Administration

Table Of Contents
Table 56. Registry Keys for Configuring True SSO on the Enrollment Server (Continued)
Registry Key
Min
&
Max Type Description
ConnectToTrustingDomains
N/A REG_SZ Species whether to connect to explicitly
trusting/incoming domains. The default is TRUE.
Use one of the following values:
n
0 means false; do not connect to explicitly
trusting/incoming domains.
n
!=0 means true.
PreferLocalCa
N/A REG_SZ Species whether to prefer the locally installed CA, if
available, for performance benets. If set to TRUE, the
enrollment server will send requests to the local CA. If the
connection to the local CA fails, the enrollment server will
try to send certicates requests to alternate CAs. The
default is FALSE.
Use one of the following values:
n
0 means false.
n
!=0 means true.
MaxSubmitRetryTime
9500-
59000
DWORD Amount of time to wait before retrying to submit a
certicate signing request, in milliseconds. The default is
25000.
SubmitLatencyWarningTime
500 -
5000
DWORD Submit latency warning time when the interface is
marked "Degraded" (in milliseconds). The default is 1500.
The enrollment server uses this seing to determine
whether a CA should be considered to be in a degraded
state. If the last three certicate requests took more
milliseconds to complete than are specied by this seing,
the CA is considered degraded, and this status appears in
the View Administrator Health Status dashboard.
A CA usually issues a certicate within 20 ms, but if the
CA has been idle for a few hours, any initial request
might take longer to complete. This seing allows an
administrator to nd out that a CA is slow, without
necessary having the CA marked as slow. Use this seing
to congure the threshold for marking the CA as slow.
Connection Server Configuration Settings
You can edit View LDAP on View Connection Server to congure a timeout for generating certicates and
whether to enable load balancing certicate requests between enrollment server (recommended).
To change the advanced conguration seings, you must use ADSI Edit on a View Connection Server host.
You can connect by typing in the distinguished name DC=vdi, DC=vmware, DC=int as the connection point,
and typing in the server name and port for the computer localhost:389. Expand OU=Properties, select
OU=Global, and double-click CN=Common in the right pane.
You can then edit the pae-NameValuePair aribute to add one or more of the values listed in the following
table. You must use the syntax name=value when adding values.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 93