Display Managers Explained: GDM, SDDM, greetd and Booting to a Desktop

Display Managers Explained: GDM, SDDM, greetd and Booting to a Desktop

The login screen is not part of your desktop. It is a separate program that authenticates you and then starts the desktop, which is why choosing the wrong one breaks Wayland sessions in ways that look like desktop bugs.

What it does

A display manager:

  1. Starts on a free virtual terminal
  2. Draws a login screen, itself a small graphical session
  3. Authenticates through PAM
  4. Reads the available sessions from desktop files
  5. Starts the chosen session as you
  6. Handles logout, switching users, and sometimes screen locking

Steps 3 and 5 are the ones that matter. It is a privileged process that launches your session, which is why a bad one is both a functional and a security problem.

# which one is running
systemctl status display-manager
cat /etc/systemd/system/display-manager.service | grep ExecStart

# the graphical target it hangs off
systemctl status graphical.target

display-manager.service is a symlink to whichever one is enabled. That indirection is how systemctl commands work regardless of which you use.

The options

DesktopWaylandWeight
GDMGNOMEExcellentHeavy
SDDMKDE PlasmaGoodMedium
LightDMAnyVia greeters, patchyLight
greetdAnyExcellentVery light
LXDM, XDMLegacyNoMinimal

GDM is GNOME’s, and it does things no other display manager does: per-session Wayland handling, fingerprint and smartcard integration, proper handling of the GNOME keyring unlock. On GNOME it is the only sensible choice, and it pulls in a lot of GNOME.

SDDM is KDE’s. Qt-based, themeable, works well with Plasma and fine with other desktops. Lighter than GDM.

LightDM was the cross-desktop standard for years. It separates the greeter from the manager, so the appearance is swappable. Its Wayland support depends entirely on the greeter and is the weak point now.

greetd is the modern minimal option: a small daemon with a pluggable greeter, designed for Wayland compositors. tuigreet gives it a text interface on the console; gtkgreet a graphical one. This is the choice for Sway, Hyprland and river.

Switching

# install the new one
sudo apt install sddm

# Debian and Ubuntu present a chooser
sudo dpkg-reconfigure sddm

# or do it manually, anywhere
sudo systemctl disable gdm
sudo systemctl enable sddm
sudo systemctl reboot

Disable the old one explicitly. Two display managers enabled at once contend for the virtual terminal and you get a black screen or a login loop. This is the single most common failure when switching.

# check exactly one is enabled
systemctl list-unit-files --state=enabled | grep -E 'gdm|sddm|lightdm|greetd'

Before rebooting, make sure you can reach a text console: Ctrl+Alt+F3 usually, or F2. If the new manager does not start, that is how you fix it rather than reinstalling.

Where sessions come from

ls /usr/share/xsessions/            # X11
ls /usr/share/wayland-sessions/     # Wayland
# /usr/share/wayland-sessions/sway.desktop
[Desktop Entry]
Name=Sway
Comment=An i3-compatible Wayland compositor
Exec=sway
Type=Application

That is all a session is. The display manager lists these files and runs Exec for the one you pick.

A session missing from the list means the desktop file is missing, or it is a Wayland session under a display manager that does not offer Wayland. Writing one by hand works:

sudo tee /usr/share/wayland-sessions/mycompositor.desktop <<'EOF'
[Desktop Entry]
Name=My Compositor
Exec=/usr/local/bin/start-compositor
Type=Application
EOF

For a compositor needing environment setup, point Exec at a wrapper script rather than the binary, and set the variables there.

Autologin

Every manager supports it. All of them have the same security consequence.

# GDM: /etc/gdm3/custom.conf  (or /etc/gdm/custom.conf)
[daemon]
AutomaticLoginEnable=true
AutomaticLogin=yourusername
# SDDM: /etc/sddm.conf.d/autologin.conf
[Autologin]
User=yourusername
Session=plasma.desktop
# LightDM: /etc/lightdm/lightdm.conf
[Seat:*]
autologin-user=yourusername
autologin-user-timeout=0
# greetd: /etc/greetd/config.toml
[initial_session]
command = "sway"
user = "yourusername"

Anyone with physical access has your session. That includes your browser sessions, your ssh agent, and your keyring.

It also defeats the point of disk encryption for a laptop you carry around: the disk decrypts at boot, and then the machine logs itself in. Someone who takes it powered off has nothing; someone who takes it and boots it has everything. Our encryption guide covers the threat model.

Reasonable for a desktop at home, a kiosk, or a media machine. Not for anything mobile.

There is also a keyring consequence: the login keyring is normally unlocked by your password at login. With autologin there is no password, so applications prompt for it later, or you set a blank keyring password, which stores your saved credentials unencrypted.

Wayland

# what am I in
echo "$XDG_SESSION_TYPE"
loginctl show-session "$(loginctl | awk '/'"$USER"'/{print $1; exit}')" -p Type
# GDM: to force X11
# /etc/gdm3/custom.conf
[daemon]
WaylandEnable=false
# SDDM: run the greeter itself under Wayland
# /etc/sddm.conf.d/wayland.conf
[General]
DisplayServer=wayland

A detail worth knowing: the greeter’s session type and your session’s type are separate. SDDM can draw itself with X11 and still start a Wayland session. Which is usually fine, and is a source of confusion when diagnosing.

