Administration

Table Of Contents
Table 54. vdmutil truesso Command Options for Managing Authenticators
Command and Options Description
--list --authenticator [--verbose]
Lists the fully qualied domain names (FQDNs) of all SAML
authenticators found in the domain. For each one, species whether
True SSO is enabled. If you use the --verbose option, the FQDNs of
the associated connection servers are also listed.
--list --authenticator --name label
For the specied authenticator, lists whether True SSO is enabled, and
lists the FQDNs of the associated connection servers. For label use one
of the names listed when you use the --authenticator option
without the --name option.
--edit --authenticator --name label
--truessoMode mode-value
For the specied authenticator, sets the True SSO mode to the value
you specify, where mode-value can be one of the following values:
n
ENABLED. True SSO is used only when the Active Directory
credentials of the user is not available.
n
ALWAYS. True SSO is always used even if vIDM has the AD
credentials of the user.
n
DISABLED. True SSO is disabled.
For label use one of the names listed when you use the
--authenticator option without the --name option.
Advanced Configuration Settings for True SSO
You can manage the True SSO advanced seings by using the GPO template on the Horizon Agent machine,
registry seings on the enrollment server, and LDAP entries on the connection server. These seings include
default timeout, congure load balancing, specify domains to be included, and more.
Horizon Agent Configuration Settings
You can use GPO template on the agent OS to turn o True SSO at the pool level or to change defaults for
certicate seings such as key size and count and seings for reconnect aempts.
N The following table shows the seings to use for conguring the agent on individual virtual
machines, but you can alternatively use the Horizon Agent Conguration ADM template le
(vdm_agent.adm) to make these policy seings apply to all the virtual machines in a desktop or application
pool. If a policy is set the policy takes precedence over the registry seings
This ADM le is available in a bundled .zip le named VMware-Horizon-Extras-Bundle-x.x.x-yyyyyyy.zip,
which you can download from the VMware download site at
hps://my.vmware.com/web/vmware/downloads. Under Desktop & End-User Computing, select the
VMware Horizon 7 download, which includes the bundled .zip le.
Table 55. Keys for Configuring True SSO on Horizon Agent
Key
Min &
Max Description
Disable True SSO
N/A
Set this key to true to disable the feature on the agent. Use this
seing in the group policy to disable True SSO at the pool level. The
default is false.
Certificate wait timeout
10
-120
Species timeout period of certicates to arrive on the agent, in
seconds. The default is 40.
Minimum key size
1024 -
8192
Minimum allowed size for a key. The default is 1024, meaning that
by default, if the key size is below 1024, the key cannot be used.
All key sizes
N/A Comma-separated list of key sizes that can be used. Up to 5 sizes
can be specied; for example: 1024,2048,3072,4096. The default is
2048.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 83