


0 or empty to prevent users connecting as guests, even if GuestAccessEnable is TRUE.Specify a value consisting of one or particular combinations of the following characters: *For a value other than 0, GuestAccessEnable must also be set to TRUE. A simple port scanning attack could see your computer taken over by a malicious entity. Only specify None for direct connections to internal computers only, and never for direct connections to computers over the Internet, nor for cloud connections.For example, Certificate+SystemAuth means VNC Server requires the connecting VNC Viewer user to pass both Certificate Authentication and System Authentication. You can create your own multi-factor custom authentication scheme by using the + character to require VNC Server to check multiple authentication types.For example, SingleSignOn,SystemAuth means VNC Server will try to authenticate the connecting VNC Viewer using Single Sign On and if this fails, use System Authentication instead. You can configure VNC Server to prompt for a fallback authentication method if the primary authentication fails by using the, character.VncAuth is the only scheme that allows direct connections from non-RealVNC VNC Viewers.

User account credentials, and then responses to a third party RADIUS server. System authentication + RADIUS authentication User account credentials, provided transparently.Īn X.509 certificate, provided transparently. Note: when Single sign-on is selected using the Authentication dropdown in VNC Server's Options it sets a parameter value of SingleSignOn,SystemAuth to allow for fallback. User account email, and then responses to one or more PAM modules. *Do not edit this parameter if you have a Home subscription, or remote access will not be available. However, it may be useful in the context of some regulatory compliance regimes, to guarantee that session data will never be transmitted via third party servers.Īn equivalent VNC Viewer AllowCloudRelay parameter is available to prevent cloud connections from particular desktop computers. Setting this parameter to FALSE will cause an unquantifiable percentage of cloud connections to fail. Note that session data relayed via our cloud service is encrypted end-to-end, so cannot be deciphered by RealVNC, nor anyone else. However, intermediate network hardware may mean this is not possible, so the cloud service automatically falls back to relaying session data this ensures cloud connections succeed. Where possible, the cloud service then negotiates peer-to-peer sessions between endpoints, so session data is transmitted directly between them this is likely to be more performant. Specify FALSE to prevent cloud connections to the VNC Server computer if they would be relayed via RealVNC’s cloud service.Īll cloud connections are brokered by RealVNC’s cloud service.
