User manual

Table Of Contents
You can set the verification mode so that end users cannot change it. Set the "Security Mode" key in
the /Library/Preferences/com.vmware.view.plist (Horizon Client 3.0)
or /Library/Preferences/com.vmware.horizon.plist (Horizon Client 3.1 and later) file on Mac clients to one
of the following values:
n
1 implements Never connect to untrusted servers.
n
2 implements Warn before connecting to untrusted servers.
n
3 implements Do not verify server identity certificates.
Configure Advanced SSL Options
You can select the security protocols that Horizon Client can use. You can also specify the cipher control
string.
The advanced SSL options that you configure in Horizon Client are used to encrypt communications
between Horizon Client and View Connection Server and View Agent. In Horizon Client 3.1 and later, these
options are also used to encrypt the USB channel (communication between the USB service daemon and
View Agent).
IMPORTANT If the only protocol you enable on the client is TLS v1.1, you must verify that TLS v1.1 is also
enabled on the remote desktop. Otherwise, USB devices cannot be redirected to the remote desktop.
Prerequisites
Verify the security protocol that the View server can use. If you configure a security protocol for
Horizon Client that is not enabled on the View server to which the client connects, an SSL error occurs and
the connection fails. For information about configuring the security protocols that are accepted by View
Connection Server instances, see the View Security document.
Horizon Client and View Connection Server support TLS v1.0 and TLS v1.1 by default. You should change
the security protocols in Horizon Client only if your View administrator instructs you to do so, or if your
View server does not support the current settings.
Procedure
1 Select VMware Horizon View Client > Preferences (Horizon Client 3.0) or VMware Horizon Client >
Preferences (Horizon Client 3.1 and later) from the menu bar, click Security, and click Advanced.
2 To enable or disable a security protocol, select the check box next to the security protocol name.
TLSv1.0 and TLSv1.1 are enabled by default.
3 To change the cipher control string, replace the default string.
The default cipher control string (AES:!aNULL:@STRENGTH) includes cipher suites that use either 128-
bit or 256-bit AES encryption, except for anonymous DH algorithms, and sorts them by strength.
NOTE In Horizon Client 3.1 and later, the USB service daemon adds RC4 (:RC4-SHA: +RC4) to the end
of the cipher control string when it connects to a remote desktop.
4 (Optional) If you need to revert to the default settings, click Restore Defaults.
5 Click Confirm to save your changes.
Your changes take effect the next time you connect to View Connection Server.
Using VMware Horizon Client for Mac OS X
12 VMware, Inc.