
fi
}
print_warn() print_warn()
{ {
if [ -t 1 ]; then
printf "\033[1m[ \033[1;33mWARN\033[0m ]\033[0m " printf "\033[1m[ \033[1;33mWARN\033[0m ]\033[0m "
else }
printf "[ WARN ] "
fi
}
print_ng() print_ng()
{ {
if [ -t 1 ]; then
printf "\033[1m[ \033[1;31mNG\033[0m ]\033[0m " printf "\033[1m[ \033[1;31mNG\033[0m ]\033[0m "
else }
else
print_ok()
{
printf "[ OK ] "
}
print_warn()
{
printf "[ WARN ] "
}
print_ng()
{
printf "[ NG ] " printf "[ NG ] "
fi }
} fi
# ----------------------------------------------------------------------------- # -----------------------------------------------------------------------------
# G E T I N I V A L U E # G E T I N I V A L U E
@@ -155,9 +160,16 @@ else
fi fi
# Groups agree between sesman and xrdp? # Groups agree between sesman and xrdp?
if [ "$runtime_user" = "$SessionSockdirGroup" ]; then if [ -z "$SessionSockdirGroup" ] || [ "$SessionSockdirGroup" = "root" ]; then
print_ok
echo "sesman.ini is configured for secure connections to sesman sessions."
elif [ "$SessionSockdirGroup" = "$runtime_group" ]; then
print_ok print_ok
echo "xrdp.ini and sesman.ini agree on group ownership" echo "xrdp.ini and sesman.ini agree on group ownership"
print_warn
echo "consider setting SessionSockdirGroup = root for maximum security"
else else
print_ng print_ng
echo "xrdp.ini and sesman.ini do not agree on group ownership" echo "xrdp.ini and sesman.ini do not agree on group ownership"
@@ -214,7 +226,7 @@ fi
# privileges. On Debian for example, we might be using the 'ssl-cert' # privileges. On Debian for example, we might be using the 'ssl-cert'
# group to obtain access to /etc/ssl/private/ssl-cert-snakeoil.key # group to obtain access to /etc/ssl/private/ssl-cert-snakeoil.key
for file in "$certificate" "$key_file"; do for file in "$certificate" "$key_file"; do
if ! [ -e $file ]; then if ! [ -e "$file" ]; then
print_ng print_ng
echo "$file does not exist" echo "$file does not exist"
errors=$(( errors + 1 )) errors=$(( errors + 1 ))
+3
View File
@@ -307,6 +307,9 @@ password=ask
; display number of the session, and (if applicable) 'u' with the numeric ; display number of the session, and (if applicable) 'u' with the numeric
; UID of the session. ; UID of the session.
; ;
; You will also need to change the value of SessionSockdirGroup in
; sesman.ini to allow xrdp to reach the chansrv instance
;
; If 'username' or 'pamusername' is set, you probably don't need to use ; If 'username' or 'pamusername' is set, you probably don't need to use
; the two parameter variant with 'u'. ; the two parameter variant with 'u'.
#chansrvport=DISPLAY(n) #chansrvport=DISPLAY(n)