Centos配置VNC远程

2024-07-17 10:58:15 浏览数 (3)

摘要

本文主要讲述了Centos如何通安装tigervnc-server,去实现VNC远程连接到Centos。

配置过程

tigervnc-server

先用yum安装tigervnc-server

代码语言:javascript复制
yum install tigervnc-server

安装完成后,其默认的配置文件在/lib/systemd/system/vncserver@.service,内容如下

代码语言:shell复制
# The vncserver service unit file
#
# Quick HowTo:
# 1. Copy this file to /etc/systemd/system/vncserver@.service
# 2. Replace <USER> with the actual user name and edit vncserver
#    parameters in the wrapper script located in /usr/bin/vncserver_wrapper
# 3. Run `systemctl daemon-reload`
# 4. Run `systemctl enable vncserver@:<display>.service`
#
# DO NOT RUN THIS SERVICE if your local area network is
# untrusted!  For a secure way of using VNC, you should
# limit connections to the local host and then tunnel from
# the machine you want to view VNC on (host A) to the machine
# whose VNC output you want to view (host B)
#
# [user@hostA ~]$ ssh -v -C -L 590N:localhost:590M hostB
#
# this will open a connection on port 590N of your hostA to hostB's port 590M
# (in fact, it ssh-connects to hostB and then connects to localhost (on hostB).
# See the ssh man page for details on port forwarding)
#
# You can then point a VNC client on hostA at vncdisplay N of localhost and with
# the help of ssh, you end up seeing what hostB makes available on port 590M
#
# Use "-nolisten tcp" to prevent X connections to your VNC server via TCP.
#
# Use "-localhost" to prevent remote VNC clients connecting except when
# doing so through a secure tunnel.  See the "-via" option in the
# `man vncviewer' manual page.


[Unit]
Description=Remote desktop service (VNC)
After=syslog.target network.target

[Service]
Type=simple

# Clean any existing files in /tmp/.X11-unix environment
ExecStartPre=/bin/sh -c '/usr/bin/vncserver -kill %i > /dev/null 2>&1 || :'
ExecStart=/usr/bin/vncserver_wrapper <USER> %i
ExecStop=/bin/sh -c '/usr/bin/vncserver -kill %i > /dev/null 2>&1 || :'

[Install]
WantedBy=multi-user.target

/usr/bin/vncserver_wrapper是一个用于启动和停止VNC服务器的脚本,它可以接收以下参数:

代码语言:javascript复制
•  <USER>:指定运行VNC服务器的用户,需要替换为实际的用户名。
•  %i:指定VNC服务器的显示编号,需要在服务名中用@符号后面的数字或字符串表示,比如vncserver@:1.service。
•  -geometry:指定VNC会话的分辨率,比如-geometry 1280x1024。
•  -kill:停止VNC服务器,需要指定显示编号,比如-kill :1。

配置文件

将默认提供的文件复制到/etc/systemd/system,命令如下:

代码语言:javascript复制
sudo cp /lib/systemd/system/vncserver@.service /etc/systemd/system/vncserver@:1.service

其中vncserver@:1.service中的:1,是所谓的服务实例名称,这个参数会作为上文配置的i传入,并且该VNC服务的端口号就是5900 i。

然后设置用于VNC登录的用户(这里用oracle作为示例)以及分辨率:

代码语言:shell复制
[Install]
WantedBy=multi-user.target

# oracle使用,要以root权限启动,但是以oracle执行
[Unit]
Description=Remote desktop service (VNC)
After=syslog.target network.target

[Service]
Type=forking

ExecStartPre=/bin/sh -c '/usr/bin/vncserver -kill %i > /dev/null 2>&1 || :'
ExecStart=/usr/sbin/runuser -l oracle -c "/usr/bin/vncserver %i -geometry 1280x720  -depth 24"
# 这里的 /tmp/.X1-lock中的X后面的数字对应i
ExecStartPost=/usr/bin/cp /tmp/.X1-lock /root/.vnc
PIDFile=/root/.vnc/.X1-lock
ExecStop=/bin/sh -c '/usr/bin/vncserver -kill %i > /dev/null 2>&1 || :'

[Install]
WantedBy=multi-user.target

要注意的是,这里Serivce中的PIDFile需要owner是root,但是我们通过runuser -l oracle启动的VNC创建的PIDFile的owner是oracle,直接填/home/oracle/.vnc/%H%i.pid会报错:PID file is not owned by root. Refusing.所以这采取曲线方案,将VNC运行的pid用root复制一份,并将PIDFile路径指向该复制就行。

完成编辑后重新加载systemctl:

代码语言:javascript复制
systemctl daemon-reload

正常运行的话是下面的提示

代码语言:shell复制
systemctl status vncserver@:1.service
● vncserver@:1.service - Remote desktop service (VNC)
   Loaded: loaded (/etc/systemd/system/vncserver@:1.service; enabled; vendor preset: disabled)
   Active: active (running) since 二 2024-07-16 11:12:14 CST; 23h ago
  Process: 1961 ExecStartPost=/usr/bin/cp /tmp/.X1-lock /root/.vnc (code=exited, status=0/SUCCESS)
  Process: 1380 ExecStart=/usr/sbin/runuser -l oracle -c /usr/bin/vncserver %i -geometry 1280x720  -depth 24 (code=exited, status=0/SUCCESS)
  Process: 1302 ExecStartPre=/bin/sh -c /usr/bin/vncserver -kill %i > /dev/null 2>&1 || : (code=exited, status=0/SUCCESS)
 Main PID: 1882 (Xvnc)
   CGroup: /system.slice/system-vncserver.slice/vncserver@:1.service
           ‣ 1882 /usr/bin/Xvnc :1 -auth /home/oracle/.Xauthority -depth 24 -desktop localhost:1 (oracle) -fp catalogue:/etc/X11/fontpath.d -geometry 1280x720 -pn -rfbauth /home/oracle/.vnc/passwd -r...

7月 16 11:12:07 localhost systemd[1]: Starting Remote desktop service (VNC)...
7月 16 11:12:14 localhost systemd[1]: Started Remote desktop service (VNC).

设置VNC访问密码

命令行切换到你要VNC登录的账号。执行vncpasswd,设置密码,也可以单独设置一个只能浏览的密码:

代码语言:javascript复制
vncpasswd
Password:
Verify:
Would you like to enter a view-only password (y/n)? n
A view-only password is not used

修改防火墙

将VNC的服务开通,当然你也可以选择直接放通端口:

代码语言:javascript复制
firewall-cmd --add-service=vnc-server --permanent
firewall-cmd --reload

设置开机自启

代码语言:javascript复制
systemctl enable vncserver@:1.service

1 人点赞