Administration

Table Of Contents
Table 23. Global Security Settings for Client Sessions and Connections
Setting Description
Reauthenticate secure tunnel
connections after network
interruption
Determines if user credentials must be reauthenticated after a network interruption
when Horizon clients use secure tunnel connections to remote desktops.
When you select this seing, if a secure tunnel connection is interrupted,
Horizon Client requires the user to reauthenticate before reconnecting.
This seing oers increased security. For example, if a laptop is stolen and moved
to a dierent network, the user cannot automatically gain access to the remote
desktop without entering credentials.
When this seing is not selected, the client reconnects to the remote desktop
without requiring the user to reauthenticate.
This seing has no eect when the secure tunnel is not used.
Message security mode Determines the security mechanism used for sending JMS messages between
components
n
When the mode is set to Enabled, signing and verication of the JMS messages
passed between View components takes place.
n
When the mode is set to Enhanced, security is provided by mutually
authenticated SSL JMS connections and access control on JMS topics.
For details, see “Message Security Mode for View Components,” on page 30.
For new installations, by default, message security mode is set to Enhanced. If you
upgrade from a previous version, the seing used in the previous version is
retained.
Enhanced Security Status (Read-
only)
Read-only eld that appears when Message security mode is changed from
Enabled to Enhanced. Because the change is made in phases, this eld shows the
progress through the phases:
n
Waiting for Message Bus restart is the rst phase. This state is displayed until
you manually restart either all View Connection Server instances in the pod or
the VMware Horizon View Message Bus Component service on all View
Connection Server hosts in the pod.
n
Pending Enhanced is the next state. After all View Message Bus Component
services have been restarted, the system begins changing the message security
mode to Enhanced for all desktops and security servers.
n
Enhanced is the nal state, indicating that all components are now using
Enhanced message security mode.
You can also use the vdmutil command-line utility to monitor progress. See
“Using the vdmutil Utility to Congure the JMS Message Security Mode,” on
page 31.
Use IPSec for Security Server
connections
Determines whether to use Internet Protocol Security (IPSec) for connections
between security servers and View Connection Server instances.
By default, secure connections (using IPSec) for security server connections is
enabled.
N If you upgrade to View 5.1 or later from an earlier View release, the global seing Require SSL for
client connections is displayed in View Administrator, but only if the seing was disabled in your View
conguration before you upgraded. Because SSL is required for all Horizon Client connections and View
Administrator connections to View, this seing is not displayed in fresh installations of View 5.1 or later
versions and is not displayed after an upgrade if the seing was already enabled in the previous View
conguration.
After an upgrade, if you do not enable the Require SSL for client connections seing, HTTPS connections
from Horizon clients will fail, unless they connect to an intermediate device that is congured to make
onward connections using HTTP. See “O-load SSL Connections to Intermediate Servers,” on page 34.
Chapter 2 Configuring View Connection Server
VMware, Inc. 29