ThinLinc: Remote Access to Linux Desktops
ThinLinc: Remote Access to Linux Desktops
In enterprise environments, remote access to Linux desktops often comes down to VNC with flaky encryption or RDP proxies held together with workarounds. ThinLinc by Cendio is a full-featured remote desktop solution that runs on top of VNC, supports RDP clients, and provides a web-based administration interface without the usual hassle with certificates and firewalls.
What Is ThinLinc
ThinLinc is a remote desktop access solution with a server-plus-clients architecture. The server runs VNC sessions on the backend, and clients connect through a web browser or native ThinLinc clients. The protocol between client and server is tunneled over SSH, which solves the encryption problem out of the box.
Key features:
- Built-in web server for browser-based desktop access
- Native clients for Linux, Windows, and macOS
- Load balancing across multiple servers
- Single sign-on (SSO) via Kerberos and LDAP
- Session management through web panel and CLI
Installing the Server
ThinLinc ships as packages for RHEL/CentOS 7/8/9 and Ubuntu/Debian. For installation on a RHEL system:
For Ubuntu/Debian:
After installation, the web panel is available at https://<host>:1443.
Port 1443 is the standard ThinLinc web interface port. If a firewall is in place, open it along with port 22 for SSH tunneling.
Server Configuration
The main configuration lives in /etc/thinlinc/. Key files:
| File | Purpose |
|---|---|
tlconfig | Global server settings |
vncserver-config-defaults | VNC session parameters |
client-to-server.d/ | Port and device forwarding rules |
ssl/ | Certificates and keys |
Basic configuration via tlconfig:
For VNC parameter tuning:
After changing configuration via tlconfig, restart the services: sudo systemctl restart tlwebd vncserver@:*.
Client Connections
ThinLinc provides several connection methods:
- Web browser — navigate to
https://<host>:1443, enter credentials. Works on any device with a modern browser. - Native client — download from the same URL. Clients are available for Linux, Windows, and macOS.
- RDP client — ThinLinc supports RDP proxying, allowing connections via standard
rdesktoporfreerdp.
Connecting via native client:
Manual SSH tunnel connection:
Administration and Session Management
All active sessions can be viewed through the web panel (https://<host>:1443/admin) or via CLI:
For bulk operations:
The admin web panel allows:
- Viewing session lists and their status
- Sending messages to users
- Forcefully terminating sessions
- Viewing logs and usage metrics
Security and Integration
ThinLinc uses SSH for encrypting traffic between client and server. Web server certificates can be replaced with your own:
LDAP/Kerberos integration:
For PAM integration:
ThinLinc supports USB device and audio forwarding over the SSH tunnel. Configure it in client-to-server.d/ rules for specific devices.
ThinLinc is a ready-made solution that eliminates the manual assembly of VNC infrastructure with firewalls and certificates. For environments that need remote access to Linux desktops without security compromises, it is one of the most straightforward paths available.