git: d4a1d44ce1f0 - main - net/xrdp: Generate default keys/certs at first startup instead of post-install

From: Koichiro Iwao <meta_at_FreeBSD.org>
Date: Fri, 18 Sep 2026 08:29:19 UTC
The branch main has been updated by meta:

URL: https://cgit.FreeBSD.org/ports/commit/?id=d4a1d44ce1f0d07d08090961906e63a1fe442a62

commit d4a1d44ce1f0d07d08090961906e63a1fe442a62
Author:     Koichiro Iwao <meta@FreeBSD.org>
AuthorDate: 2026-09-18 06:57:36 +0000
Commit:     Koichiro Iwao <meta@FreeBSD.org>
CommitDate: 2026-09-18 08:28:19 +0000

    net/xrdp: Generate default keys/certs at first startup instead of post-install
    
    Generating keys/certs during post-install leads to duplicate keys when
    provisioning multiple hosts from a single VM image.
    
    The default snakeoil certificate has been switched to a 5-year Ed25519
    certificate.
    
    Reported by:    cperciva (via email)
    Obtained from:  https://github.com/neutrinolabs/xrdp/pull/3874
    Sponsored by:   Cybertrust Japan
---
 net/xrdp/Makefile               |  6 ++++--
 net/xrdp/distinfo               |  4 +++-
 net/xrdp/files/pkg-deinstall.in | 34 -------------------------------
 net/xrdp/files/pkg-install.in   | 44 -----------------------------------------
 4 files changed, 7 insertions(+), 81 deletions(-)

diff --git a/net/xrdp/Makefile b/net/xrdp/Makefile
index 5ecea36e48cc..cc6533192942 100644
--- a/net/xrdp/Makefile
+++ b/net/xrdp/Makefile
@@ -1,12 +1,14 @@
 PORTNAME=	xrdp
 DISTVERSION=	0.10.6.1
-PORTREVISION=	2
+PORTREVISION=	3
 PORTEPOCH=	1
 CATEGORIES=	net
 MASTER_SITES=	https://github.com/neutrinolabs/${PORTNAME}/releases/download/v${DISTVERSION}/
 DIST_SUBDIR?=	${PORTNAME}
 
 PATCH_SITES=	https://github.com/neutrinolabs/${PORTNAME}/commit/
+PATCHFILES=	70cc370.patch
+PATCH_DIST_STRIP= -p1
 
 MAINTAINER=	meta@FreeBSD.org
 COMMENT=	Open source Remote Desktop Protocol (RDP) server
@@ -42,7 +44,7 @@ INSTALL_TARGET=	install-strip
 
 LDFLAGS+=	-lssl
 CONFLICTS=	xrdp-devel
-SUB_FILES=	pkg-deinstall pkg-install pkg-message
+SUB_FILES=	pkg-message
 SUB_LIST=	OPENSSLBASE=${OPENSSLBASE}
 
 OPTIONS_DEFINE=			DEBUG FUSE IPV6
diff --git a/net/xrdp/distinfo b/net/xrdp/distinfo
index 8ae644bf308a..179bb864f130 100644
--- a/net/xrdp/distinfo
+++ b/net/xrdp/distinfo
@@ -1,3 +1,5 @@
-TIMESTAMP = 1783408198
+TIMESTAMP = 1789713753
 SHA256 (xrdp/xrdp-0.10.6.1.tar.gz) = 2f7beb5a3b2529c8d72dc0df9b8cdca31ab0e0c14d1e3421210f5e6ec0ab3b75
 SIZE (xrdp/xrdp-0.10.6.1.tar.gz) = 2494511
+SHA256 (xrdp/70cc370.patch) = 19ac99fff5fbf298795b4b5f8f6d0169509e92ab3bcd0c25095768d865cf9b4c
+SIZE (xrdp/70cc370.patch) = 2946
diff --git a/net/xrdp/files/pkg-deinstall.in b/net/xrdp/files/pkg-deinstall.in
deleted file mode 100644
index 3ebbe5952d43..000000000000
--- a/net/xrdp/files/pkg-deinstall.in
+++ /dev/null
@@ -1,34 +0,0 @@
-#!/bin/sh
-# vim:ts=4:sw=4:et
-
-if [ $# -ne 2 ]; then
-    echo "usage: $0 distname { DEINSTALL | POST-DEINSTALL }" >&2
-    exit 1
-fi
-
-case $2 in
-    DEINSTALL)
-        : nothing to do here
-        ;;
-    POST-DEINSTALL)
-        RSAKEYS=%%ETCDIR%%/rsakeys.ini
-        PRIVATEKEY=%%ETCDIR%%/key.pem
-        CERTIFICATE=%%ETCDIR%%/cert.pem
-
-        # if keys are generated during post-install script, remove it
-        # but do not remove user's keys
-        for f in $RSAKEYS $PRIVATEKEY $CERTIFICATE;
-        do
-            if cmp -s "${f}.sample" "${f}"; then
-                rm -f "${f}"
-            fi
-                rm -f "${f}.sample"
-        done
-        ;;
-    *)
-        echo "usage: $0 distname { DEINSTALL | POST-DEINSTALL }" >&2
-        exit 1
-        ;;
-esac
-
-exit 0
diff --git a/net/xrdp/files/pkg-install.in b/net/xrdp/files/pkg-install.in
deleted file mode 100644
index 728714ad985e..000000000000
--- a/net/xrdp/files/pkg-install.in
+++ /dev/null
@@ -1,44 +0,0 @@
-#!/bin/sh
-# vim:ts=4:sw=4:et
-
-if [ $# -ne 2 ]; then
-    echo "usage: $0 distname { PRE-INSTALL | POST-INSTALL }" >&2
-    exit 1
-fi
-
-case $2 in
-    PRE-INSTALL)
-        : nothing to do here
-        ;;
-    POST-INSTALL)
-        RSAKEYS=%%ETCDIR%%/rsakeys.ini
-        PRIVATEKEY=%%ETCDIR%%/key.pem
-        CERTIFICATE=%%ETCDIR%%/cert.pem
-        # make sure rsakeys and certificates are private
-        umask 077
-        # generate rsakeys.ini
-        [ -e "$RSAKEYS" ] || %%PREFIX%%/bin/xrdp-keygen xrdp "$RSAKEYS".sample && \
-        # generate self-signed certificate
-        [ -e "$PRIVATEKEY" -a -e "$CERTIFICATE" ] || \
-            %%OPENSSLBASE%%/bin/openssl req \
-                 -x509 \
-                 -newkey rsa:4096 \
-                 -keyout "$PRIVATEKEY".sample \
-                 -sha256 \
-                 -nodes \
-                 -out "$CERTIFICATE".sample \
-                 -days 365 \
-                 -subj "/CN=$(hostname)"
-
-        for f in "$RSAKEYS" "$PRIVATEKEY" "$CERTIFICATE"
-        do
-            [ -e "${f}" ] || cp -n "${f}.sample" "${f}"
-        done
-        ;;
-    *)
-        echo "usage: $0 distname { PRE-INSTALL | POST-INSTALL }" >&2
-        exit 1
-        ;;
-esac
-
-exit 0