Skip to main content

How to VNC from a Mac to a Raspberry Pi or Linux desktop

By Lucas Russo, developer of SSHive · Updated

Switch on the VNC server of the machine you want to see, add one profile in SSHive, test it, then route it through an SSH tunnel so the session travels encrypted.

Estimated time: 5 minutes

VNC shows you the screen of another machine and lets you drive it: the desktop of a Raspberry Pi with no monitor attached, an Ubuntu workstation in the next room, a Mac mini in a cupboard. Which server does the sharing depends on the system, wayvnc on current Raspberry Pi OS, x11vnc on an Ubuntu desktop running Xorg, the built-in Screen Sharing on a Mac, and each one asks for a different kind of password, which decides what you type into SSHive. The viewer is part of SSHive Pro on the Mac. With a plain VNC password the session itself travels unencrypted, so the last step puts it inside SSH, and on Ubuntu closes port 5900 to the network as well.

Step-by-step

  1. Turn on the VNC server on the machine you want to see

    Raspberry Pi OS. Run sudo raspi-config, then Interface Options › VNC › Yes; on the desktop, the same switch is under Preferences › Control Centre › Interfaces. On the Wayland desktop of current Raspberry Pi OS this starts wayvnc, which signs you in with your Raspberry Pi username and password; on a Pi still running X11, the same switch starts RealVNC Server. Ubuntu, Xorg session. Install the server with sudo apt install x11vnc and store a VNC password with x11vnc -storepasswd, which writes it to ~/.vnc/passwd. In a terminal of the desktop session, echo $DISPLAY prints the X display of that session, often :0 or :1. Share it with x11vnc -display :0 -auth guess -rfbauth ~/.vnc/passwd -forever, with :0 replaced by that value; -forever keeps x11vnc running after you disconnect. x11vnc shares an X11 display, so a Wayland session gives it nothing to show. macOS. System Settings › General › Sharing, turn on Screen Sharing, then use the ⓘ button next to it to choose who may connect. Your macOS account and password work as they are; for a separate password, turn on VNC viewers may control screen with password. On Linux, ss -tln | grep 5900 should now show a listener. x11vnc also prints the port it listens on when it starts, PORT=5900 by default, whichever display it shares.
  2. Create the VNC profile in SSHive (Pro)

    Sidebar › +. In the Type row pick VNC: the port switches to 5900. Fill Name, Host (the machine's IP or name) and Password. Username is optional, and what goes in it depends on the server: your Raspberry Pi account for wayvnc, your macOS account for Screen Sharing, nothing for an x11vnc VNC password. VNC needs Pro: in the free version the VNC button carries a PRO badge and opens the upgrade window.
  3. Test before you connect

    Test Connection asks the server which sign-in methods it offers and names the one SSHive will use, without sending the password. SSHive supports four on the Mac: VNC password, RSA-AES, VeNCrypt / X.509 and Apple Screen Sharing. If the server offers none of them, the test says so and lists what it does offer: that is the moment to change the server's security setting rather than retype the password.
  4. Send VNC through SSH (local port 15900)

    There is no jump-host field on a VNC profile: the tunnel lives on the SSH profile of the same machine. (1) Open that SSH profile, Advanced options › Local Tunnels (-L) › + Add: local port 15900, remote host localhost, remote port 5900; 15900 rather than 5900, because your own Mac already listens on 5900 when its Screen Sharing is on. (2) Point the VNC profile at host localhost, port 15900. (3) Connect the SSH profile first, then the VNC one. (4) On Ubuntu, restart x11vnc with -localhost added to its command: it then accepts connections from the machine itself only, where the tunnel comes out, and port 5900 is closed to the network. Screen Sharing and wayvnc keep listening on the network: the tunnel protects your session, not their port. For a Mac as the target, turn on Remote Login in the same Sharing pane so SSH can reach it. The free version includes 1 local tunnel, and the SSH tunnel guide covers the rest.

Frequently asked questions

Can SSHive open a Mac's Screen Sharing?+
Yes. Apple describes Screen Sharing as compatible with VNC, and Apple Screen Sharing is one of the four sign-in methods SSHive supports: enter the target Mac's account name and password in the profile. If you also turned on the VNC password option, Test Connection tells you which of the two SSHive will use.
Can I open the same machine from my iPhone or iPad?+
Yes, with the VNC viewer of SSHive for iPhone and iPad, with one difference: the iPhone and iPad app supports VNC password, RSA-AES, UltraVNC MS-Logon II and Apple Screen Sharing, but not VeNCrypt / X.509. A wayvnc server that insists on VeNCrypt opens from the Mac only.

Related SSHive features

VNC Viewer

Built-in VNC viewer

SSH Tunnels

Local, remote & SOCKS5 proxy

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.

Download SSHive Free