Administration

Table Of Contents
Note If you upgrade to View 5.1 or later from an earlier View release, the global setting Require SSL for
client connections is displayed in View Administrator, but only if the setting was disabled in your View
configuration before you upgraded. Because SSL is required for all Horizon Client connections and View
Administrator connections to View, this setting is not displayed in fresh installations of View 5.1 or later
versions and is not displayed after an upgrade if the setting was already enabled in the previous View
configuration.
After an upgrade, if you do not enable the Require SSL for client connections setting, HTTPS
connections from Horizon clients will fail, unless they connect to an intermediate device that is configured
to make onward connections using HTTP. See Off-load SSL Connections to Intermediate Servers.
Message Security Mode for View Components
You can set the message security mode to specify the security mechanism used when JMS messages
pass among View components.
Table 24 shows the options you can select to configure the message security mode. To set an option,
select it from the Message security mode list in the Global Settings dialog window.
Table 24. Message Security Mode Options
Option Description
Disabled Message security mode is disabled.
Mixed Message security mode is enabled but not enforced.
You can use this mode to detect components in your View environment that predate View 3.0. The log files
generated by View Connection Server contain references to these components. This setting is not recommended.
Use this setting only to discover components that need to be upgraded.
Enabled Message security mode is enabled, using a combination of message signing and encryption. JMS messages are
rejected if the signature is missing or invalid, or if a message was modified after it was signed.
Some JMS messages are encrypted because they carry sensitive information such as user credentials. If you use
the Enabled setting, you can also use IPSec to encrypt all JMS messages between View Connection Server
instances, and between View Connection Server instances and security servers.
Note View components that predate View 3.0 are not allowed to communicate with other View components.
Enhanced SSL is used for all JMS connections. JMS access control is also enabled so that desktops, security servers, and
View Connection Server instances can only send and receive JMS messages on certain topics.
View components that predate Horizon 6 version 6.1 cannot communicate with a View Connection Server 6.1
instance.
Note Using this mode requires opening TCP port 4002 between DMZ-based security servers and their paired
View Connection Server instances.
View Administration
VMware, Inc. 33