Administration

Table Of Contents
When a user or administrator initiates a connection to a View Connection Server instance or security
server that is configured for smart card authentication, the View Connection Server instance or security
server sends a list of trusted certificate authorities (CAs) to the client system. The client system checks
the list of trusted CAs against the available user certificates, selects a suitable certificate, and then
prompts the user or administrator to enter a smart card PIN. If there are multiple valid user certificates,
the client system prompts the user or administrator to select a certificate.
The client system sends the user certificate to the View Connection Server instance or security server,
which verifies the certificate by checking the certificate trust and validity period. Typically, users and
administrators can successfully authenticate if their user certificate is signed and valid. If certificate
revocation checking is configured, users or administrators who have revoked user certificates are
prevented from authenticating.
In some environments, a user's smart card certificate can map to multiple Active Directory domain user
accounts. A user might have multiple accounts with administrator privileges and needs to specify which
account to use in the Username hint field during smart card login. To make the Username hint field
appear on the Horizon Client login dialog box, the administrator must enable the smart card user name
hints feature for the Connection Server instance in View Administrator. The smart card user can then
enter a user name or UPN in the Username hint field during smart card login.
If your environment uses an Access Point appliance for secure external access, you must configure the
Access Point appliance to support the smart card user name hints feature. The smart card user name
hints feature is supported only with Access Point 2.7.2 and later. For information about enabling the smart
card user name hints feature in Access Point, see the Deploying and Configuring Access Point document.
Display protocol switching is not supported with smart card authentication in Horizon Client. To change
display protocols after authenticating with a smart card in Horizon Client, a user must log off and log on
again.
Configure Smart Card Authentication on View Connection
Server
To configure smart card authentication, you must obtain a root certificate and add it to a server truststore
file, modify View Connection Server configuration properties, and configure smart card authentication
settings. Depending on your particular environment, you might need to perform additional steps.
Procedure
1 Obtain the Certificate Authority Certificates
You must obtain all applicable CA (certificate authority) certificates for all trusted user certificates on
the smart cards presented by your users and administrators. These certificates include root
certificates and can include intermediate certificates if the user's smart card certificate was issued by
an intermediate certificate authority.
2 Obtain the CA Certificate from Windows
If you have a CA-signed user certificate or a smart card that contains one, and Windows trusts the
root certificate, you can export the root certificate from Windows. If the issuer of the user certificate
is an intermediate certificate authority, you can export that certificate.
View Administration
VMware, Inc. 47