Merge pull request #488 from metalefty/docs

Update man pages and config files
master
Itamar Reis Peixoto 8 years ago committed by GitHub
commit f7b0b0d89c

@ -1,5 +1,5 @@
.\" .\"
.TH "sesman.ini" "5" "0.1.0" "xrdp team" "" .TH "sesman.ini" "5" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
\fBsesman.ini\fR \- Configuration file for \fBxrdp-sesman\fR(8) \fBsesman.ini\fR \- Configuration file for \fBxrdp-sesman\fR(8)
@ -47,14 +47,15 @@ Following parameters can be used in the \fB[Globals]\fR section.
.TP .TP
\fBListenAddress\fR=\fIip address\fR \fBListenAddress\fR=\fIip address\fR
xrdp-sesman listening address. Default is 0.0.0.0 (all interfaces). xrdp-sesman listening address. If not specified, defaults to \fI0.0.0.0\fR
(all interfaces).
.TP .TP
\fBListenPort\fR=\fIport number\fR \fBListenPort\fR=\fIport number\fR
xrdp-sesman listening port. Default is 3350. xrdp-sesman listening port. If not specified, defaults to \fI3350\fR.
.TP .TP
\fBEnableUserWindowManager\fR=\fI[0|1]\fR \fBEnableUserWindowManager\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR, this option enables user If set to \fB1\fR, \fBtrue\fR or \fByes\fR, this option enables user
specific startup script. That is, xrdp-sesman will execute the script specific startup script. That is, xrdp-sesman will execute the script
specified by \fBUserWindowManager\fR if it exists. specified by \fBUserWindowManager\fR if it exists.
@ -75,8 +76,8 @@ Following parameters can be used in the \fB[Logging]\fR section.
.TP .TP
\fBLogFile\fR=\fIfilename\fR \fBLogFile\fR=\fIfilename\fR
Log file path. It can be either absolute or relative. The default is Log file path. It can be either absolute or relative. If not specified,
\fI./sesman.log\fR defaults to \fI./sesman.log\fR
.TP .TP
\fBLogLevel\fR=\fIlevel\fR \fBLogLevel\fR=\fIlevel\fR
@ -95,7 +96,7 @@ logged \fIregardless\fR of the selected logging level.
debug mode, this options will output many more low\-level messages. debug mode, this options will output many more low\-level messages.
.TP .TP
\fBEnableSyslog\fR=\fI[0|1]\fR \fBEnableSyslog\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR, this option enables logging to If set to \fB1\fR, \fBtrue\fR or \fByes\fR, this option enables logging to
syslog. syslog.
@ -111,7 +112,8 @@ Following parameters can be used in the \fB[Sessions]\fR section.
.TP .TP
\fBX11DisplayOffset\fR=\fInumber\fR \fBX11DisplayOffset\fR=\fInumber\fR
The first X display number available for xrdp-sesman. This prevents The first X display number available for xrdp-sesman. This prevents
xrdp-sesman from interfering with real X11 servers. The default is 10. xrdp-sesman from interfering with real X11 servers. If not specified,
defaults to \fI10\fR.
.TP .TP
\fBMaxSessions\fR=\fInumber\fR \fBMaxSessions\fR=\fInumber\fR
@ -119,7 +121,7 @@ Sets the maximum number of simultaneous sessions. If not set or set to
\fI0\fR, unlimited session are allowed. \fI0\fR, unlimited session are allowed.
.TP .TP
\fBKillDisconnected\fR=\fI[0|1]\fR \fBKillDisconnected\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR, every session will be killed If set to \fB1\fR, \fBtrue\fR or \fByes\fR, every session will be killed
within 60 seconds after the user disconnects. within 60 seconds after the user disconnects.
@ -163,15 +165,15 @@ off. For Xvnc connections, \fBDisplaySize\fR is always enabled as well.
Following parameters can be used in the \fB[Security]\fR section. Following parameters can be used in the \fB[Security]\fR section.
.TP .TP
\fBAllowRootLogin\fR=\fI[0|1]\fR \fBAllowRootLogin\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR, enables root login on the If set to \fB1\fR, \fBtrue\fR or \fByes\fR, enables root login on the
terminal server. terminal server.
.TP .TP
\fBMaxLoginRetry\fR=\fInumber\fR \fBMaxLoginRetry\fR=\fInumber\fR
The number of login attempts that are allowed on terminal server. If set The number of login attempts that are allowed on terminal server. If set
to \fI0\fR, unlimited attempts are allowed. The default value for this to \fI0\fR, unlimited attempts are allowed. If not specified, defaults to
field is \fI3\fR. \fI3\fR.
.TP .TP
\fBTerminalServerUsers\fR=\fIgroup\fR \fBTerminalServerUsers\fR=\fIgroup\fR
@ -185,7 +187,7 @@ login for all users is enabled.
have session management rights. have session management rights.
.TP .TP
\fBAlwaysGroupCheck\fR=\fI[0|1]\fR \fBAlwaysGroupCheck\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR, require group membership even If set to \fB1\fR, \fBtrue\fR or \fByes\fR, require group membership even
if the group specified in \fBTerminalServerUsers\fR doesn't exist. if the group specified in \fBTerminalServerUsers\fR doesn't exist.
@ -207,10 +209,10 @@ Following parameters can be used in the \fB[Chansrv]\fR section.
.TP .TP
\fBFuseMountName\fR=\fIstring\fR \fBFuseMountName\fR=\fIstring\fR
Directory for drive redirection, relative to the user home directory. Directory for drive redirection, relative to the user home directory.
