Harry, Can you share the command or systemd file you're using to launch the Xvnc process?
-Nick On Thu, May 21, 2026 at 9:46 AM Devine, Harry (FAA) via user < [email protected]> wrote: > So I just read that thread, and it appears that the user with the issue > solved it by setting securitytypes to vncauth. My > /etc/tigervnc/vncserver-config-defaults already has this configured: > > > > session=gnome > > securitytypes=vncauth > > Log=*:stderr:100 > > > > And I still get the issue. I have 3 separate Guac servers that are having > the same issue. All 3 Guac servers are RHEL 9.7, and the VNC server that > we’re trying to connect to are running TigerVNC 1.15 on RHEL 9.7 as well > (I’m trying to connect to the same VNC server that’s RHEL 9.7 from 2 of > those Guac servers). The 3rd Guac server that’s on RHEL 9.7 is trying to > connect to a VNC server that’s running RHEL 8.10, and the TigerVNC version > is also 1.15.0. > > > > Thanks, > > Harry > > > > > > [image: Image] > > Harry Devine > > Secure-OSE System Administrator > > U.S. Department of Transportation > > FAA/AJM-2432 > > (609) 485-4218 (Office) > > (609) 612-7274 (FAA Cell) > > *[email protected] <[email protected]>* > > > > *William J Hughes Technical Center* > > *Building 300 3rd Floor Column L20* > > *Atlantic City NJ 08405* > > > > > > *From:* Vincent Sherwood <[email protected]> > *Sent:* Thursday, May 21, 2026 9:32 AM > *To:* Nick Couchman <[email protected]>; user <[email protected]> > *Cc:* Devine, Harry (FAA) <[email protected]> > *Subject:* Re: Issue with VNC in 1.6.0 > > > > You don't often get email from [email protected]. Learn why this is > important <https://aka.ms/LearnAboutSenderIdentification> > > *CAUTION:* This email originated from outside of the Federal Aviation > Administration (FAA). Do not click on links or open attachments unless you > recognize the sender and know the content is safe. > > > > See this thread - they seem to have had a similar issue with different > software. > > > > Could it be a server-side configuration that is causing the problem - > https://forum.devolutions.net/topics/44630/vnc-security-type-preference-to-pick-vnc-over-vencrypt > > > > Vincent > ------------------------------ > > *From:* Devine, Harry (FAA) via user <[email protected]> > *Sent:* Thursday 21 May 2026 14:03 > *To:* Nick Couchman <[email protected]>; user <[email protected]> > *Cc:* Devine, Harry (FAA) <[email protected]> > *Subject:* RE: Issue with VNC in 1.6.0 > > > > I sent your concern over to Red Hat. What I am having trouble figuring > out is how TigerVNC viewer seems to work one way (as I get prompted for the > password, and the VNC server reads the password file, validates, and opens > the VNC connectin), yet Guacamole does not work (the password is in the > connection via the GUI, I don’t get prompted for a password which I would > not expect a prompt anyway since the password should be getting sent in the > connection request), but the VNC server says that it reads the password > file but returns “Authentication failed”. > > > > When I try with Guac, the VNC server log shows: > > > > Thu May 21 08:46:28 2026 > > XserverDesktop: New client, sock 24 > > Connections: Accepted: 172.26.170.237::37758 > > SConnection: Reading protocol version > > SConnection: Client needs protocol version 3.8 > > SConnection: Processing security type message > > SConnection: Processing security type message > > SConnection: Client requests security type VncAuth(2) > > SConnection: Processing security message > > SConnection: Processing security message > > SVncAuth: Reading password file > > SConnection: Authentication error: Authentication failed > > XserverDesktop: Client gone, sock 24 > > VNCSConnST: Closing 172.26.170.237::37758: Authentication failed > > EncodeManager: Framebuffer updates: 0 > > EncodeManager: Total: 0 rects, 0 pixels > > EncodeManager: 0 B (1:-nan ratio) > > Connections: Closed: 172.26.170.237::37758 > > ComparingUpdateTracker: 0 pixels in / 0 pixels out > > ComparingUpdateTracker: (1:-nan ratio) > > > > When I try using TigerVNC viewer from a VM on our network, I specify the > IP address and port 5902, I get prompted for the password, and the > connection works: > > > > Thu May 21 08:49:20 2026 > > SConnection: Processing security message > > SVncAuth: Reading password file > > VNCServerST: Starting desktop > > VNCSConnST: Server default pixel format depth 24 (32bpp) little-endian > rgb888 > > SConnection: Reading client initialisation > > SConnection: Reading client initialisation > > VNCServerST: Non-shared connection - closing clients > > SMsgHandler: Got client clipboard capabilities: > > SMsgHandler: Plain text (only notify) > > VNCSConnST: Got request for framebuffer resize to 1024x704 > > VNCSConnST: 1 screen(s) > > VNCSConnST: 1804289383 (0x6b8b4567): 1024x704+0+0 (flags 0x00000000) > > VNCSConnST: > > RandR: Resizing screen framebuffer to 1024x704 > > RandR: Temporarily disabling output 'VNC-0' > > ComparingUpdateTracker: 0 pixels in / 0 pixels out > > ComparingUpdateTracker: (1:-nan ratio) > > RandR: Reconfiguring new output 'VNC-0' to 1024x704+0+0 > > VNCSConnST: Got request for framebuffer resize to 1024x683 > > VNCSConnST: 1 screen(s) > > VNCSConnST: 1804289383 (0x6b8b4567): 1024x683+0+0 (flags 0x00000000) > > VNCSConnST: > > RandR: Resizing screen framebuffer to 