Reference Guide

Parameter Description
[ScepUserPwd=scep_enrollment_user_password
]
[ScepUserPwdEnc=encrypted_scep_enrollment_
user_password]
CACertHashTypeCACertHashType is used to verify the authenticity of the
certificate authority. This option must be set to MD5, SHA1, or SHA256.
CACertHash—This is the hash value used to verify certificate authority's
certificate. Client will not issue a certificate request to a SCEP server and cannot
pass certificate chain checking through a valid certificate authority.
EnrollPwd or EnrollPwdEnc—These keywords are used to set the enrollment
password from a SCEP administrator.
EnrollPwd is the plain-text enrollment password and EnrollPwdEnc is the
encrypted form of the same enrollment password. Use only one of these two fields
to set the used enrollment password.
As a substitute of using EnrollPwd or EnrollPwdEnc to directly specify an enrollment
password, client allows using a SCEP administrator's credential to automatically get
an enrollment password from a Windows SCEP server. In this case, the ScepUser,
ScepUserDomain, ScepUserPwd (or ScepUserPwdEnc, in encrypted form
instead of plan-text) are used to specify the SCEP administrator's credential, and
ScepAdminUrl must be set correctly to specify the corresponding SCEP admin web
page's URL. If neither EnrollPwd nor EnrollPwdEnc is set, client will try to use these
set of settings to automatically get an enrollment password and then use that
password to request a certificate. If communication security is necessary in your
environment during this phase, please add https:// as the prefix for ScepAdminUrl
to use HTTPS instead of the default HTTP protocol.
Use ScepAutoEnroll=no AutoRenew=yes to only enable SCEP auto renew; all other
parameters are not needed if ScepAutoEnroll is set to no.
NOTE:
SCEP server’s URL must be an HTTP or HTTPS link. Do not add
protocol prefix to RequestURL and ScepAdminURL.
SelectServerList={PNA, VDI}
[Default=default_desc]
list of servers {Server1; Server2; ...ServerN}
Allows users to select one PNA or VDI server during logon. For server use the
format:
description = <server’s description> host = <server’s url> [ <options>]
NOTE: There must be “description” and “host” key words on each
server.
For PNA server options
, use the options of the PnliteServer parameter in
Connection Settings: wnos.ini files, {username} INI, and $MAC INI Files.
PNA example:
SelectServerList=PNA Default=test3 description =
test1 host = 192.168.0.10 autoconnectlist
=* reconnectfrombutton=0 description = test2 host =
HostName2.wyse.com TimeOut=200 descriprion = test3 host =
https://server3.wyse.com
For a VDI server: If you want to use a VDI broker, specify ConnectionBroker in
wnos.ini. Otherwise the VDI broker’s type is default.
VDI example:
ConnectionBroker=vmware
SelectServerList=VDI \
Default=test5 \
description=test4 host=192.18.0.11 \
description=test6 host=host2
The Default option following "SelectServerList={PNA, VDI}" can specify the default
server. The value is one of server description defined after that. After one selects
another server and sign off, this default server is selected. If default option is not
specified, the last selected server is selected in the next sign on.
30
Parameters for wnos INI files only