Xpra密码文件的正确格式是什么?是否有合规生成工具?
It looks like you're hitting a common pitfall with Xpra's password authentication—your current onetwo|bucklemyshoe format isn't what Xpra expects, even when enabling insecure plain-text mode. Let's break down the correct format, where to find documentation, and how to generate a valid file easily:
Correct Password File Format
Xpra's password file uses a specific line format per user, not a simple username|password split. The valid formats are:
- Hashed (Recommended for production)
Supported algorithms includeusername:$hash_algorithm$hashed_passwordsha1,sha256,sha512, etc. For example:onetwo:$sha1$d033e22ae348aeb5660fc2140aec35850c4da997 - Plain-text (Only for testing, insecure)
If you must use plain text (even with the "Insecure plain-text passwords" option enabled), you need to prefix the password withplain::username:plain:bucklemyshoe
Where to Find Official Documentation
You don't need to jump to external websites—Xpra includes built-in documentation for its authentication system. Just run this command in your terminal to view the local docs:
xpra docs authentication
This will pull up the exact format requirements, along with other authentication methods supported by Xpra.
Tools to Generate Valid Password Files
The easiest way to create a compliant password file is using Xpra's own xpra password utility:
- Run the command, specifying your desired password file path:
xpra password --file /path/to/your/passfile - Follow the prompts to enter your username and password—this tool automatically handles hashing and writes the correct line format to the file.
If you need to generate entries programmatically (e.g., for automation), you can use a simple Python script. Here's an example for SHA-1 hashing:
import hashlib import getpass username = input("Username: ") password = getpass.getpass("Password: ") # Generate SHA-1 hash hashed_pass = hashlib.sha1(password.encode("utf-8")).hexdigest() entry = f"{username}:$sha1${hashed_pass}" # Write to file with open("/path/to/your/passfile", "w") as f: f.write(entry + "\n")
Quick Notes:
- Always use hashed entries in production—plain-text is extremely insecure.
- Set strict permissions on your password file (e.g.,
chmod 600 /path/to/passfile) to prevent unauthorized access.
内容的提问来源于stack exchange,提问作者vfclists

