Hi Michael, Hi Arnaud, Thank you for your comments in this bug.
My toughts are the following: I wonder what's the purpose of the ssl-cert group if it feels wrong to add a system user to that group. If this is definitely a no-go, copying the snackoil key to /etc/xrdp/key.pem could help. Though, this seems a somewhat hack-ish approach. Otherwise, it seems pointless that xrdp's postinst script generates snackoil cert and key at all. A different approach would be to use debconf [1] to query the desired base configuration from the person installing xrdp in case there is no sane default configuration possible. Downside is the considerable amount of work implementing this would cause to the maintainer. All in all, xrdp should come with a working initial configuration. Best, Sven [1] https://packages.debian.org/unstable/debconf -- GPG Fingerprint 3DF5 E8AA 43FC 9FDF D086 F195 ADF5 0EDA F8AD D585
signature.asc
Description: This is a digitally signed message part

