Administration

Table Of Contents
Setting Up Smart Card
Authentication
3
For added security, you can configure a Connection Server instance or security server so that
users and administrators can authenticate by using smart cards.
A smart card is a small plastic card that contains a computer chip. The chip, which is like a
miniature computer, includes secure storage for data, including private keys and public key
certificates. One type of smart card used by the United States Department of Defense is called
a Common Access Card (CAC).
With smart card authentication, a user or administrator inserts a smart card into a smart card
reader attached to the client computer and enters a PIN. Smart card authentication provides
two-factor authentication by verifying both what the person has (the smart card) and what the
person knows (the PIN).
See the
Horizon 7 Installation
document for information about hardware and software
requirements for implementing smart card authentication. The Microsoft TechNet Web site
includes detailed information on planning and implementing smart card authentication for
Windows systems.
To use smart cards, client machines must have smart card middleware and a smart card reader.
To install certificates on smart cards, you must set up a computer to act as an enrollment
station. For information about whether a particular type of Horizon Client supports smart cards,
see the Horizon Client documentation at https://docs.vmware.com/en/VMware-Horizon-Client/
index.html.
This chapter includes the following topics:
n Logging In with a Smart Card
n Configure Smart Card Authentication on Horizon Connection Server
n Configure Smart Card Authentication on Third-Party Solutions
n Prepare Active Directory for Smart Card Authentication
n Verify Your Smart Card Authentication Configuration
n Using Smart Card Certificate Revocation Checking
VMware, Inc.
51