Created if it doesn't exist. Defaults to \fIxrdp_client\fR Created if it doesn't exist. If not specified, defaults to \fIxrdp_client\fR.
.SH "SESSIONS VARIABLES" .SH "SESSIONS VARIABLES"
All entries it the \fB[SessionVariables]\fR section are set as All entries in the \fB[SessionVariables]\fR section are set as
environment variables in the user's session. environment variables in the user's session.
.SH "FILES" .SH "FILES"
@ -222,4 +224,4 @@ environment variables in the user's session.
.BR xrdp (8), .BR xrdp (8),
.BR xrdp.ini (5) .BR xrdp.ini (5)
For more info on \fBxrdp\fR see http://xrdp.sf.net For more info on \fBxrdp\fR see http://www.xrdp.org/

@ -1,4 +1,4 @@
.TH "xrdp\-chansrv" "8" "0.7.0" "xrdp team" "" .TH "xrdp\-chansrv" "8" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
\fBxrdp\-chansrv\fR \- \fBxrdp\fR channel server \fBxrdp\-chansrv\fR \- \fBxrdp\fR channel server
@ -43,4 +43,4 @@ Log file used by \fBxrdp\-chansrv\fP(8).
.BR xrdp\-sesman (8), .BR xrdp\-sesman (8),
.BR sesman.ini (5). .BR sesman.ini (5).
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -1,4 +1,4 @@
.TH "xrdp-dis" "8" "0.7.0" "xrdp team" .TH "xrdp-dis" "1" "0.9.0" "xrdp team"
.SH NAME .SH NAME
xrdp\-dis \- xrdp disconnect utility xrdp\-dis \- xrdp disconnect utility
@ -19,5 +19,9 @@ to get the default host and display number.
.I /tmp/.xrdp/xrdp_disconnect_display_* .I /tmp/.xrdp/xrdp_disconnect_display_*
UNIX socket used to communicate with the \fBxrdp\fP(8) session manager. UNIX socket used to communicate with the \fBxrdp\fP(8) session manager.
.SH KNOWN ISSUES
.TP
This utility doesn't support disconnecting xorgxrdp sessions so far.
.SH SEE ALSO .SH SEE ALSO
.BR xrdp (1). .BR xrdp (8).

@ -1,4 +1,4 @@
.TH "xrdp\-genkeymap" "8" "0.1.0" "xrdp team" "" .TH "xrdp\-genkeymap" "8" "0.9.0" "xrdp team" ""
.de URL .de URL
. \\$2 \(laURL: \\$1 \(ra\\$3 . \\$2 \(laURL: \\$1 \(ra\\$3
.. ..
@ -26,31 +26,31 @@ Files containing the keyboard mapping for language \fIXXXXXXXX\fP, which is a 8
.RS 8 .RS 8
.TP .TP
.B 00000405 .B 00000405
cs czech cs Czech
.TP .TP
.B 00000407 .B 00000407
de german de German
.TP .TP
.B 00000409 .B 00000409
en-us us english en-us US English
.TP .TP
.B 0000040c .B 0000040c
fr french fr French
.TP .TP
.B 00000410 .B 00000410
it italy it Italian
.TP .TP
.B 00000416 .B 00000416
br Portuguese (Brazil) br Portuguese (Brazil)
.TP .TP
.B 00000419 .B 00000419
ru russian ru Russian
.TP .TP
.B 0000041d .B 0000041d
se swedish se Swedish
.TP .TP
.B 00000809 .B 00000809
en-uk uk english en-uk UK English
.RE .RE
.SH "AUTHORS" .SH "AUTHORS"
@ -64,4 +64,4 @@ Simone Fedele <ilsimo@users.sourceforge.net>
.BR unicode (7), .BR unicode (7),
.URL "https://github.com/FreeRDP/FreeRDP/wiki/Keyboard" "Description of Keyboard Input mapping" . .URL "https://github.com/FreeRDP/FreeRDP/wiki/Keyboard" "Description of Keyboard Input mapping" .
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -3,7 +3,7 @@
.\" Copyright © 2007, 2008 Vincent Bernat <bernat@debian.org> .\" Copyright © 2007, 2008 Vincent Bernat <bernat@debian.org>
.\" License: GPL-2+ .\" License: GPL-2+
.\"- .\"-
.TH xrdp\-keygen 8 "0.7.0" "xrdp team" .TH xrdp\-keygen 8 "0.9.0" "xrdp team"
.SH NAME .SH NAME
xrdp\-keygen \- xrdp RSA key generation utility xrdp\-keygen \- xrdp RSA key generation utility

@ -1,4 +1,4 @@
.TH "xrdp\-sesman" "8" "0.1.0" "xrdp team" "" .TH "xrdp\-sesman" "8" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
xrdp\-sesman \- \fBxrdp\fR(8) session manager xrdp\-sesman \- \fBxrdp\fR(8) session manager
@ -9,7 +9,7 @@ xrdp\-sesman \- \fBxrdp\fR(8) session manager
.SH "DESCRIPTION" .SH "DESCRIPTION"
\fBxrdp\-sesman\fR is \fBxrdp\fR(8) session manager. \fBxrdp\-sesman\fR is \fBxrdp\fR(8) session manager.
.br .br
It manages user sessions by authenticating the user and starting the appropriate Xserver It manages user sessions by authenticating the user and starting the appropriate Xserver.
