Re: [ rdesktop-Bugs-2817779 ] Can't connect to WinServ 2008 SP2: "internal license error"
Henrik Andersson <[email protected]> Thu, 03 Nov 2011 10:10:02 +0100
| Newsgroups | gmane.network.rdesktop.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Thomas, I'm worried that scatter licenses into several directories introduces an inconsistency that might be handled wrong from the windows terminal server view of the device connecting like the following example: 2 users connects to TS from an unknown device to the WTS: User A connects and receives a temporary CAL while still connected user B connects without the temporary CAL issued for user A, would the WTS handle this situation the correct way, issuing same temporary CAL as given to user A or a would a new one be issued ? Lets say if a new one is issued eg. the device will have 2 temporary CALS and what happens if user A connects and the temporary CAL upgrades and allocates a real device CAL, and then user B connects with his temporary CAL that is to be upgraded ? This is just one example of probably alot of test cases such as license revoking on server side etc., that we must verify if we store device CAL per user. Microsoft defines the license storage as system wide ,see http://support.microsoft.com/kb/187614 for reference, and i think we would gain both time / stability if we follow that road. My example /usr/share/rdesktop was just used as an example, proper place might even be /var/cache/rdesktop/licensestorage due the license storage in my opinion could be seen as a cache ?! Kind Regards, Henrik Andersson On 10/05/2011 05:10 PM, Thomas Uhle wrote: > Hi Henrik, > > that actually seems to be true if you think of starting rdesktop as a user > that has write access to /usr/share/rdesktop/..., but I can warrant that > this is never going to happen with our IT administrators. Moreover, the > licences are updated from time to time during the authentication process. > So users will definitely need write access. > Whether RDS per User CALs will be delivered/stored or not, I cannot tell > since we only have RDS per Device CALs. Anyway, what is the problem about > storing the CALs in the user's home? The previous implementation also > stored the CALs in the user's home. That is why I only proposed to amend > the directory structure. I simply wanted to make as few changes as > possible. > > Perhaps, a possible solution could be to share licences in some directory > like /var/rdesktop/licences/ with read/write/set-gid permission for > everyone and if the sticky bit is set as well because the subtree /var/ is > always local. In some affiliations the subtree /usr/ is shared per NFS > among several servers for simple maintainance reasons. > In addition, I would like to have tested whether a user is granted access > by presenting a CAL that another user has received before, before I would > propose such a "directory move". Unfortunately, I cannot check this until > next week. > > Best regards, > > > Thomas ------------------------------------------------------------------------------ RSA(R) Conference 2012 Save $700 by Nov 18 Register now http://p.sf.net/sfu/rsa-sfdev2dev1