Re: [ rdesktop-Bugs-2817779 ] Can't connect to WinServ 2008 SP2: "internal license error"

Henrik Andersson <[email protected]> Thu, 03 Nov 2011 10:10:02 +0100
Newsgroups gmane.network.rdesktop.devel
Message-ID <[email protected]>
Hi Thomas,

I'm worried that scatter licenses into several directories introduces an
inconsistency that might be handled wrong from the windows terminal
server view of the device connecting like the following example:

2 users connects to TS from an unknown device to the WTS:

User A connects and receives a temporary CAL while still connected
user B connects without the temporary CAL issued for user A, would
the WTS handle this situation the correct way, issuing same temporary
CAL as given to user A or a would a new one be issued ?

Lets say if a new one is issued eg. the device will have 2 temporary
CALS and what happens if user A connects and the temporary CAL
upgrades and allocates a real device CAL, and then user B connects
with his temporary CAL that is to be upgraded ?

This is just one example of probably alot of test cases such as license
revoking on server side etc., that we must verify if we store device CAL
per user. Microsoft defines the license storage as system wide ,see
http://support.microsoft.com/kb/187614 for reference, and i think we
would gain both time / stability if we follow that road.

My example /usr/share/rdesktop was just used as an example, proper
place might even be /var/cache/rdesktop/licensestorage due the license
storage in my opinion could be seen as a cache ?!



Kind Regards,

Henrik Andersson


On 10/05/2011 05:10 PM, Thomas Uhle wrote:
> Hi Henrik,
>
> that actually seems to be true if you think of starting rdesktop as a user
> that has write access to /usr/share/rdesktop/..., but I can warrant that
> this is never going to happen with our IT administrators. Moreover, the
> licences are updated from time to time during the authentication process.
> So users will definitely need write access.
> Whether RDS per User CALs will be delivered/stored or not, I cannot tell
> since we only have RDS per Device CALs. Anyway, what is the problem about
> storing the CALs in the user's home? The previous implementation also
> stored the CALs in the user's home. That is why I only proposed to amend
> the directory structure. I simply wanted to make as few changes as
> possible.
>
> Perhaps, a possible solution could be to share licences in some directory
> like /var/rdesktop/licences/ with read/write/set-gid permission for
> everyone and if the sticky bit is set as well because the subtree /var/ is
> always local. In some affiliations the subtree /usr/ is shared per NFS
> among several servers for simple maintainance reasons.
> In addition, I would like to have tested whether a user is granted access
> by presenting a CAL that another user has received before, before I would
> propose such a "directory move". Unfortunately, I cannot check this until
> next week.
>
> Best regards,
>
>
> Thomas


------------------------------------------------------------------------------
RSA(R) Conference 2012
Save $700 by Nov 18
Register now
http://p.sf.net/sfu/rsa-sfdev2dev1