Administration

Table Of Contents
Table 55. Keys for Configuring True SSO on Horizon Agent
Key
Min &
Max Description
Disable True SSO
N/A
Set this key to true to disable the feature on the agent. Use this
seing in the group policy to disable True SSO at the pool level. The
default is false.
Certificate wait timeout
10
-120
Species timeout period of certicates to arrive on the agent, in
seconds. The default is 40.
Minimum key size
1024 -
8192
Minimum allowed size for a key. The default is 1024, meaning that
by default, if the key size is below 1024, the key cannot be used.
All key sizes
N/A Comma-separated list of key sizes that can be used. Up to 5 sizes
can be specied; for example: 1024,2048,3072,4096. The default is
2048.
Number of keys to pre-create
1-100 Number of keys to pre-create on RDS servers that provide remote
desktops and hosted Windows applications. The default is 5.
Minimum validity period required
for a certificate
N/A Minimum validity period, in minutes, required for a certicate
when it is being reused to reconnect a user. The default is 5.
Enrollment Server Configuration Settings
You can use Windows Registry seings on the enrollment server OS to congure which domains to connect
to, various timeout periods, polling periods, and retries, and whether to prefer using the certicate authority
that is installed on the same local server (recommended).
To change the advanced conguration seings, you can open the Windows Registry Editor (regedit.exe) on
the enrollment server machine and navigate to the following registry key:
HKLM\SOFTWARE\VMware, Inc.\VMware VDM\Enrollment Service
Table 56. Registry Keys for Configuring True SSO on the Enrollment Server
Registry Key
Min
&
Max Type Description
ConnectToDomains
N/A REG_MUL
TI_SZ
List of domains the enrollment server aempts to connect
to automatically. For this multi-string registry type, the
DNS fully qualied domain name (FQDN) of each
domain is listed on its own line.
The default is to trust all domains.
ExcludeDomains
N/A REG_MUL
TI_SZ
List of domains the enrollment server does not connect to
automatically. If the connection server provides a
conguration set with any of the domains, the enrollment
server will aempt to connect to that domain or domains.
For this multi-string registry type, the DNS FQDN of each
domain is listed on its own line.
The default is to exclude no domains.
ConnectToDomainsInForest
N/A REG_SZ Species whether to connect to and use all domains in the
forest that the enrollment server is a member of. The
default is TRUE.
Use one of the following values:
n
0 means false; do not connect to the domains of the
forest being used.
n
!=0 means true.
View Administration
92 VMware, Inc.