463e500f77
1) In FIPS mode, Classic RDP security is not allowed at all. 2) In FIPS mode xrdp-keygen creates an empty file 3) Documentation wording improved around the security_level setting 4) Logging improved around the security negotiation 5) Warnings now generated if Classic RDP security is negotiated
49 lines
1.4 KiB
Plaintext
49 lines
1.4 KiB
Plaintext
.\" Hey, EMACS: -*- nroff -*-
|
|
.\"-
|
|
.\" Copyright © 2007, 2008 Vincent Bernat <bernat@debian.org>
|
|
.\" License: GPL-2+
|
|
.\"-
|
|
.TH xrdp\-keygen 8 "@PACKAGE_VERSION@" "xrdp team"
|
|
.SH NAME
|
|
xrdp\-keygen \- xrdp RSA key generation utility
|
|
|
|
.SH SYNOPSIS
|
|
.B xrdp\-keygen xrdp
|
|
< \fIoutfile\fP | \fBauto\fP >
|
|
.br
|
|
.B xrdp\-keygen test
|
|
|
|
.SH DESCRIPTION
|
|
\fBxrdp\-keygen\fP generates the file
|
|
.I @sysconfdir@/@sysconfsubdir@/rsakeys.ini
|
|
which contains the RSA key pair used to perform authentication to
|
|
remote clients. The public key is self-signed.
|
|
|
|
.SH OPTIONS
|
|
This program takes one of the following options:
|
|
.TP
|
|
\fBxrdp\fP \fIoutfile\fP
|
|
Generate a new key pair.
|
|
The key data is stored in the file named \fIoutfile\fP.
|
|
.br
|
|
If \fBauto\fP is used as \fIoutfile\fP, the default file \fI@sysconfdir@/@sysconfsubdir@/rsakeys.ini\fP gets created if it does not yet exists.
|
|
.TP
|
|
.B test
|
|
Generate a test key pair and print information to standard output.
|
|
|
|
.SH NOTES
|
|
On machines with FIPS enabled, this program will generate an empty file,
|
|
and a warning. On these machines, xrdp cannot use Classic RDP encryption.
|
|
|
|
.SH FILES
|
|
.TP
|
|
.I @sysconfdir@/@sysconfsubdir@/rsakeys.ini
|
|
RSA public and private key pair used to identify this XRDP server.
|
|
|
|
.SH SEE ALSO
|
|
.BR xrdp (8),
|
|
.BR xrdp\-sesman (8).
|
|
|
|
.SH AUTHOR
|
|
This manual page was originally written by Vincent Bernat <bernat@luffy.cx>.
|