In cloud server management, CentOS is typically delivered with a minimal installation that provides only a command-line interface. For users requiring a graphical interface—whether to run visual development tools, manage database clients, or configure services that depend on a GUI—setting up a stable remote desktop environment is an essential requirement. This article outlines the complete process, from initial environment preparation to achieving stable operation, focusing on the XRDP protocol.
Pre-setup Environment Verification
The CentOS version determines the package management commands used and the compatibility of the desktop environment. CentOS 7 uses `yum` and comes with GNOME Classic (based on X11) by default, offering good compatibility with XRDP. In contrast, CentOS 8 and Stream 9 use `dnf`; their default GNOME environment has switched to Wayland. Since XRDP only supports X11 sessions, a Wayland environment causes a black screen or connection failure, necessitating manual disabling of Wayland.
Regarding hardware, the minimum requirement for a graphical desktop environment is 2GB of RAM. If the server has only 1GB of RAM, a lightweight desktop environment like XFCE is recommended; otherwise, the system will experience significant lag after installing GNOME.
Choosing a Desktop Environment: Decisions Based on Resource Constraints
There are three main desktop environments available for CentOS, each with significantly different resource footprints:
| Desktop Environment | Memory Usage (Idle) | Installation Size | Suitable Scenarios |
| GNOME | ~800MB–1.2GB | Large | Full desktop experience, feature-rich |
| KDE Plasma | ~600MB–1GB | Large | Highly customizable, Windows-like interface |
| XFCE | ~300MB–500MB | ~800MB | Low-spec cloud servers, resource-constrained scenarios |
XFCE strikes an excellent balance between resource usage and functionality; testing shows it can reduce memory consumption by over 50%, making it the most practical choice for remote desktops on cloud servers. The complete commands to install XFCE are as follows:
sudo yum update -y
sudo yum install epel-release -y
sudo yum groupinstall "Xfce" -y
If you prefer GNOME, you can run `sudo yum groupinstall "GNOME Desktop" -y` on CentOS 7.
XRDP Installation and Core Configuration
As an open-source RDP server implementation, XRDP is seamlessly compatible with the built-in Windows Remote Desktop client (mstsc.exe) and offers distinct advantages over VNC in terms of transmission efficiency and client compatibility.
Installation steps:
Enable the EPEL repository
sudo yum install epel-release -y
Install XRDP and VNC dependencies
sudo yum install xrdp tigervnc-server-minimal -y
Start the service and enable it to launch at boot
sudo systemctl enable xrdp --now
Key configuration step: Create an `.xsession` file for the user to tell XRDP which desktop environment to launch:
Execute as the target user
echo "xfce4-session" > ~/.xsession
chmod 644 ~/.xsession
If using GNOME, replace the content with `echo "gnome-session" > ~/.xsession`. The file owner must be the logged-in user, not root; incorrect ownership is a common cause of the "black screen" issue after connecting.
Firewall and SELinux Configuration
XRDP listens on port 3389 by default. If FirewallD is running, you must allow this port:
sudo firewall-cmd --add-port=3389/tcp --permanent
sudo firewall-cmd --reload
When SELinux is in enforcing mode, it may prevent XRDP from binding to the network port or invoking graphical components. If the connection is refused despite the firewall allowing the port, execute:
sudo setsebool -P xrdp_exec_t 1
sudo setsebool -P xrdp_connect_net 1
If the issue persists, you can temporarily set SELinux to permissive mode to verify: `sudo setenforce 0`. Once XRDP is confirmed to be working correctly, adjust the policies specifically. Three Keys to Stable Operation
The root cause of a black screen after connection usually lies outside the network layer. In addition to the aforementioned `.xsession` file, CentOS 8 and later versions require Wayland to be disabled. Edit `/etc/gdm/custom.conf` (for GNOME) or `/etc/lightdm/lightdm.conf` (for LightDM), uncomment and set `WaylandEnable=false`, then restart the display manager.
If the Windows client reports an "Authentication Error," it is due to an update in the CredSSP encryption policy rather than an issue with XRDP itself. In a trusted enterprise intranet environment, this can be resolved by adjusting the "Encryption Oracle Remediation" policy via the Group Policy Editor.
In multi-user concurrent scenarios, XRDP supports independent sessions, but each session consumes desktop environment resources. It is recommended to reserve at least 512MB of RAM for each active user and to use XFCE consistently in the `.xsession` file to manage resource consumption.
The core logic of setting up a CentOS virtual desktop from scratch can be summarized as follows: select an appropriate desktop environment to establish a resource baseline; install XRDP to enable the remote connection channel; configure the firewall and SELinux to remove connectivity barriers; and configure `.xsession` to ensure the session launches correctly. All four steps are essential, and the quality of the first three directly determines whether issues like black screens or disconnections occur during the fourth step. For users focused on lightweight management and development/debugging, the XFCE+XRDP combination offers the most pragmatic balance between resource efficiency and user experience.
EN
CN