Public bug reported:

[Impact]

The freerdp3 connect autopkgtest fails on Stonking amd64 with freerdp3
3.31.1+dfsg-1 and xrdp 0.10.6.1-2ubuntu1, potentially blocking proposed
migration.

Local reproduction with the same versions shows that xrdp cannot read
its TLS key, falls back to classic RDP and reports a MAC checksum error.

https://autopkgtest.ubuntu.com/results/autopkgtest-
stonking/stonking/amd64/f/freerdp3/20260905_113830_4f929@/log.gz

[Test Plan]

Run the unpatched and patched tests in separate clean testbeds with
identical binary versions.

Before patch:

    autopkgtest -B ./freerdp3 --test-name=connect --shell --apt-
pocket=proposed=src:xrdp --no-apt-fallback -- qemu "$XRDP_TEST_IMAGE"

Expected: connect FAIL, with private-key permission and MAC errors in
the server log.

After patch:

    the same autopkgtest as above.

Expected: xrdp belongs to ssl-cert, a TLS connection is established and
connect passes.

[Where problems could occur]

The change affects test setup only.
If group addition or service restart fails, TLS may remain unavailable and the 
test may fail.
ssl-cert membership also grants access to other keys readable by the group, so 
testbeds must not contain production private keys.

[Other Info]

Patch:
https://salsa.debian.org/seyeongkim/freerdp3/-/commit/e526451232371ff47a7d01876817208a33b6c34b

Debian discussion:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138658#80

** Affects: freerdp3 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167457

Title:
  freerdp3 connect autopkgtest fails when xrdp cannot read its TLS key

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/freerdp3/+bug/2167457/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to