vmconnect mode: support all security modes when used in Hyper-V environment
This commit is contained in:
+54
-4
@@ -116,6 +116,11 @@ xrdp_iso_negotiate_security(struct xrdp_iso *self)
|
||||
{
|
||||
security_type_mask = PROTOCOL_SSL;
|
||||
}
|
||||
/* But VMConnect mode supports everything. */
|
||||
if (client_info->vmconnect)
|
||||
{
|
||||
security_type_mask |= PROTOCOL_HYBRID | PROTOCOL_HYBRID_EX;
|
||||
}
|
||||
|
||||
/* Logically 'and' this value with the mask requested by the client, and
|
||||
* see what's left */
|
||||
@@ -124,8 +129,36 @@ xrdp_iso_negotiate_security(struct xrdp_iso *self)
|
||||
protostr);
|
||||
security_type_mask &= self->requestedProtocol;
|
||||
|
||||
/* In VMConnect mode, we support everything. */
|
||||
if (client_info->vmconnect && (self->requestedProtocol > PROTOCOL_RDP))
|
||||
{
|
||||
if (security_type_mask & PROTOCOL_HYBRID_EX)
|
||||
{
|
||||
LOG(LOG_LEVEL_INFO, "Selected HYBRID_EX security");
|
||||
self->selectedProtocol = PROTOCOL_HYBRID_EX;
|
||||
got_protocol = 1;
|
||||
}
|
||||
else if (security_type_mask & PROTOCOL_HYBRID)
|
||||
{
|
||||
LOG(LOG_LEVEL_INFO, "Selected HYBRID security");
|
||||
self->selectedProtocol = PROTOCOL_HYBRID;
|
||||
got_protocol = 1;
|
||||
}
|
||||
else if (security_type_mask & PROTOCOL_SSL)
|
||||
{
|
||||
LOG(LOG_LEVEL_INFO, "Selected TLS security");
|
||||
self->selectedProtocol = PROTOCOL_SSL;
|
||||
got_protocol = 1;
|
||||
}
|
||||
else
|
||||
{
|
||||
/* Impossible */
|
||||
LOG(LOG_LEVEL_ERROR, "Impossible case.");
|
||||
rv = 1;
|
||||
}
|
||||
}
|
||||
/* Is there a match on SSL/TLS? */
|
||||
if ((security_type_mask & PROTOCOL_SSL) != 0)
|
||||
else if ((security_type_mask & PROTOCOL_SSL) != 0)
|
||||
{
|
||||
/* Can we do TLS? (basic check) */
|
||||
if (g_file_readable(client_info->certificate) &&
|
||||
@@ -205,13 +238,20 @@ xrdp_iso_process_rdp_neg_req(struct xrdp_iso *self, struct stream *s)
|
||||
/* The type field has already been read to determine that this function
|
||||
should be called */
|
||||
in_uint8(s, flags); /* flags */
|
||||
if (flags != 0x0 && flags != 0x8 && flags != 0x1)
|
||||
if ((flags & 0x0000000b) != flags)
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR,
|
||||
"Unsupported [MS-RDPBCGR] RDP_NEG_REQ flags: 0x%2.2x", flags);
|
||||
return 1;
|
||||
}
|
||||
|
||||
/* If both flags are set, it means 'OR', so fail only if only the one is set. */
|
||||
if ((flags & REDIRECTED_AUTHENTICATION_MODE_REQUIRED) && !(flags & RESTRICTED_ADMIN_MODE_REQUIRED))
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "[MS-RDPBCGR] RDP_NEG_REQ: RemoteGuard isn't supported !");
|
||||
return 1;
|
||||
}
|
||||
|
||||
in_uint16_le(s, len); /* length */
|
||||
if (len != 8)
|
||||
{
|
||||
@@ -374,9 +414,12 @@ xrdp_iso_send_cc(struct xrdp_iso *self)
|
||||
char *holdp;
|
||||
char *len_ptr;
|
||||
char *len_indicator_ptr;
|
||||
char flags;
|
||||
int len;
|
||||
int len_indicator;
|
||||
|
||||
struct xrdp_client_info *client_info = &(self->mcs_layer->sec_layer->rdp_layer->client_info);
|
||||
|
||||
make_stream(s);
|
||||
init_stream(s, 8192);
|
||||
|
||||
@@ -410,10 +453,17 @@ xrdp_iso_send_cc(struct xrdp_iso *self)
|
||||
}
|
||||
else
|
||||
{
|
||||
flags = EXTENDED_CLIENT_DATA_SUPPORTED;
|
||||
|
||||
if (client_info->vmconnect)
|
||||
{
|
||||
/* NLA is handled by the host and not us. */
|
||||
flags |= RESTRICTED_ADMIN_MODE_SUPPORTED;
|
||||
}
|
||||
|
||||
/* [MS-RDPBCGR] RDP_NEG_RSP */
|
||||
out_uint8(s, RDP_NEG_RSP); /* type*/
|
||||
//TODO: hardcoded flags
|
||||
out_uint8(s, EXTENDED_CLIENT_DATA_SUPPORTED); /* flags */
|
||||
out_uint8(s, flags); /* flags */
|
||||
out_uint16_le(s, 8); /* length (must be 8) */
|
||||
out_uint32_le(s, self->selectedProtocol); /* selectedProtocol */
|
||||
LOG_DEVEL(LOG_LEVEL_TRACE, "Adding structure [MS-RDPBCGR] RDP_NEG_RSP "
|
||||
|
||||
Reference in New Issue
Block a user