Administration

Table Of Contents
Add an Intermediate Certificate to Intermediate Certification Authorities
If you use an intermediate certication authority (CA) to issue smart card login or domain controller
certicates, you must add the intermediate certicate to the Intermediate Certication Authorities group
policy in Active Directory.
Procedure
1 On the Active Directory server, navigate to the Group Policy Management plug-in.
AD Version Navigation Path
Windows 2003
a Select Start > All Programs > Administrative Tools > Active Directory
Users and Computers.
b Right-click your domain and click Properties.
c On the Group Policy tab, click Open to open the Group Policy
Management plug-in.
d Right-click Default Domain Policy, and click Edit.
Windows 2008
a Select Start > Administrative Tools > Group Policy Management.
b Expand your domain, right-click Default Domain Policy, and click
Edit.
2 Expand the Computer  section and open the policy for Windows 
 Key.
3 Right-click Intermediate  Authorities and select Import.
4 Follow the prompts in the wizard to import the intermediate certicate (for example,
intermediateCA.cer) and click OK.
5 Close the Group Policy window.
All of the systems in the domain now have a copy of the intermediate certicate in their intermediate
certication authority store.
Verify Your Smart Card Authentication Configuration
After you set up smart card authentication for the rst time, or when smart card authentication is not
working correctly, you should verify your smart card authentication conguration.
Procedure
n
Verify that each client system has smart card middleware, a smart card with a valid certicate, and a
smart card reader. For end users, verify that they have Horizon Client.
See the documentation provided by your smart card vendor for information on conguring smart card
software and hardware.
n
On each client system, select Start >  > Control Panel > Internet Options > Content >
 > Personal to verify that certicates are available for smart card authentication.
When a user or administrator inserts a smart card into the smart card reader, Windows copies
certicates from the smart card to the user's computer. Applications on the client system, including
Horizon Client, can use these certicates.
n
In the locked.properties le on the View Connection Server or security server host, verify that the
useCertAuth property is set to true and is spelled correctly.
The locked.properties le is located in install_directory\VMware\VMware
View\Server\sslgateway\conf. The useCertAuth property is commonly misspelled as userCertAuth.
View Administration
52 VMware, Inc.