See this thread - they seem to have had a similar issue with different software.

Could it be a server-side configuration that is causing the problem - 
https://forum.devolutions.net/topics/44630/vnc-security-type-preference-to-pick-vnc-over-vencrypt

Vincent
________________________________
From: Devine, Harry (FAA) via user <[email protected]>
Sent: Thursday 21 May 2026 14:03
To: Nick Couchman <[email protected]>; user <[email protected]>
Cc: Devine, Harry (FAA) <[email protected]>
Subject: RE: Issue with VNC in 1.6.0


I sent your concern over to Red Hat.  What I am having trouble figuring out is 
how TigerVNC viewer seems to work one way (as I get prompted for the password, 
and the VNC server reads the password file, validates, and opens the VNC 
connectin), yet Guacamole does not work (the password is in the connection via 
the GUI, I don’t get prompted for a password which I would not expect a prompt 
anyway since the password should be getting sent in the connection request), 
but the VNC server says that it reads the password file but returns 
“Authentication failed”.



When I try with Guac, the VNC server log shows:



Thu May 21 08:46:28 2026

XserverDesktop: New client, sock 24

Connections: Accepted: 172.26.170.237::37758

SConnection: Reading protocol version

SConnection: Client needs protocol version 3.8

SConnection: Processing security type message

SConnection: Processing security type message

SConnection: Client requests security type VncAuth(2)

SConnection: Processing security message

SConnection: Processing security message

SVncAuth:    Reading password file

SConnection: Authentication error: Authentication failed

XserverDesktop: Client gone, sock 24

VNCSConnST:  Closing 172.26.170.237::37758: Authentication failed

EncodeManager: Framebuffer updates: 0

EncodeManager:   Total: 0 rects, 0 pixels

EncodeManager:          0 B (1:-nan ratio)

Connections: Closed: 172.26.170.237::37758

ComparingUpdateTracker: 0 pixels in / 0 pixels out

ComparingUpdateTracker: (1:-nan ratio)



When I try using TigerVNC viewer from a VM on our network, I specify the IP 
address and port 5902, I get prompted for the password, and the connection 
works:



Thu May 21 08:49:20 2026

SConnection: Processing security message

SVncAuth:    Reading password file

VNCServerST: Starting desktop

VNCSConnST:  Server default pixel format depth 24 (32bpp) little-endian rgb888

SConnection: Reading client initialisation

SConnection: Reading client initialisation

VNCServerST: Non-shared connection - closing clients

SMsgHandler: Got client clipboard capabilities:

SMsgHandler:     Plain text (only notify)

VNCSConnST:  Got request for framebuffer resize to 1024x704

VNCSConnST:  1 screen(s)

VNCSConnST:      1804289383 (0x6b8b4567): 1024x704+0+0 (flags 0x00000000)

VNCSConnST:

 RandR:       Resizing screen framebuffer to 1024x704

RandR:       Temporarily disabling output 'VNC-0'

ComparingUpdateTracker: 0 pixels in / 0 pixels out

ComparingUpdateTracker: (1:-nan ratio)

RandR:       Reconfiguring new output 'VNC-0' to 1024x704+0+0

VNCSConnST:  Got request for framebuffer resize to 1024x683

VNCSConnST:  1 screen(s)

VNCSConnST:      1804289383 (0x6b8b4567): 1024x683+0+0 (flags 0x00000000)

VNCSConnST:

 RandR:       Resizing screen framebuffer to 1024x683

RandR:       Temporarily disabling output 'VNC-0'

ComparingUpdateTracker: 0 pixels in / 0 pixels out

ComparingUpdateTracker: (1:-nan ratio)

RandR:       Reconfiguring new output 'VNC-0' to 1024x683+0+0



The password in the Guac connection GUI is the same one that I enter when I get 
prompted in the TigerVNC viewer.  I know that in the password file, it appears 
to be stored as some sort of encrypted string.  Is it possible that the 
TigerVNC viewer is encrypting what I enter for the password, so it “checks out” 
and works, and maybe the password in the Guac connection GUI is plain text?



