RDP Access on Fedora Linux: The Two Real Ways to Set It Up

  • Home
  • Blog
  • RDP Access on Fedora Linux: The Two Real Ways to Set It Up
DateJan 7, 2025

There are exactly two legitimate ways to get RDP working on Fedora, and which one you need depends entirely on whether you’re running GNOME on Wayland or something else. Most guides skip the part that actually breaks setups on real Fedora installs: a missing SELinux policy that fails silently instead of giving you a useful error.

Method 1: GNOME’s Native RDP (Wayland)

If you’re running GNOME on Wayland, you don’t need a third-party RDP server at all — GNOME has one built in via gnome-remote-desktop, and it’s GNOME-specific; it won’t work on KDE or other desktop environments [1]. As of GNOME 46, it supports headless, multi-user sessions — the desktop doesn’t need to already be running for someone to connect, and every user on the server can be accessed via RDP simultaneously [1]. Enable it with:

systemctl enable --user --now gnome-remote-desktop

You can configure everything remotely via grdctl over SSH, without needing physical access to the machine [1].

Method 2: xrdp (Xorg or Non-GNOME Desktops)

If you’re not on GNOME/Wayland, xrdp is the standard option. It’s open source, Apache 2.0-licensed software that provides “a graphical login to remote machines using Microsoft Remote Desktop Protocol” [2], compatible with a wide range of clients — FreeRDP, rdesktop, KRDC, Windows’ own client, and more [2]. For proper desktop integration on Xorg, it needs the xorgxrdp module; without it, it falls back to using Xvnc [2]. RDP transport is encrypted via TLS by default [2].

The SELinux Gotcha That Breaks Most Guides

This is the part that causes the most confused “it just doesn’t connect, no error” reports. Fedora 40 didn’t ship an SELinux policy for GNOME Remote Desktop at all — connections fail silently rather than with a clear error message. Fedora 41 and later do ship the policy [1], but if you’re on an affected version (including some Silverblue and Bluefin installs), you’ll see connection timeouts and transport errors even after trying audit2allow [1].

A Fedora Discussion thread has a confirmed working fix: a custom SELinux policy module allowing the specific socket operations GNOME Remote Desktop needs (permissions like allow system_dbusd_t unconfined_service_t:tcp_socket { read write } and related rules for xdm_t), compiled and installed via semodule [1] — multiple users on Silverblue confirmed it resolved the issue [1].

xrdp’s SELinux situation is different and generally less painful: on current Fedora, xrdp works out of the box under SELinux Enforcing without extra configuration in most cases, though if you do hit a denial, checking ausearch -m avc -ts recent and toggling setsebool -P xrdp_sshd_connect on covers the common case.

Which Method Do You Need?

FactorGNOME Native RDPxrdp
Works withGNOME on Wayland only [1]Xorg, most desktop environments [2]
Setupsystemctl enable --user --now gnome-remote-desktopInstall xrdp + xorgxrdp [2]
Multi-user supportYes, since GNOME 46, headless [1]Per-session, standard multi-user
Common SELinux issueMissing policy on Fedora 40, fixed in 41+ [1]Usually works out of the box on current Fedora

Which Setup Fits You?

What’s your desktop setup?

Pick the closest match.

Frequently Asked Questions

Why does RDP fail with no error message on my Fedora GNOME install?

Almost certainly the missing SELinux policy on Fedora 40 — it causes silent connection timeouts rather than a useful denial message [1]. Upgrading to Fedora 41+ or applying the confirmed custom policy module fixes it [1].

Can I use GNOME’s native RDP on KDE?

No — it’s a GNOME-specific feature and won’t work on KDE or other desktop environments [1]. Use xrdp instead.

Does xrdp need extra SELinux configuration on Fedora?

Usually not on current Fedora releases — it typically works under SELinux Enforcing out of the box. If you hit a denial, check ausearch -m avc -ts recent for specifics.

Is xrdp free and open source?

Yes — Apache 2.0-licensed, hosted on GitHub [2].

Conclusion

GNOME on Wayland gets native RDP for free via gnome-remote-desktop; anything else needs xrdp with the xorgxrdp module. The single most common blocker isn’t either tool itself — it’s Fedora 40’s missing SELinux policy for GNOME Remote Desktop, which fails silently instead of erroring clearly. If RDP just won’t connect and you’re not on Fedora 41+, that’s the first thing to check, not your firewall or network settings.

References

  1. Fedora Discussion — “Gnome Remote Desktop with SELinux enforced” — discussion.fedoraproject.org
  2. GitHub — neutrinolabs/xrdp (official repository) — github.com
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x