Harry,
Can you share the command or systemd file you're using to launch the Xvnc
process?

-Nick

On Thu, May 21, 2026 at 9:46 AM Devine, Harry (FAA) via user <
[email protected]> wrote:

> So I just read that thread, and it appears that the user with the issue
> solved it by setting securitytypes to vncauth.  My
> /etc/tigervnc/vncserver-config-defaults already has this configured:
>
>
>
> session=gnome
>
> securitytypes=vncauth
>
> Log=*:stderr:100
>
>
>
> And I still get the issue.  I have 3 separate Guac servers that are having
> the same issue.  All 3 Guac servers are RHEL 9.7, and the VNC server that
> we’re trying to connect to are running TigerVNC 1.15 on RHEL 9.7 as well
> (I’m trying to connect to the same VNC server that’s RHEL 9.7 from 2 of
> those Guac servers).  The 3rd Guac server that’s on RHEL 9.7 is trying to
> connect to a VNC server that’s running RHEL 8.10, and the TigerVNC version
> is also 1.15.0.
>
>
>
> Thanks,
>
> Harry
>
>
>
>
>
> [image: Image]
>
> Harry Devine
>
> Secure-OSE System Administrator
>
> U.S. Department of Transportation
>
> FAA/AJM-2432
>
> (609) 485-4218 (Office)
>
> (609) 612-7274 (FAA Cell)
>
> *[email protected] <[email protected]>*
>
>
>
> *William J Hughes Technical Center*
>
> *Building 300 3rd Floor Column L20*
>
> *Atlantic City NJ 08405*
>
>
>
>
>
> *From:* Vincent Sherwood <[email protected]>
> *Sent:* Thursday, May 21, 2026 9:32 AM
> *To:* Nick Couchman <[email protected]>; user <[email protected]>
> *Cc:* Devine, Harry (FAA) <[email protected]>
> *Subject:* Re: Issue with VNC in 1.6.0
>
>
>
> You don't often get email from [email protected]. Learn why this is
> important <https://aka.ms/LearnAboutSenderIdentification>
>
> *CAUTION:* This email originated from outside of the Federal Aviation
> Administration (FAA). Do not click on links or open attachments unless you
> recognize the sender and know the content is safe.
>
>
>
> See this thread - they seem to have had a similar issue with different
> software.
>
>
>
> Could it be a server-side configuration that is causing the problem -
> https://forum.devolutions.net/topics/44630/vnc-security-type-preference-to-pick-vnc-over-vencrypt
>
>
>
> Vincent
> ------------------------------
>
> *From:* Devine, Harry (FAA) via user <[email protected]>
> *Sent:* Thursday 21 May 2026 14:03
> *To:* Nick Couchman <[email protected]>; user <[email protected]>
> *Cc:* Devine, Harry (FAA) <[email protected]>
> *Subject:* RE: Issue with VNC in 1.6.0
>
>
>
> I sent your concern over to Red Hat.  What I am having trouble figuring
> out is how TigerVNC viewer seems to work one way (as I get prompted for the
> password, and the VNC server reads the password file, validates, and opens
> the VNC connectin), yet Guacamole does not work (the password is in the
> connection via the GUI, I don’t get prompted for a password which I would
> not expect a prompt anyway since the password should be getting sent in the
> connection request), but the VNC server says that it reads the password
> file but returns “Authentication failed”.
>
>
>
> When I try with Guac, the VNC server log shows:
>
>
>
> Thu May 21 08:46:28 2026
>
> XserverDesktop: New client, sock 24
>
> Connections: Accepted: 172.26.170.237::37758
>
> SConnection: Reading protocol version
>
> SConnection: Client needs protocol version 3.8
>
> SConnection: Processing security type message
>
> SConnection: Processing security type message
>
> SConnection: Client requests security type VncAuth(2)
>
> SConnection: Processing security message
>
> SConnection: Processing security message
>
> SVncAuth:    Reading password file
>
> SConnection: Authentication error: Authentication failed
>
> XserverDesktop: Client gone, sock 24
>
> VNCSConnST:  Closing 172.26.170.237::37758: Authentication failed
>
> EncodeManager: Framebuffer updates: 0
>
> EncodeManager:   Total: 0 rects, 0 pixels
>
> EncodeManager:          0 B (1:-nan ratio)
>
> Connections: Closed: 172.26.170.237::37758
>
> ComparingUpdateTracker: 0 pixels in / 0 pixels out
>
> ComparingUpdateTracker: (1:-nan ratio)
>
>
>
> When I try using TigerVNC viewer from a VM on our network, I specify the
> IP address and port 5902, I get prompted for the password, and the
> connection works:
>
>
>
> Thu May 21 08:49:20 2026
>
> SConnection: Processing security message
>
> SVncAuth:    Reading password file
>
> VNCServerST: Starting desktop
>
> VNCSConnST:  Server default pixel format depth 24 (32bpp) little-endian
> rgb888
>
> SConnection: Reading client initialisation
>
> SConnection: Reading client initialisation
>
> VNCServerST: Non-shared connection - closing clients
>
> SMsgHandler: Got client clipboard capabilities:
>
> SMsgHandler:     Plain text (only notify)
>
> VNCSConnST:  Got request for framebuffer resize to 1024x704
>
> VNCSConnST:  1 screen(s)
>
> VNCSConnST:      1804289383 (0x6b8b4567): 1024x704+0+0 (flags 0x00000000)
>
> VNCSConnST:
>
>  RandR:       Resizing screen framebuffer to 1024x704
>
> RandR:       Temporarily disabling output 'VNC-0'
>
> ComparingUpdateTracker: 0 pixels in / 0 pixels out
>
> ComparingUpdateTracker: (1:-nan ratio)
>
> RandR:       Reconfiguring new output 'VNC-0' to 1024x704+0+0
>
> VNCSConnST:  Got request for framebuffer resize to 1024x683
>
> VNCSConnST:  1 screen(s)
>
> VNCSConnST:      1804289383 (0x6b8b4567): 1024x683+0+0 (flags 0x00000000)
>
> VNCSConnST:
>
>  RandR:       Resizing screen framebuffer to 1024x683