.SH "OPTIONS" .SH "OPTIONS"
.TP .TP
@ -44,4 +44,4 @@ Simone Fedele <ilsimo@users.sourceforge.net>
.BR xrdp (8), .BR xrdp (8),
.BR xrdp.ini (5) .BR xrdp.ini (5)
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -1,4 +1,4 @@
.TH "xrdp\-sesrun" "8" "0.7.0" "xrdp team" "" .TH "xrdp\-sesrun" "8" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
xrdp\-sesrun \- \fBsesman\fR(8) session launcher xrdp\-sesrun \- \fBsesman\fR(8) session launcher
@ -47,4 +47,4 @@ Simone Fedele <ilsimo@users.sourceforge.net>
.BR xrdp (8), .BR xrdp (8),
.BR xrdp.ini (5) .BR xrdp.ini (5)
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -1,4 +1,4 @@
.TH "xrdp\-sessvc" "8" "0.7.0" "xrdp team" "" .TH "xrdp\-sessvc" "8" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
xrdp\-sessvc \- \fBxrdp\fR session supervisor xrdp\-sessvc \- \fBxrdp\fR session supervisor
@ -23,4 +23,4 @@ The process ID of the forked Window Manager to monitor.
.SH "SEE ALSO" .SH "SEE ALSO"
.BR xrdp\-sesrun (8). .BR xrdp\-sesrun (8).
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -1,4 +1,4 @@
.TH "xrdp-xcon" "8" "0.7.0" "xrdp team" .TH "xrdp-xcon" "8" "0.9.0" "xrdp team"
.SH NAME .SH NAME
xrdp\-xcon \- X11 event loop debugging helper for XRDP xrdp\-xcon \- X11 event loop debugging helper for XRDP

@ -1,4 +1,4 @@
.TH "xrdp" "8" "0.1.0" "xrdp team" "" .TH "xrdp" "8" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
\fBxrdp\fR \- a Remote Desktop Protocol (RDP) server \fBxrdp\fR \- a Remote Desktop Protocol (RDP) server
@ -43,4 +43,4 @@ Simone Fedele <ilsimo@users.sourceforge.net>
.BR sesman.ini (5), .BR sesman.ini (5),
.BR sesrun (8) .BR sesrun (8)
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -1,4 +1,4 @@
.TH "xrdp.ini" "5" "0.7.0" "xrdp team" "" .TH "xrdp.ini" "5" "0.9.0" "xrdp team" ""
.SH "NAME" .SH "NAME"
\fBxrdp.ini\fR \- Configuration file for \fBxrdp\fR(8) \fBxrdp.ini\fR \- Configuration file for \fBxrdp\fR(8)
@ -17,9 +17,6 @@ It is composed by a number of sections, each one composed by a section name, enc
.TP .TP
\fB[Channels]\fP \- channel subsystem parameters \fB[Channels]\fP \- channel subsystem parameters
.TP
\fI[Connection]\fP \- contain the info on which services \fBxrdp\fR(8) can connect to.
.LP .LP
All options and values (except for file names and paths) are case insensitive, and are described in detail below. All options and values (except for file names and paths) are case insensitive, and are described in detail below.
@ -28,7 +25,7 @@ The options to be specified in the \fB[Globals]\fR section are the following:
.TP .TP
\fBaddress\fP=\fIip address\fP \fBaddress\fP=\fIip address\fP
Specifies xrdp listening address. Default is 0.0.0.0 (all interfaces) Specify xrdp listening address. If not specified, defaults to 0.0.0.0 (all interfaces).
.TP .TP
\fBautorun\fP=\fIsession_name\fP \fBautorun\fP=\fIsession_name\fP
@ -37,56 +34,86 @@ By default a drop-down list with all available connections is shown.
A connection can also be chosen by the connecting client by setting the \fBLOGIN DOMAIN\fP to a valid \fIsession name\fP. A connection can also be chosen by the connecting client by setting the \fBLOGIN DOMAIN\fP to a valid \fIsession name\fP.
.TP .TP
\fBbitmap_cache\fR=\fI[0|1]\fR \fBbitmap_cache\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables bitmap caching in \fBxrdp\fR(8). If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables bitmap caching in \fBxrdp\fR(8).
.TP .TP
\fBbitmap_compression\fR=\fI[0|1]\fR \fBbitmap_compression\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables bitmap compression in \fBxrdp\fR(8). If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables bitmap compression in \fBxrdp\fR(8).
.TP .TP
\fBbulk_compression\fP=\fI[0|1]\fP \fBbulk_compression\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables compression of bulk data in \fBxrdp\fR(8). If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables compression of bulk data in \fBxrdp\fR(8).
.TP .TP
\fBchannel_code\fP=\fI[0|1]\fP \fBcertificate\fP=\fI/path/to/certificate\fP
.TP
\fBkey_file\fP=\fI/path/to/private_key\fP
Set location of TLS certificate and private key. They must be written in PEM format.
If not specified, defaults to \fB${XRDP_CFG_DIR}/cert.pem\fP, \fB${XRDP_CFG_DIR}/key.pem\fP.
This parameter is effective only if \fBsecurity_layer\fP is set to \fBtls\fP or \fBnegotiate\fP.
.TP
\fBchannel_code\fP=\fI[true|false]\fP
If set to \fB0\fR, \fBfalse\fR or \fBno\fR this option disables all channels \fBxrdp\fR(8). If set to \fB0\fR, \fBfalse\fR or \fBno\fR this option disables all channels \fBxrdp\fR(8).
See section \fBCHANNELS\fP below for more fine grained options. See section \fBCHANNELS\fP below for more fine grained options.
