# wayvnc — installed to /etc/wayvnc/config by build-thin-client-iso.sh. # Format is plain key=value, one per line (not TOML, not INI sections). # # There is deliberately NO `password=` line in this file. wayvnc only accepts the # password inline, so committing one here would put a live credential for a full # remote-control channel into git. Instead /usr/local/bin/start-wayvnc reads # /etc/wayvnc/wayvnc-password (mode 0600, never committed) and writes a merged config # into $XDG_RUNTIME_DIR at session start. If that file still holds the build-time # sentinel, start-wayvnc refuses to launch — no unauthenticated VNC server, ever. # Bound to all interfaces on purpose: wayvnc is this project's remote-control channel # (the confirmed replacement for RDP), so it has to be reachable from the LAN, not # just loopback. That is exactly why the auth below is not optional. address=0.0.0.0 port=5900 enable_auth=true username=@KIOSK_USERNAME@ # wayvnc >= 0.7 uses this for RSA-AES auth. rsa_private_key_file=/etc/wayvnc/rsa_key.pem # wayvnc <= 0.6 authenticates over TLS instead and needs these two; harmless on newer # builds. Both are generated by 0300-wayvnc.hook.chroot, self-signed. private_key_file=/etc/wayvnc/tls_key.pem certificate_file=/etc/wayvnc/tls_cert.pem