Administration

Table Of Contents
Table 24. Message Security Mode Options (Continued)
Option Description
Enabled Message security mode is enabled, using a combination of message signing and encryption. JMS messages
are rejected if the signature is missing or invalid, or if a message was modied after it was signed.
Some JMS messages are encrypted because they carry sensitive information such as user credentials. If you
use the Enabled seing, you can also use IPSec to encrypt all JMS messages between View Connection
Server instances, and between View Connection Server instances and security servers.
N View components that predate View 3.0 are not allowed to communicate with other View
components.
Enhanced SSL is used for all JMS connections. JMS access control is also enabled so that desktops, security servers,
and View Connection Server instances can only send and receive JMS messages on certain topics.
View components that predate Horizon 6 version 6.1 cannot communicate with a View Connection Server
6.1 instance.
N Using this mode requires opening TCP port 4002 between DMZ-based security servers and their
paired View Connection Server instances.
When you rst install View on a system, the message security mode is set to Enhanced. If you upgrade View
from a previous release, the message security mode remains unchanged from its existing seing.
I If you plan to change an upgraded View environment from Enabled to Enhanced, you must
rst upgrade all View Connection Server instances, security servers, and View desktops to Horizon 6
version 6.1 or a later release. After you change the seing to Enhanced, the new seing takes place in stages.
1 You must manually restart the VMware Horizon View Message Bus Component service on all View
Connection Server hosts in the pod, or restart the View Connection Server instances.
2 After the services are restarted, the View Connection Server instances recongure the message security
mode on all desktops and security servers, changing the mode to Enhanced.
3 To monitor the progress in View Administrator, go to View  > Global .
On the Security tab, the Enhanced Security Status item will show Enhanced when all components
have made the transition to Enhanced mode.
Alternatively, you can use the vdmutil command-line utility to monitor progress. See “Using the
vdmutil Utility to Congure the JMS Message Security Mode,” on page 31.
View components that predate Horizon 6 version 6.1 cannot communicate with a View Connection Server
6.1 instance that uses Enhanced mode
If you plan to change an active View environment from Disabled to Enabled, or from Enabled to Disabled,
change to Mixed mode for a short time before you make the nal change. For example, if your current mode
is Disabled, change to Mixed mode for one day, then change to Enabled. In Mixed mode, signatures are
aached to messages but not veried, which allows the change of message mode to propagate through the
environment.
Using the vdmutil Utility to Configure the JMS Message Security Mode
You can use the vdmutil command-line interface to congure and manage the security mechanism used
when JMS messages are passed between View components.
Syntax and Location of the Utility
The vdmutil command can perform the same operations as the lmvutil command that was included with
earlier versions of View. In addition, the vdmutil command has options for determining the message
security mode being used and monitoring the progress of changing all View components to Enhanced
mode. Use the following form of the vdmutil command from a Windows command prompt.
vdmutil command_option [additional_option argument] ...
Chapter 2 Configuring View Connection Server
VMware, Inc. 31