.TP .TP
\fBcrypt_level\fP=\fIlow|medium|high|fips\fP \fBcrypt_level\fP=\fI[low|medium|high|fips]\fP
.\" <http://blogs.msdn.com/b/openspecification/archive/2011/12/08/encryption-negotiation-in-rdp-connection.aspx> .\" <http://blogs.msdn.com/b/openspecification/archive/2011/12/08/encryption-negotiation-in-rdp-connection.aspx>
RDP connection are controlled by two encryption settings: \fIEncryption Level\fP and \fIEncryption Method\fP. Regulate encryption level of Standard RDP Security.
The only supported \fIEncryption Method\fP is \fB40BIT_ENCRYPTION\fP, \fB128BIT_ENCRYPTION\fP and \fB56BIT_ENCRYPTION\fP are currently not supported. This parameter is effective only if \fBsecurity_layer\fP is set to \fBrdp\fP or \fBnegotiate\fP.
Encryption in Standard RDP Security is controlled by two settings: \fIEncryption Level\fP
and \fIEncryption Method\fP. The only supported \fIEncryption Method\fP are \fB40BIT_ENCRYPTION\fP
and \fB128BIT_ENCRYPTION\fP. \fB56BIT_ENCRYPTION\fP is not supported.
This option controls the \fIEncryption Level\fP: This option controls the \fIEncryption Level\fP:
.RS 8 .RS 8
.TP .TP
.B low .B low
All data sent from the client to the server is protected by encryption based on the maximum key strength supported by the client. All data sent from the client to the server is protected by encryption based on
the maximum key strength supported by the client.
.I This is the only level that the traffic sent by the server to client is not encrypted. .I This is the only level that the traffic sent by the server to client is not encrypted.
.TP .TP
.B medium .B medium
All data sent between the client and the server is protected by encryption based on the maximum key strength supported by the client. All data sent between the client and the server is protected by encryption based on
the maximum key strength supported by the client (client compatible).
.TP .TP
.B high .B high
All data sent between the client and server is protected by encryption based on the server's maximum key strength. All data sent between the client and the server is protected by encryption based on
the server's maximum key strength (sever compatible).
.TP .TP
.B fips .B fips
All data sent between the client and server is protected using Federal Information Processing Standard 140-1 validated encryption methods. All data sent between the client and server is protected using Federal Information
.I This level is required for Windows clients (mstsc.exe) if the client's group policy enforces FIPS-compliance mode. Processing Standard 140-1 validated encryption methods.
.I This level is required for Windows clients (mstsc.exe) if the client's group policy
.I enforces FIPS-compliance mode.
.RE .RE
.TP .TP
\fBfork\fP=\fI[0|1]\fP \fBdisableSSLv3\fP=\fI[true|false]\fP
If set to \fB1\fP, \fBtrue\fP or \fByes\fP, \fBxrdp\fP will not accept SSLv3 connections.
If not specified, defaults to \fBfalse\fP.
This parameter is effective only if \fBsecurity_layer\fP is set to \fBtls\fP or \fBnegotiate\fP.
.TP
\fBfork\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR for each incoming connection \fBxrdp\fR(8) forks a sub-process instead of using threads. If set to \fB1\fR, \fBtrue\fR or \fByes\fR for each incoming connection \fBxrdp\fR(8) forks a sub-process instead of using threads.
.TP .TP
\fBhidelogwindow\fP=\fI[0|1]\fP \fBhidelogwindow\fP=\fI[true|false]\fP
If set to \fB1\fP, \fBtrue\fP or \fByes\fP, \fBxrdp\fP will not show a window for log messages. If set to \fB1\fP, \fBtrue\fP or \fByes\fP, \fBxrdp\fP will not show a window for log messages.
If not specified, defaults to \fBfalse\fP.
.TP .TP
\fBmax_bpp\fP=\fI[8|15|16|24]\fP \fBmax_bpp\fP=\fI[8|15|16|24|32]\fP
Limit the color depth by specifying the maximum number of bits per pixel. Limit the color depth by specifying the maximum number of bits per pixel.
If not specified or set to \fB0\fP, unlimited.
.TP
\fBpamerrortxt\fP=\fIerror_text\fP
Specify text passed to PAM when authentication failed. The maximum length is \fB256\fP.
.TP .TP
\fBport\fP=\fIport\fP \fBport\fP=\fIport\fP
@ -94,15 +121,60 @@ Specify TCP port to listen on for incoming connections.
The default for RDP is \fB3389\fP. The default for RDP is \fB3389\fP.
.TP .TP
\fBtcp_keepalive\fP=\fI[yes|no]\fP \fBrequire_credentials\fP=\fI[true|false]\fP
If set to \fB1\fP, \fBtrue\fP or \fByes\fP, \fBxrdp\fP requires clients to include username and
password initial connection phase. In other words, xrdp doesn't allow clients to show login
screen if set to true. If not specified, defaults to \fBfalse\fP.
.TP
\fBsecurity_layer\fP=\fI[tls|rdp|negotiate]\fP
Regulate security methods. If not specified, defaults to \fBnegotiate\fP.
.RS 8
.TP
.B tls
Enhanced RDP Security is used. All security operations (encryption, decryption, data integrity
verification, and server authentication) are implemented by TLS.
.TP
.B rdp
Standard RDP Security, which is not safe from man-in-the-middle attack, is used. The encryption level
of Standard RDP Security is controlled by \fBcrypt_level\fP.
.TP
.B negotiate
Negotiate these security methods with clients.
.RE
.TP
\fBtcp_keepalive\fP=\fI[true|false]\fP
Regulate if the listening socket uses socket option \fBSO_KEEPALIVE\fP. Regulate if the listening socket uses socket option \fBSO_KEEPALIVE\fP.