>
> RandR:       Temporarily disabling output 'VNC-0'
>
> ComparingUpdateTracker: 0 pixels in / 0 pixels out
>
> ComparingUpdateTracker: (1:-nan ratio)
>
> RandR:       Reconfiguring new output 'VNC-0' to 1024x683+0+0
>
>
>
> The password in the Guac connection GUI is the same one that I enter when
> I get prompted in the TigerVNC viewer.  I know that in the password file,
> it appears to be stored as some sort of encrypted string.  Is it possible
> that the TigerVNC viewer is encrypting what I enter for the password, so it
> “checks out” and works, and maybe the password in the Guac connection GUI
> is plain text?
>
>
>
> Thanks,
>
> Harry
>
>
>
>
>
> [image: Image]
>
> Harry Devine
>
> Secure-OSE System Administrator
>
> U.S. Department of Transportation
>
> FAA/AJM-2432
>
> (609) 485-4218 (Office)
>
> (609) 612-7274 (FAA Cell)
>
> *[email protected] <[email protected]>*
>
>
>
> *William J Hughes Technical Center*
>
> *Building 300 3rd Floor Column L20*
>
> *Atlantic City NJ 08405*
>
>
>
>
>
> *From:* Nick Couchman <[email protected]>
> *Sent:* Wednesday, May 20, 2026 5:02 PM
> *To:* Devine, Harry (FAA) <[email protected]>; user <
> [email protected]>
> *Subject:* Re: Issue with VNC in 1.6.0
>
>
>
> *CAUTION:* This email originated from outside of the Federal Aviation
> Administration (FAA). Do not click on links or open attachments unless you
> recognize the sender and know the content is safe.
>
>
>
> On Wed, May 20, 2026 at 3:49 PM Devine, Harry (FAA) <[email protected]>
> wrote:
>
> More details:  I read that the password is stored in  what appears to be
> an encrypted state.  At no point do I get prompted for the user password,
> however, in the Guac connection settings, the username and password are
> configured.  So I’m not sure why it’s not passing that along.  I’m assuming
> that it is.
>
>
>
> So I tried a test on the VNC server I have and removed the passwd file
> that had the encrypted password in it, and simply echoed the desired
> password into passwd as plain text.  Now I get the following in the VNC
> server log:
>
>
>
> Wed May 20 15:34:50 2026
>
> XserverDesktop: New client, sock 24
>
> Connections: Accepted: 172.26.170.237::36046
>
> SConnection: Reading protocol version
>
> SConnection: Client needs protocol version 3.8
>
> SConnection: Processing security type message
>
> SConnection: Processing security type message
>
> SConnection: Client requests security type VncAuth(2)
>
> SConnection: Processing security message
>
> SConnection: Processing security message
>
> SVncAuth:    Reading password file
>
> XserverDesktop: Client gone, sock 24
>
> *VNCSConnST:  Closing 172.26.170.237::36046: No password configured*
>
> EncodeManager: Framebuffer updates: 0
>
> EncodeManager:   Total: 0 rects, 0 pixels
>
> EncodeManager:          0 B (1:-nan ratio)
>
> Connections: Closed: 172.26.170.237::36046
>
> ComparingUpdateTracker: 0 pixels in / 0 pixels out
>
> ComparingUpdateTracker: (1:-nan ratio)
>
>
>
> So what it looks like to me is that both Guacamole and TigerVNC Viewer can
> access the password file, but Guacamole doesn’t seem to know how to decrypt
> the value in it.  Whereas, the TigerVNC Viewer DOES know how to decrypt
> it.  And the Viewer also prompts for the password.
>
>
>
> Does this make sense?  How can I actually prove this theory?  I have no
> way of knowing what Guacamole is actually sending so it’s very hard to
> troubleshoot.
>
>
>
>
>
> Well, the thing that puzzles me about this, is that I don't know how
> Guacamole would know how or where to read a VNC passwd file in order to
> authenticate to the VNC server. Unless you've modified the guacamole-server
> (guacd) code, guacd only ever authenticates with the information that is
> provided in the connection parameters, which is what you see in the
> Guacamole UI when you manage the connection. And if you've cleared out the
> username and password in the connection parameters, and you're connecting
> to the VNC server that requires a username and/or password, you should be
> getting a prompt for one or both of those (I think VncAuth is
> password-only, no username).
>
>
>
> -Nick
>
>
> IT Solutions Email Disclaimer - The information contained in this email
> message, including any files transmitted with it, is confidential and may
> be legally privileged.
>
> This e-mail is intended only for the personal attention of the stated
> addressee(s). Any access to this email, including any files transmitted
> with it, by any other person is unauthorised. If you are not an addressee,
> you must not disclose, copy, circulate or in any other way use or rely on
> the accuracy or completeness of the information contained in this email or
> any files transmitted with it.
>
> If you have received this email in error, please inform the sender
> immediately and delete it and all copies from your system. You may not
> forward this email without the permission of the authorised sender.
>
> The views expressed in this email are those of the author, and do not
> necessarily represent the views of IT Solutions or its affiliates. Internet
> communications are not secure and IT Solutions cannot therefore accept
> legal responsibility for the contents of this message nor for any damage
> caused by viruses. This email has been scanned at the originating end. For
> further information on IT Solutions visit https://www.itsolutions.ie
>

Reply via email to