User manual

Table Of Contents
6 If prompted, supply Active Directory credentials.
a Type the user name and password of a user who is entitled to use at least one desktop or
application pool.
b Select a domain.
c Tap to select the Save Password check box if your administrator has enabled this feature and if the
server certificate can be fully verified.
If this is the first time you are saving a password, you are prompted to activate the device
administrator, which is required in order to save a password on Android devices.
d Tap Connect.
The desktop and application selector screen appears.
7 Tap a desktop or application to connect to it.
If you are using smart card authentication, you are not prompted to supply your PIN again, but the
login process takes longer than if you use Active Directory authentication.
If you are connecting to a session-based remote desktop, which is hosted on a Microsoft RDS host, and
if the desktop is already set to use the Microsoft RDP display protocol, you will not be able to connect
immediately. You will be prompted to have the system log you off of the remote operating system so
that a connection can be made with the PCoIP display protocol from VMware.
After you connect to a desktop or application for the first time, a shortcut for the desktop or application is
saved to the Recent Connections screen (Horizon Client 3.0) or Recent tab (Horizon Client 3.1 and later). The
next time you want to connect to the remote desktop or application, you can tap the shortcut instead of
typing the server's name.
Certificate Checking Modes for Horizon Client
Administrators and sometimes end users can configure whether client connections are rejected if any or
some server certificate checks fail.
Certificate checking occurs for SSL connections between View Connection Server and Horizon Client.
Certificate verification includes the following checks:
n
Is the certificate intended for a purpose other than verifying the identity of the sender and encrypting
server communications? That is, is it the correct type of certificate?
n
Has the certificate expired, or is it valid only in the future? That is, is the certificate valid according to
the computer clock?
n
Does the common name on the certificate match the host name of the server that sends it? A mismatch
can occur if a load balancer redirects Horizon Client to a server that has a certificate that does not match
the host name entered in Horizon Client. Another reason a mismatch can occur is if you enter an IP
address rather than a host name in the client.
n
Is the certificate signed by an unknown or untrusted certificate authority (CA)? Self-signed certificates
are one type of untrusted CA.
To pass this check, the certificate's chain of trust must be rooted in the device's local certificate store.
IMPORTANT For instructions about distributing a self-signed root certificate that users can install on their
Android devices, as well as instructions for installing a certificate on an Android device, see documentation
on the Google Web site, such as the Android 3.0 User's Guide.
Chapter 3 Managing Remote Desktop and Application Connections
VMware, Inc. 25