If set to \fB1\fP, \fBtrue\fP or \fByes\fP and the network connection disappears without closing messages, the connection will be closed. If set to \fB1\fP, \fBtrue\fP or \fByes\fP and the network connection disappears
without closing messages, the connection will be closed.
.TP .TP
\fBtcp_nodelay\fP=\fI[yes|no]\fP \fBtcp_nodelay\fP=\fI[true|false]\fP
Regulate if the listening socket uses socket option \fBTCP_NODELAY\fP. Regulate if the listening socket uses socket option \fBTCP_NODELAY\fP.
If set to \fB1\fP, \fBtrue\fP or \fByes\fP, no buffering will be performed in the TCP stack. If set to \fB1\fP, \fBtrue\fP or \fByes\fP, no buffering will be performed in the TCP stack.
.TP
\fBtcp_send_buffer_bytes\fP=\fIbuffer_size\fP
.TP
\fBtcp_recv_buffer_bytes\fP=\fIbuffer_size\fP
Specify send/recv buffer sizes in bytes. The default value depends on operating system.
.TP
\fBtls_ciphers\fP=\fIcipher_suite\fP
Specifies TLS cipher suite. The format of this parameter is equivalent to which
\fBopenssl\fP(1) ciphers subcommand accepts.
(ex. $ openssl ciphers 'HIGH:!ADH:!SHA1')
This parameter is effective only if \fBsecurity_layer\fP is set to \fBtls\fP or \fBnegotiate\fP.
.TP
\fBuse_fastpath\fP=\fI[input|output|both|none]\fP
If not specified, defaults to \fBnone\fP.
.TP .TP
\fBblack\fP=\fI000000\fP \fBblack\fP=\fI000000\fP
.TP .TP
@ -127,7 +199,7 @@ The lowest value that can be given to one of the light sources is 0 (hex 00).
The highest value is 255 (hex FF). The highest value is 255 (hex FF).
.SH "LOGGING" .SH "LOGGING"
The following parameters can be used in the \fB[logging]\fR section: The following parameters can be used in the \fB[Logging]\fR section:
.TP .TP
\fBLogFile\fR=\fI${SESMAN_LOG_DIR}/sesman.log\fR \fBLogFile\fR=\fI${SESMAN_LOG_DIR}/sesman.log\fR
@ -148,7 +220,7 @@ This option can have one of the following values:
\fBDEBUG\fR or \fB4\fR \- Log everything. If \fBsesman\fR is compiled in debug mode, this options will output many more low\-level message, useful for developers \fBDEBUG\fR or \fB4\fR \- Log everything. If \fBsesman\fR is compiled in debug mode, this options will output many more low\-level message, useful for developers
.TP .TP
\fBEnableSyslog\fR=\fI[0|1]\fR \fBEnableSyslog\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables logging to syslog. Otherwise syslog is disabled. If set to \fB1\fR, \fBtrue\fR or \fByes\fR this option enables logging to syslog. Otherwise syslog is disabled.
.TP .TP
@ -163,27 +235,27 @@ Not all channels are supported in all cases, so setting a value to \fItrue\fP is
Channels can also be enabled or disabled on a per connection basis by prefixing each setting with \fBchannel.\fP in the channel section. Channels can also be enabled or disabled on a per connection basis by prefixing each setting with \fBchannel.\fP in the channel section.
.TP .TP
\fBrdpdr\fP=\fI[0|1]\fP \fBrdpdr\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for device redirection is allowed. If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for device redirection is allowed.
.TP .TP
\fBrdpsnd\fP=\fI[0|1]\fP \fBrdpsnd\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for sound is allowed. If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for sound is allowed.
.TP .TP
\fBdrdynvc\fP=\fI[0|1]\fP \fBdrdynvc\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel to initiate additional dynamic virtual channels is allowed. If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel to initiate additional dynamic virtual channels is allowed.
.TP .TP
\fBcliprdr\fP=\fI[0|1]\fP \fBcliprdr\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for clipboard redirection is allowed. If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for clipboard redirection is allowed.
.TP .TP
\fBrail\fP=\fI[0|1]\fP \fBrail\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for remote applications integrated locally (RAIL) is allowed. If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for remote applications integrated locally (RAIL) is allowed.
.TP .TP
\fBxrdpvr\fP=\fI[0|1]\fP \fBxrdpvr\fP=\fI[true|false]\fP
If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for XRDP Video streaming is allowed. If set to \fB1\fR, \fBtrue\fR or \fByes\fR using the RDP channel for XRDP Video streaming is allowed.
.SH "CONNECTIONS" .SH "CONNECTIONS"
@ -224,8 +296,8 @@ This is an example \fBxrdp.ini\fR:
.nf .nf
[Globals] [Globals]
bitmap_cache=yes bitmap_cache=true
bitmap_compression=yes bitmap_compression=true
[vnc1] [vnc1]
name=sesman name=sesman
@ -245,4 +317,4 @@ ${XRDP_CFG_DIR}/xrdp.ini
.BR sesrun (8), .BR sesrun (8),
.BR sesman.ini (5) .BR sesman.ini (5)
for more info on \fBxrdp\fR see http://xrdp.sf.net for more info on \fBxrdp\fR see http://www.xrdp.org/

@ -19,7 +19,7 @@ setxkbmap -model pc105 -layout gb
setxkbmap -model pc104 -layout de setxkbmap -model pc104 -layout de
./xrdp-genkeymap ../instfiles/km-00000407.ini ./xrdp-genkeymap ../instfiles/km-00000407.ini
# Italy 'it' 0x00000410 # Italian 'it' 0x00000410
setxkbmap -model pc104 -layout it setxkbmap -model pc104 -layout it
./xrdp-genkeymap ../instfiles/km-00000410.ini ./xrdp-genkeymap ../instfiles/km-00000410.ini

@ -1,59 +1,58 @@
[Globals] [Globals]
ListenAddress=127.0.0.1 ListenAddress=127.0.0.1
ListenPort=3350 ListenPort=3350
EnableUserWindowManager=1 EnableUserWindowManager=true
UserWindowManager=startwm.sh UserWindowManager=startwm.sh
DefaultWindowManager=startwm.sh DefaultWindowManager=startwm.sh
[Security] [Security]