1024x683 > > RandR: Temporarily disabling output 'VNC-0' > > ComparingUpdateTracker: 0 pixels in / 0 pixels out > > ComparingUpdateTracker: (1:-nan ratio) > > RandR: Reconfiguring new output 'VNC-0' to 1024x683+0+0 > > > > The password in the Guac connection GUI is the same one that I enter when > I get prompted in the TigerVNC viewer. I know that in the password file, > it appears to be stored as some sort of encrypted string. Is it possible > that the TigerVNC viewer is encrypting what I enter for the password, so it > “checks out” and works, and maybe the password in the Guac connection GUI > is plain text? > > > > Thanks, > > Harry > > > > > > [image: Image] > > Harry Devine > > Secure-OSE System Administrator > > U.S. Department of Transportation > > FAA/AJM-2432 > > (609) 485-4218 (Office) > > (609) 612-7274 (FAA Cell) > > *[email protected] <[email protected]>* > > > > *William J Hughes Technical Center* > > *Building 300 3rd Floor Column L20* > > *Atlantic City NJ 08405* > > > > > > *From:* Nick Couchman <[email protected]> > *Sent:* Wednesday, May 20, 2026 5:02 PM > *To:* Devine, Harry (FAA) <[email protected]>; user < > [email protected]> > *Subject:* Re: Issue with VNC in 1.6.0 > > > > *CAUTION:* This email originated from outside of the Federal Aviation > Administration (FAA). Do not click on links or open attachments unless you > recognize the sender and know the content is safe. > > > > On Wed, May 20, 2026 at 3:49 PM Devine, Harry (FAA) <[email protected]> > wrote: > > More details: I read that the password is stored in what appears to be > an encrypted state. At no point do I get prompted for the user password, > however, in the Guac connection settings, the username and password are > configured. So I’m not sure why it’s not passing that along. I’m assuming > that it is. > > > > So I tried a test on the VNC server I have and removed the passwd file > that had the encrypted password in it, and simply echoed the desired > password into passwd as plain text. Now I get the following in the VNC > server log: > > > > Wed May 20 15:34:50 2026 > > XserverDesktop: New client, sock 24 > > Connections: Accepted: 172.26.170.237::36046 > > SConnection: Reading protocol version > > SConnection: Client needs protocol version 3.8 > > SConnection: Processing security type message > > SConnection: Processing security type message > > SConnection: Client requests security type VncAuth(2) > > SConnection: Processing security message > > SConnection: Processing security message > > SVncAuth: Reading password file > > XserverDesktop: Client gone, sock 24 > > *VNCSConnST: Closing 172.26.170.237::36046: No password configured* > > EncodeManager: Framebuffer updates: 0 > > EncodeManager: Total: 0 rects, 0 pixels > > EncodeManager: 0 B (1:-nan ratio) > > Connections: Closed: 172.26.170.237::36046 > > ComparingUpdateTracker: 0 pixels in / 0 pixels out > > ComparingUpdateTracker: (1:-nan ratio) > > > > So what it looks like to me is that both Guacamole and TigerVNC Viewer can > access the password file, but Guacamole doesn’t seem to know how to decrypt > the value in it. Whereas, the TigerVNC Viewer DOES know how to decrypt > it. And the Viewer also prompts for the password. > > > > Does this make sense? How can I actually prove this theory? I have no > way of knowing what Guacamole is actually sending so it’s very hard to > troubleshoot. > > > > > > Well, the thing that puzzles me about this, is that I don't know how > Guacamole would know how or where to read a VNC passwd file in order to > authenticate to the VNC server. Unless you've modified the guacamole-server > (guacd) code, guacd only ever authenticates with the information that is > provided in the connection parameters, which is what you see in the > Guacamole UI when you manage the connection. And if you've cleared out the > username and password in the connection parameters, and you're connecting > to the VNC server that requires a username and/or password, you should be > getting a prompt for one or both of those (I think VncAuth is > password-only, no username). > > > > -Nick > > > IT Solutions Email Disclaimer - The information contained in this email > message, including any files transmitted with it, is confidential and may > be legally privileged. > > This e-mail is intended only for the personal attention of the stated > addressee(s). Any access to this email, including any files transmitted > with it, by any other person is unauthorised. If you are not an addressee, > you must not disclose, copy, circulate or in any other way use or rely on > the accuracy or completeness of the information contained in this email or > any files transmitted with it. > > If you have received this email in error, please inform the sender > immediately and delete it and all copies from your system. You may not > forward this email without the permission of the authorised sender. > > The views expressed in this email are those of the author, and do not > necessarily represent the views of IT Solutions or its affiliates. Internet > communications are not secure and IT Solutions cannot therefore accept > legal responsibility for the contents of this message nor for any damage > caused by viruses. This email has been scanned at the originating end. For > further information on IT Solutions visit https://www.itsolutions.ie >