GDM historically disabled Wayland automatically with the proprietary NVIDIA driver. That gating has been relaxed as the driver improved, and it is still worth checking when a Wayland session refuses to appear. Our NVIDIA guide and Wayland comparison cover the specifics.

Running without one

A display manager is optional. You can start a compositor from a text login.

# in ~/.bash_profile
if [ -z "$WAYLAND_DISPLAY" ] && [ "$XDG_VTNR" = 1 ]; then
    exec sway
fi

Log in on VT1 and the compositor replaces the shell. Log in on VT2 and you get a normal shell.

exec matters, because it replaces the shell rather than leaving one waiting behind the session.

The XDG_VTNR = 1 test is what keeps other consoles usable. Without it, every login starts a compositor. Our shell startup files guide covers why .bash_profile rather than .bashrc.

For X11, startx is the equivalent, reading ~/.xinitrc.

What you lose: no session switching, no graphical unlock of the keyring at login, and loginctl session registration that some software expects. In practice PAM still creates the session via login, so most of it works.

What you gain: one less privileged service, a faster boot, and no display manager to misconfigure. Popular with minimal Wayland setups, and a reasonable choice on a single-user machine.

greetd sits between the two: a real display manager, and small enough that it does not feel like one.

Debugging a black screen

# switch to a console first
# Ctrl+Alt+F3

# what is enabled, and is more than one
systemctl list-unit-files --state=enabled | grep -iE 'gdm|sddm|lightdm|greetd'

# why did it fail
systemctl status display-manager
journalctl -b -u display-manager --no-pager | tail -40

# graphics driver loaded at all
lspci -k | grep -A3 -iE 'vga|3d'
journalctl -b -k | grep -iE 'drm|nouveau|amdgpu|i915|nvidia' | tail -20

# stop it and test from the console directly
sudo systemctl stop display-manager
sway                       # or startx

That last step is the most informative one. Starting the compositor by hand puts its errors on your terminal instead of into a session that has already died.

Causes in rough order of frequency:

  1. Two display managers enabled
  2. Graphics driver not loaded, after a kernel update that did not rebuild the module. Our DKMS guide covers that case
  3. A broken session desktop file, so there is nothing to start
  4. Full disk, so the session cannot write anything
  5. Wayland with a driver that will not do it
# emergency route: boot to a console instead of a desktop
# add to the kernel command line, once, from the GRUB menu
systemd.unit=multi-user.target

# or permanently
sudo systemctl set-default multi-user.target
sudo systemctl set-default graphical.target    # to undo

Editing the kernel command line at the boot menu for a single boot is the fastest way into a machine whose graphical stack is broken, per our kernel parameters guide.

Hardening it

The login screen faces anyone standing at the machine.

# GDM: no user list, so usernames are not disclosed
# /etc/dconf/db/gdm.d/00-login-screen
[org/gnome/login-screen]
disable-user-list=true
# SDDM
[Theme]
# most themes honour this
# no guest session
sudo systemctl mask lightdm-guest-session 2>/dev/null

# limit who may log in graphically, via PAM
# /etc/pam.d/gdm-password
auth required pam_succeed_if.so user ingroup desktopusers

Hiding the user list is worth doing on a shared or public machine: it removes free reconnaissance. It does nothing against someone who already knows the username.

The PAM group restriction is the stronger control, and it belongs in the service-specific file rather than common-auth, for the reasons our PAM guide sets out.

Frequently Asked Questions

What does a display manager actually do?

It starts a graphical session and authenticates the user into it. That means running on a free virtual terminal, drawing a login screen, checking credentials through PAM, and then launching the desktop session the user picked. It is a separate program from the desktop itself.

Which display manager should I use?

The one your desktop ships with: GDM for GNOME, SDDM for KDE Plasma. They integrate with those desktops properly, particularly for Wayland. For a standalone window manager, greetd is lighter and simpler, and LightDM is the traditional cross-desktop choice.

How do I change my display manager?

Install the new one, then disable the old service and enable the new one. On Debian and Ubuntu, dpkg-reconfigure on any display manager package presents a chooser that sets it for you. Have a console login available in case the new one does not start.

Why does my session not appear in the login screen list?

Because there is no desktop entry for it, or the entry is in the wrong place. Sessions come from desktop files under /usr/share/xsessions for X11 and /usr/share/wayland-sessions for Wayland, and a Wayland session will not appear if your display manager does not support Wayland.

Can I boot straight to a desktop without a login screen?

Yes. Every display manager supports autologin through its config, and you can also skip the display manager entirely by starting the compositor from your shell profile on a specific virtual terminal. Autologin means anyone with physical access has your session, so it undermines disk encryption at the point it matters.

Why is my screen black after enabling a display manager?

Usually a graphics driver problem or a conflict with another display manager still enabled. Switch to a text console, check which services are active, and read the journal for that unit. Two display managers enabled at once fight over the virtual terminal and neither wins.