AllowRootLogin=1 AllowRootLogin=true
MaxLoginRetry=4 MaxLoginRetry=4
TerminalServerUsers=tsusers TerminalServerUsers=tsusers
TerminalServerAdmins=tsadmins TerminalServerAdmins=tsadmins
# When AlwaysGroupCheck = false access will be permitted ; When AlwaysGroupCheck=false access will be permitted
# if the group TerminalServerUsers is not defined. ; if the group TerminalServerUsers is not defined.
AlwaysGroupCheck=false AlwaysGroupCheck=false
[Sessions] [Sessions]
;; X11DisplayOffset - x11 display number offset
## X11DisplayOffset - x11 display number offset ; Type: integer
# Type: integer ; Default: 10
# Default: 10
X11DisplayOffset=10 X11DisplayOffset=10
## MaxSessions - maximum number of connections to an xrdp server ;; MaxSessions - maximum number of connections to an xrdp server
# Type: integer ; Type: integer
# Default: 0 ; Default: 0
MaxSessions=50 MaxSessions=50
## KillDisconnected - kill disconnected sessions ;; KillDisconnected - kill disconnected sessions
# Type: integer ; Type: boolean
# Default: 0 ; Default: false
# if 1, true, or yes, kill session after 60 seconds ; if 1, true, or yes, kill session after 60 seconds
KillDisconnected=0 KillDisconnected=false
## IdleTimeLimit - when to disconnect idle sessions ;; IdleTimeLimit - when to disconnect idle sessions
# Type: integer ; Type: integer
# Default: 0 ; Default: 0
# if not zero, the seconds without mouse or keyboard input before disconnect ; if not zero, the seconds without mouse or keyboard input before disconnect
# not complete yet ; not complete yet
IdleTimeLimit=0 IdleTimeLimit=0
## DisconnectedTimeLimit - when to kill idle sessions ;; DisconnectedTimeLimit - when to kill idle sessions
# Type: integer ; Type: integer
# Default: 0 ; Default: 0
# if not zero, the seconds before a disconnected session is killed ; if not zero, the seconds before a disconnected session is killed
# min 60 seconds ; min 60 seconds
DisconnectedTimeLimit=0 DisconnectedTimeLimit=0
## Policy - session allocation policy ;; Policy - session allocation policy
# Type: enum [ "Default" | "UBD" | "UBI" | "UBC" | "UBDI" | "UBDC" ] ; Type: enum [ "Default" | "UBD" | "UBI" | "UBC" | "UBDI" | "UBDC" ]
# Default: Xrdp:<User,BitPerPixel> and Xvnc:<User,BitPerPixel,DisplaySize> ; Default: Xrdp:<User,BitPerPixel> and Xvnc:<User,BitPerPixel,DisplaySize>
# "UBD" session per <User,BitPerPixel,DisplaySize> ; "UBD" session per <User,BitPerPixel,DisplaySize>
# "UBI" session per <User,BitPerPixel,IPAddr> ; "UBI" session per <User,BitPerPixel,IPAddr>
# "UBC" session per <User,BitPerPixel,Connection> ; "UBC" session per <User,BitPerPixel,Connection>
# "UBDI" session per <User,BitPerPixel,DisplaySize,IPAddr> ; "UBDI" session per <User,BitPerPixel,DisplaySize,IPAddr>
# "UBDC" session per <User,BitPerPixel,DisplaySize,Connection> ; "UBDC" session per <User,BitPerPixel,DisplaySize,Connection>
Policy=Default Policy=Default
[Logging] [Logging]
@ -92,7 +91,7 @@ param=-logfile
param=/dev/null param=/dev/null
[Chansrv] [Chansrv]
# drive redirection, defaults to xrdp_client if not set ; drive redirection, defaults to xrdp_client if not set
FuseMountName=thinclient_drives FuseMountName=thinclient_drives
[SessionVariables] [SessionVariables]

@ -1,43 +1,57 @@
[globals] [Globals]
# xrdp.ini file version number ; xrdp.ini file version number
ini_version=1 ini_version=1
bitmap_cache=yes ; fork a new process for each incoming connection
bitmap_compression=yes fork=true
; tcp port to listen
port=3389 port=3389
allow_channels=true ; regulate if the listening socket use socket option tcp_nodelay
max_bpp=32 ; no buffering will be performed in the TCP stack
fork=yes tcp_nodelay=true
# minimum security level allowed for client ; regulate if the listening socket use socket option keepalive
# can be 'none', 'low', 'medium', 'high', 'fips' ; if the network connection disappear without close messages the connection will be closed
crypt_level=high tcp_keepalive=true
# security layer can be 'tls', 'rdp' or 'negotiate' #tcp_send_buffer_bytes=32768
# for client compatible layer #tcp_recv_buffer_bytes=32768
; security layer can be 'tls', 'rdp' or 'negotiate'
; for client compatible layer
security_layer=negotiate security_layer=negotiate