Thanks,

Harry





[Image]

Harry Devine

Secure-OSE System Administrator

U.S. Department of Transportation

FAA/AJM-2432

(609) 485-4218 (Office)

(609) 612-7274 (FAA Cell)

[email protected]<mailto:[email protected]>



William J Hughes Technical Center

Building 300 3rd Floor Column L20

Atlantic City NJ 08405





From: Nick Couchman <[email protected]>
Sent: Wednesday, May 20, 2026 5:02 PM
To: Devine, Harry (FAA) <[email protected]>; user <[email protected]>
Subject: Re: Issue with VNC in 1.6.0



CAUTION: This email originated from outside of the Federal Aviation 
Administration (FAA). Do not click on links or open attachments unless you 
recognize the sender and know the content is safe.



On Wed, May 20, 2026 at 3:49 PM Devine, Harry (FAA) 
<[email protected]<mailto:[email protected]>> wrote:

More details:  I read that the password is stored in  what appears to be an 
encrypted state.  At no point do I get prompted for the user password, however, 
in the Guac connection settings, the username and password are configured.  So 
I’m not sure why it’s not passing that along.  I’m assuming that it is.



So I tried a test on the VNC server I have and removed the passwd file that had 
the encrypted password in it, and simply echoed the desired password into 
passwd as plain text.  Now I get the following in the VNC server log:



Wed May 20 15:34:50 2026

XserverDesktop: New client, sock 24

Connections: Accepted: 172.26.170.237::36046

SConnection: Reading protocol version

SConnection: Client needs protocol version 3.8

SConnection: Processing security type message

SConnection: Processing security type message

SConnection: Client requests security type VncAuth(2)

SConnection: Processing security message

SConnection: Processing security message

SVncAuth:    Reading password file

XserverDesktop: Client gone, sock 24

VNCSConnST:  Closing 172.26.170.237::36046: No password configured

EncodeManager: Framebuffer updates: 0

EncodeManager:   Total: 0 rects, 0 pixels

EncodeManager:          0 B (1:-nan ratio)

Connections: Closed: 172.26.170.237::36046

ComparingUpdateTracker: 0 pixels in / 0 pixels out

ComparingUpdateTracker: (1:-nan ratio)



So what it looks like to me is that both Guacamole and TigerVNC Viewer can 
access the password file, but Guacamole doesn’t seem to know how to decrypt the 
value in it.  Whereas, the TigerVNC Viewer DOES know how to decrypt it.  And 
the Viewer also prompts for the password.



Does this make sense?  How can I actually prove this theory?  I have no way of 
knowing what Guacamole is actually sending so it’s very hard to troubleshoot.





Well, the thing that puzzles me about this, is that I don't know how Guacamole 
would know how or where to read a VNC passwd file in order to authenticate to 
the VNC server. Unless you've modified the guacamole-server (guacd) code, guacd 
only ever authenticates with the information that is provided in the connection 
parameters, which is what you see in the Guacamole UI when you manage the 
connection. And if you've cleared out the username and password in the 
connection parameters, and you're connecting to the VNC server that requires a 
username and/or password, you should be getting a prompt for one or both of 
those (I think VncAuth is password-only, no username).



-Nick

IT Solutions Email Disclaimer - The information contained in this email 
message, including any files transmitted with it, is confidential and may be 
legally privileged.

This e-mail is intended only for the personal attention of the stated 
addressee(s). Any access to this email, including any files transmitted with 
it, by any other person is unauthorised. If you are not an addressee, you must 
not disclose, copy, circulate or in any other way use or rely on the accuracy 
or completeness of the information contained in this email or any files 
transmitted with it.

If you have received this email in error, please inform the sender immediately 
and delete it and all copies from your system. You may not forward this email 
without the permission of the authorised sender.

The views expressed in this email are those of the author, and do not 
necessarily represent the views of IT Solutions or its affiliates. Internet 
communications are not secure and IT Solutions cannot therefore accept legal 
responsibility for the contents of this message nor for any damage caused by 
viruses. This email has been scanned at the originating end. For further 
information on IT Solutions visit https://www.itsolutions.ie

Reply via email to