JVNC Administrator Guide

Installation, upgrading, removal, unattended deployment, and where everything lives.


1. Requirements


2. Installing with JVNC_<version>.exe

  1. Run the installer. Approve the elevation prompt.
  2. Choose the components and options:
  3. Install folder (default C:\Program Files\JVNC).
  4. JVNC Server and/or JVNC Client — install only what the machine needs.
  5. Desktop shortcuts, Start Menu shortcuts.
  6. Start JVNC Server when I sign in — adds a per-user Run entry; the server then starts minimised in the tray and is listening within seconds of logon.
  7. Windows Firewall rule for the server (inbound TCP, program-based, Private + Domain profiles). The rule is named JVNC Server.
  8. Click Install. The installer copies the files, writes the shortcuts, registers JVNC in Apps & features, and optionally launches the server.

The manuals are installed to <install folder>\docs and linked from the Start Menu.

2.1 Unattended (silent) install

JVNC_1.0.1.exe /S [/D=C:\Path\To\JVNC] [/noserver] [/noclient] [/nostartup] [/nofirewall] [/nodesktop]

The installer needs elevation even when silent; run it from an elevated prompt or a deployment tool that runs as SYSTEM/administrator.


3. Upgrading

Run the new installer over the existing installation. Stable releases are named JVNC_<version>.exe; pre-release builds are JVNC_Development_Build_<version>.exe and install/upgrade the same way. It stops running JVNC processes, replaces the files, and keeps all settings, certificates and logs (they live in each user's %APPDATA%\JVNC, not in the install folder). Clients' pinned server fingerprints remain valid because the server certificate is preserved.


4. Uninstalling

Settings → Apps → JVNC → Uninstall, or run <install folder>\Uninstall.exe (Uninstall.exe /S for silent). This removes the program files, shortcuts, autostart entry, firewall rule and the Apps & features entry.

Per-user data in %APPDATA%\JVNC (settings, logs, certificates and the TOTP secret) is kept by default so a reinstall picks up where it left off. The interactive uninstaller offers to delete it; silently, pass /purge to delete it for the current user.


5. Portable use (no installer)

Copy the Server and Client folders from the installer (or a build's JVNC package) anywhere and run the .exe files directly. The self-contained build has no prerequisites. Settings still go to %APPDATA%\JVNC. You must create your own firewall rule:

netsh advfirewall firewall add rule name="JVNC Server" dir=in action=allow program="C:\Path\Server\JVNC.Server.exe" enable=yes profile=private,domain

6. File and registry locations

Item Location
Program files C:\Program Files\JVNC\Server, ...\Client, ...\docs, Uninstall.exe
Per-user settings, logs, certificates %APPDATA%\JVNC\ (server.json, client.json, *.log, server.pfx, client.pfx)
Autostart (per user) HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JVNC Server
jvnc:// URL handler (per user) HKCU\Software\Classes\jvnc — registered by the client on first run
Uninstall entry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\JVNC
Firewall rule JVNC Server (inbound, program rule)
Start Menu %ProgramData%\Microsoft\Windows\Start Menu\Programs\JVNC\

6.1 server.json reference

Key Meaning
Port Listening port.
BindAddress Empty = all interfaces, or one local IP.
AutoStart Start listening when the program starts.
StartMinimized Start hidden in the tray.
ConfirmIncoming, AutoSaveFolder File-transfer behaviour.
Tls, RequireClientCert, AllowedClientThumbs Encryption and device certificates.
RequirePassword, PasswordVerifier Connection password (default on); the verifier is base64(salt):base64(PBKDF2). Empty verifier with RequirePassword=true triggers the set-password prompt at start.
RequireTotp, TotpSecret One-time codes; the secret is stored as dpapi:… (encrypted for the user).
IpAllowList Comma-separated IPs/CIDRs.
DiffTolerance Change-detection noise tolerance per colour channel (default 8). Hides HDR/dithering flicker that would otherwise make the whole screen "change" every frame; 0 = exact comparison.
DiffMinBytes Bytes per 64×64 tile that must exceed the tolerance before the tile counts as changed (default 12).
ApproveEachConnection Prompt on the PC to allow/deny each connection (default off).
IdleTimeoutMinutes / MaxSessionMinutes Auto-disconnect on idle / total time (0 = off).
PublicRequiresClientCert Refuse public source addresses unless mutual TLS is on (default true).

Editing the file while the server runs is safe for most keys (they are read when the Security dialog is closed or the server starts); restart the server after editing to be sure.


7. Running the server for a signed-in user vs. a service

JVNC Server captures the interactive desktop and injects input as the signed-in user. It is designed to run in the user's session (autostart at sign-in), not as a Windows service. It cannot show the lock screen or log a user in; the machine must be signed in for remote control to work.

To control programs that run elevated (as administrator), run JVNC Server elevated as well (right-click → Run as administrator, or a scheduled task with highest privileges at logon).


8. Ports and multiple servers

One server per machine, one port. If several machines sit behind one router, forward a different external port to each (e.g. 5901 → PC-A:5900, 5902 → PC-B:5900) — or better, use a VPN and skip the port forwards entirely (see the Security Guide).


9. Logs and support information

%APPDATA%\JVNC\server.log and client.log record connections, disconnect reasons with full exception details, security decisions (rejections, bans, approved/unapproved certificates) and, on the client, once-per-second performance figures. Attach both when reporting a problem.