# X.509 certificate and private key ; minimum security level allowed for client
# openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365 ; can be 'none', 'low', 'medium', 'high', 'fips'
crypt_level=high
; X.509 certificate and private key
; openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365
certificate= certificate=
key_file= key_file=
# disable SSlv3 ; specify whether SSLv3 should be disabled
#disableSSLv3=yes #disableSSLv3=true
# set TLS cipher suites ; set TLS cipher suites
#tls_ciphers=HIGH #tls_ciphers=HIGH
# regulate if the listening socket use socket option tcp_nodelay ; Section name to use for automatic login if the client sends username
# no buffering will be performed in the TCP stack ; and password
tcp_nodelay=yes autorun=X11rdp
# regulate if the listening socket use socket option keepalive
# if the network connection disappear without close messages the connection will be closed
tcp_keepalive=yes
#tcp_send_buffer_bytes=32768
#tcp_recv_buffer_bytes=32768
# allow_channels=true
# colors used by windows in RGB format allow_multimon=true
# bitmap_cache=true
bitmap_compression=true
bulk_compression=true
#hidelogwindow=true
max_bpp=32
new_cursors=true
; fastpath - can be 'input', 'output', 'both', 'none'
use_fastpath=both
; when true, userid/password *must* be passed on cmd line
#require_credentials=true
; You can set the PAM error text in a gateway setup (MAX 256 chars)
#pamerrortxt=change your password according to policy at http://url
;
; colors used by windows in RGB format
;
blue=009cb5 blue=009cb5
grey=dedede grey=dedede
#black=000000 #black=000000
@ -49,68 +63,50 @@ grey=dedede
#green=00ff00 #green=00ff00
#background=626c72 #background=626c72
#hidelogwindow=yes ;
; configure login screen
# when true, userid/password *must* be passed on cmd line ;
# require_credentials=yes
# Section name to use for automatic login if the client sends username
# and password
autorun=X11rdp
bulk_compression=yes
# You can set the PAM error text in a gateway setup (MAX 256 chars) ; Login Screen Window Title
#pamerrortxt=change your password according to policy at http://url
new_cursors=yes
allow_multimon=true
# fastpath - can be set to input / output / both / none
use_fastpath=both
#
# configure login screen
#
# Login Screen Window Title
#ls_title=My Login Title #ls_title=My Login Title
# top level window background color in RGB format ; top level window background color in RGB format
ls_top_window_bg_color=009cb5 ls_top_window_bg_color=009cb5
# width and height of login screen ; width and height of login screen
ls_width=350 ls_width=350
ls_height=430 ls_height=430
# login screen background color in RGB format ; login screen background color in RGB format
ls_bg_color=dedede ls_bg_color=dedede
# optional background image filename (bmp format). ; optional background image filename (bmp format).
#ls_background_image= #ls_background_image=
# logo ; logo
# full path to bmp-file or file in shared folder ; full path to bmp-file or file in shared folder
ls_logo_filename= ls_logo_filename=
ls_logo_x_pos=55 ls_logo_x_pos=55
ls_logo_y_pos=50 ls_logo_y_pos=50
# for positioning labels such as username, password etc ; for positioning labels such as username, password etc
ls_label_x_pos=30 ls_label_x_pos=30
ls_label_width=60 ls_label_width=60
# for positioning text and combo boxes next to above labels ; for positioning text and combo boxes next to above labels
ls_input_x_pos=110 ls_input_x_pos=110
ls_input_width=210 ls_input_width=210
# y pos for first label and combo box ; y pos for first label and combo box
ls_input_y_pos=220 ls_input_y_pos=220
# OK button ; OK button
ls_btn_ok_x_pos=142 ls_btn_ok_x_pos=142
ls_btn_ok_y_pos=370 ls_btn_ok_y_pos=370
ls_btn_ok_width=85 ls_btn_ok_width=85
ls_btn_ok_height=30 ls_btn_ok_height=30
# Cancel button ; Cancel button
ls_btn_cancel_x_pos=237 ls_btn_cancel_x_pos=237
ls_btn_cancel_y_pos=370 ls_btn_cancel_y_pos=370
ls_btn_cancel_width=85 ls_btn_cancel_width=85
@ -119,17 +115,17 @@ ls_btn_cancel_height=30
[Logging] [Logging]
LogFile=xrdp.log LogFile=xrdp.log
LogLevel=DEBUG LogLevel=DEBUG
EnableSyslog=1 EnableSyslog=true
SyslogLevel=DEBUG SyslogLevel=DEBUG
# LogLevel and SysLogLevel could by any of: core, error, warning, info or debug ; LogLevel and SysLogLevel could by any of: core, error, warning, info or debug
[channels] [Channels]
