Skip to content

ThinLinc: Remote Access to Linux Desktops

ThinLinc: Remote Access to Linux Desktops

In enterprise environments, remote access to Linux desktops often comes down to VNC with flaky encryption or RDP proxies held together with workarounds. ThinLinc by Cendio is a full-featured remote desktop solution that runs on top of VNC, supports RDP clients, and provides a web-based administration interface without the usual hassle with certificates and firewalls.

What Is ThinLinc

ThinLinc is a remote desktop access solution with a server-plus-clients architecture. The server runs VNC sessions on the backend, and clients connect through a web browser or native ThinLinc clients. The protocol between client and server is tunneled over SSH, which solves the encryption problem out of the box.

Key features:

  • Built-in web server for browser-based desktop access
  • Native clients for Linux, Windows, and macOS
  • Load balancing across multiple servers
  • Single sign-on (SSO) via Kerberos and LDAP
  • Session management through web panel and CLI

Installing the Server

ThinLinc ships as packages for RHEL/CentOS 7/8/9 and Ubuntu/Debian. For installation on a RHEL system:

# Add the Cendio repository
sudo yum install -y https://www.cendio.com/downloads/thinlinc/rpm/cendio-release-latest.noarch.rpm

# Install the server
sudo yum install -y thinlinc-server

# Start services
sudo systemctl start tlwebd
sudo systemctl start vncserver@:1

For Ubuntu/Debian:

sudo dpkg -i thinlinc-server-*.deb
sudo systemctl start tlwebd
sudo systemctl start vncserver@:1

After installation, the web panel is available at https://<host>:1443.

Note

Port 1443 is the standard ThinLinc web interface port. If a firewall is in place, open it along with port 22 for SSH tunneling.

Server Configuration

The main configuration lives in /etc/thinlinc/. Key files:

FilePurpose
tlconfigGlobal server settings
vncserver-config-defaultsVNC session parameters
client-to-server.d/Port and device forwarding rules
ssl/Certificates and keys

Basic configuration via tlconfig:

# Set default screen size
sudo tlconfig --set vncserver.default_screen_width 1920
sudo tlconfig --set vncserver.default_screen_height 1080

# Set color depth
sudo tlconfig --set vncserver.default_color_depth 24

# Set home directory for sessions
sudo tlconfig --set vncserver.home_dir /var/lib/thinlinc

For VNC parameter tuning:

# Edit the VNC configuration
sudo tlconfig --edit vncserver-config-defaults
Warning

After changing configuration via tlconfig, restart the services: sudo systemctl restart tlwebd vncserver@:*.

Client Connections

ThinLinc provides several connection methods:

  1. Web browser — navigate to https://<host>:1443, enter credentials. Works on any device with a modern browser.
  2. Native client — download from the same URL. Clients are available for Linux, Windows, and macOS.
  3. RDP client — ThinLinc supports RDP proxying, allowing connections via standard rdesktop or freerdp.

Connecting via native client:

# Linux
thinlinc-client

# Windows (PowerShell)
Start-Process "C:\Program Files\ThinLinc\Client\tlclient.exe"

Manual SSH tunnel connection:

ssh -L 5901:localhost:5901 user@thinlinc-host
vncviewer localhost:5901

Administration and Session Management

All active sessions can be viewed through the web panel (https://<host>:1443/admin) or via CLI:

# List all sessions
sudo /opt/thinlinc/bin/vncserver -list

# Terminate a specific session
sudo /opt/thinlinc/bin/vncserver -kill :<display_number>

# Restart a specific session
sudo /opt/thinlinc/bin/vncserver -restart :<display_number>

For bulk operations:

# Terminate all sessions for a user
sudo /opt/thinlinc/bin/vncserver -kill -u username

# Limit sessions per user
sudo tlconfig --set vncserver.max_sessions_per_user 3

The admin web panel allows:

  • Viewing session lists and their status
  • Sending messages to users
  • Forcefully terminating sessions
  • Viewing logs and usage metrics

Security and Integration

ThinLinc uses SSH for encrypting traffic between client and server. Web server certificates can be replaced with your own:

# Replace the self-signed certificate
sudo cp server.crt /etc/thinlinc/ssl/
sudo cp server.key /etc/thinlinc/ssl/
sudo systemctl restart tlwebd

LDAP/Kerberos integration:

# Enable LDAP authentication
sudo tlconfig --set authentication.ldap.enabled true
sudo tlconfig --set authentication.ldap.server ldap://ldap.example.com
sudo tlconfig --set authentication.ldap.base_dn "dc=example,dc=com"

# Enable Kerberos
sudo tlconfig --set authentication.krb5.enabled true
sudo tlconfig --set authentication.krb5.realm EXAMPLE.COM

For PAM integration:

# Use system PAM authentication
sudo tlconfig --set authentication.pam.enabled true
Tip

ThinLinc supports USB device and audio forwarding over the SSH tunnel. Configure it in client-to-server.d/ rules for specific devices.

ThinLinc is a ready-made solution that eliminates the manual assembly of VNC infrastructure with firewalls and certificates. For environments that need remote access to Linux desktops without security compromises, it is one of the most straightforward paths available.