Administration

Table Of Contents
Logging In with a Smart Card
When a user or administrator inserts a smart card into a smart card reader, the user certicates on the smart
card are copied to the local certicate store on the client system if the client operating system is Windows.
The certicates in the local certicate store are available to all of the applications running on the client
computer, including Horizon Client.
When a user or administrator initiates a connection to a View Connection Server instance or security server
that is congured for smart card authentication, the View Connection Server instance or security server
sends a list of trusted certicate authorities (CAs) to the client system. The client system checks the list of
trusted CAs against the available user certicates, selects a suitable certicate, and then prompts the user or
administrator to enter a smart card PIN. If there are multiple valid user certicates, the client system
prompts the user or administrator to select a certicate.
The client system sends the user certicate to the View Connection Server instance or security server, which
veries the certicate by checking the certicate trust and validity period. Typically, users and
administrators can successfully authenticate if their user certicate is signed and valid. If certicate
revocation checking is congured, users or administrators who have revoked user certicates are prevented
from authenticating.
In some environments, a user's smart card certicate can map to multiple Active Directory domain user
accounts. A user might have multiple accounts with administrator privileges and needs to specify which
account to use in the Username hint eld during smart card login. To make the Username hint eld appear
on the Horizon Client login dialog box, the administrator must enable the smart card user name hints
feature for the Connection Server instance in View Administrator. The smart card user can then enter a user
name or UPN in the Username hint eld during smart card login.
If your environment uses an Access Point appliance for secure external access, you must congure the
Access Point appliance to support the smart card user name hints feature. The smart card user name hints
feature is supported only with Access Point 2.7.2 and later. For information about enabling the smart card
user name hints feature in Access Point, see the Deploying and Conguring Access Point document.
Display protocol switching is not supported with smart card authentication in Horizon Client. To change
display protocols after authenticating with a smart card in Horizon Client, a user must log o and log on
again.
Configure Smart Card Authentication on View Connection Server
To congure smart card authentication, you must obtain a root certicate and add it to a server truststore
le, modify View Connection Server conguration properties, and congure smart card authentication
seings. Depending on your particular environment, you might need to perform additional steps.
Procedure
1 Obtain the Certicate Authority Certicates on page 45
You must obtain all applicable CA (certicate authority) certicates for all trusted user certicates on
the smart cards presented by your users and administrators. These certicates include root certicates
and can include intermediate certicates if the user's smart card certicate was issued by an
intermediate certicate authority.
2 Obtain the CA Certicate from Windows on page 45
If you have a CA-signed user certicate or a smart card that contains one, and Windows trusts the root
certicate, you can export the root certicate from Windows. If the issuer of the user certicate is an
intermediate certicate authority, you can export that certicate.
View Administration
44 VMware, Inc.