# Channel names not listed here will be blocked by XRDP. ; Channel names not listed here will be blocked by XRDP.
# You can block any channel by setting its value to false. ; You can block any channel by setting its value to false.
# IMPORTANT! All channels are not supported in all use ; IMPORTANT! All channels are not supported in all use
# cases even if you set all values to true. ; cases even if you set all values to true.
# You can override these settings on each session type ; You can override these settings on each session type
# These settings are only used if allow_channels=true ; These settings are only used if allow_channels=true
rdpdr=true rdpdr=true
rdpsnd=true rdpsnd=true
drdynvc=true drdynvc=true
@ -138,12 +134,17 @@ rail=true
xrdpvr=true xrdpvr=true
tcutils=true tcutils=true
# for debugging xrdp, in section xrdp1, change port=-1 to this: ; for debugging xrdp, in section xrdp1, change port=-1 to this:
#port=/tmp/.xrdp/xrdp_display_10 #port=/tmp/.xrdp/xrdp_display_10
# for debugging xrdp, add following line to section xrdp1 ; for debugging xrdp, add following line to section xrdp1
#chansrvport=/tmp/.xrdp/xrdp_chansrv_socket_7210 #chansrvport=/tmp/.xrdp/xrdp_chansrv_socket_7210
;
; Session types
;
[X11rdp] [X11rdp]
name=X11rdp name=X11rdp
lib=libxup.so lib=libxup.so
@ -217,7 +218,7 @@ port=ask3389
username=ask username=ask
password=ask password=ask
# You can override the common channel settings for each session type ; You can override the common channel settings for each session type
#channel.rdpdr=true #channel.rdpdr=true
#channel.rdpsnd=true #channel.rdpsnd=true
#channel.drdynvc=true #channel.drdynvc=true

@ -1,59 +1,59 @@
# ;
# RDP Keyboard <-> X11 Keyboard layout map ; RDP Keyboard <-> X11 Keyboard layout map
# ;
# How this file works: ; How this file works:
# 1. load the file and scan each section to find matching "keyboard_type" ; 1. load the file and scan each section to find matching "keyboard_type"
# and "keyboard_subtype" based on the values received from the client. ; and "keyboard_subtype" based on the values received from the client.
# If not found, then jump to default section. ; If not found, then jump to default section.
# 2. in the selected section, look for "rdp_layouts" and "layouts_map". ; 2. in the selected section, look for "rdp_layouts" and "layouts_map".
# Based on the "keylayout" value from the client, find the right x11 ; Based on the "keylayout" value from the client, find the right x11
# layout value. ; layout value.
# 3. model/variant are inferred based on the "keyboard_type" and ; 3. model/variant are inferred based on the "keyboard_type" and
# "keyboard_subtype", but they can be overridden. ; "keyboard_subtype", but they can be overridden.
# ;
# ;
# RDP Keyboard Type (http://msdn.microsoft.com/en-us/library/cc240563.aspx) ; RDP Keyboard Type (http://msdn.microsoft.com/en-us/library/cc240563.aspx)
# ;
# 0 is not a valid value ; 0 is not a valid value
# ;
# 1 - IBM PC/XT or compatible (83-key) keyboard ; 1 - IBM PC/XT or compatible (83-key) keyboard
# 2 - Olivetti "ICO" (102-key) keyboard ; 2 - Olivetti "ICO" (102-key) keyboard
# 3 - IBM PC/AT (84-key) or similar keyboard ; 3 - IBM PC/AT (84-key) or similar keyboard
# 4 - IBM enhanced (101- or 102-key) keyboard ; 4 - IBM enhanced (101- or 102-key) keyboard
# 5 - Nokia 1050 and similar keyboards ; 5 - Nokia 1050 and similar keyboards
# 6 - Nokia 9140 and similar keyboards ; 6 - Nokia 9140 and similar keyboards
# 7 - Japanese keyboard ; 7 - Japanese keyboard
# ;
# RDP Keyboard Subtype is vendor dependent. XRDP defines as follows: ; RDP Keyboard Subtype is vendor dependent. XRDP defines as follows:
# ;
# 0 is not a valid value ; 0 is not a valid value
# ;
# 1 - Standard ; 1 - Standard
# 2 - FreeRDP JP keyboard ; 2 - FreeRDP JP keyboard
# 3 - Macintosh ; 3 - Macintosh
# ... - < any vendor dependent subtype > ; ... - < any vendor dependent subtype >
# ;
# The list can be augmented. ; The list can be augmented.
# ;
# default ; default
[default] [default]
# keyboard_type and keyboard_subtype is not read for default section. It ; keyboard_type and keyboard_subtype is not read for default section. It
# is only a placeholder to keep consistency. Default model/variant are ; is only a placeholder to keep consistency. Default model/variant are
# platform dependent, and could be overridden if needed. ; platform dependent, and could be overridden if needed.
keyboard_type=0 keyboard_type=0
keyboard_subtype=0 keyboard_subtype=0
# user could override variant and model, but generally they should be inferred ; user could override variant and model, but generally they should be inferred
# automatically based on keyboard type and subtype ; automatically based on keyboard type and subtype
#variant= ;variant=
#model= ;model=
# A list of supported RDP keyboard layouts ; A list of supported RDP keyboard layouts
rdp_layouts=default_rdp_layouts rdp_layouts=default_rdp_layouts
# The map from RDP keyboard layout to X11 keyboard layout ; The map from RDP keyboard layout to X11 keyboard layout
layouts_map=default_layouts_map layouts_map=default_layouts_map
[default_rdp_layouts] [default_rdp_layouts]
@ -72,7 +72,7 @@ rdp_layout_pt=0x00000816
rdp_layout_br=0x00000416 rdp_layout_br=0x00000416
rdp_layout_pl=0x00000415 rdp_layout_pl=0x00000415
# <rdp layout name> = <X11 keyboard layout value> ; <rdp layout name> = <X11 keyboard layout value>
[default_layouts_map] [default_layouts_map]
rdp_layout_us=us rdp_layout_us=us
rdp_layout_de=de rdp_layout_de=de
@ -89,8 +89,8 @@ rdp_layout_pt=pt
rdp_layout_br=br(abnt2) rdp_layout_br=br(abnt2)
rdp_layout_pl=pl rdp_layout_pl=pl
# if two sections have the same keyboard_type and keyboard_subtype, then ; if two sections have the same keyboard_type and keyboard_subtype, then
# the latter could override the former. ; the latter could override the former.
[rdp_keyboard_mac] [rdp_keyboard_mac]
keyboard_type=4 keyboard_type=4
keyboard_subtype=3 keyboard_subtype=3

Loading…
Cancel
Save