Administration

Table Of Contents
n Logging in with OCSP Certificate Revocation Checking
When you configure OCSP certificate revocation checking, Horizon 7 sends a request to an
OCSP Responder to determine the revocation status of a specific user certificate. Horizon
7 uses an OCSP signing certificate to verify that the responses it receives from the OCSP
Responder are genuine.
n Configure CRL Checking
When you configure CRL checking, Horizon 7 reads a CRL to determine the revocation status
of a smart card user certificate.
n Configure OCSP Certificate Revocation Checking
When you configure OCSP certificate revocation checking, Horizon 7 sends a verification
request to an OCSP Responder to determine the revocation status of a smart card user
certificate.
n Smart Card Certificate Revocation Checking Properties
You set values in the locked.properties file to enable and configure smart card certificate
revocation checking.
Logging in with CRL Checking
When you configure CRL checking, Horizon 7 constructs and reads a CRL to determine the
revocation status of a user certificate.
If a certificate is revoked and smart card authentication is optional, the Enter your user name and
password dialog box appears and the user must provide a password to authenticate. If smart card
authentication is required, the user receives an error message and is not allowed to authenticate.
The same events occur if Horizon 7 cannot read the CRL.
Logging in with OCSP Certificate Revocation Checking
When you configure OCSP certificate revocation checking, Horizon 7 sends a request to an OCSP
Responder to determine the revocation status of a specific user certificate. Horizon 7 uses an
OCSP signing certificate to verify that the responses it receives from the OCSP Responder are
genuine.
If the user certificate is revoked and smart card authentication is optional, the Enter your user
name and password dialog box appears and the user must provide a password to authenticate.
If smart card authentication is required, the user receives an error message and is not allowed to
authenticate.
Horizon 7 falls back to CRL checking if it does not receive a response from the OCSP Responder or
if the response is invalid.
Configure CRL Checking
When you configure CRL checking, Horizon 7 reads a CRL to determine the revocation status of a
smart card user certificate.
Horizon 7 Administration
VMware, Inc. 66