User manual

Table Of Contents
Configuring Advanced TLS/SSL Options
You can select the security protocols and cryptographic algorithms that are used to encrypt communications
between Horizon Client and Horizon servers or between Horizon Client and the agent in the remote
desktop.
These security options are also used to encrypt the USB channel (communication between the USB service
daemon and the agent).
With the default seing, cipher suites use 128- or 256-bit AES, remove anonymous DH algorithms, and then
sort the current cipher list in order of encryption algorithm key length.
By default, TLS v1.0, TLS v1.1, and TLS v1.2 are enabled. SSL v2.0 and v3.0 are not supported.
N If TLS v1.0 and RC4 are disabled, USB redirection does not work when users are connected to
Windows XP desktops. Be aware of the security risk if you choose to make this feature work by enabling
TLS v1.0 and RC4.
If you congure a security protocol for Horizon Client that is not enabled on the View server to which the
client connects, a TLS/SSL error occurs and the connection fails.
I At least one of the protocols that you enable in Horizon Client must also be enabled on the
remote desktop. Otherwise, USB devices cannot be redirected to the remote desktop.
On the client system, you can use either a group policy seing or a Windows Registry seing to change the
default ciphers and protocols. For information about using a GPO, see the seing called "Congures SSL
protocols and cryptographic algorithms," in “Security Seings for Client GPOs,” on page 44. For
information about using the SSLCipherList seing in the Windows Registry, see “Using the Windows
Registry to Congure Horizon Client,” on page 60.
Configure Application Reconnection Behavior
When you disconnect from a server, running applications might remain open. You can congure how
running applications behave when you reconnect to the server.
A View administrator can disable the application reconnection behavior seings in Horizon Client from the
command line or by seing a group policy seing. The group policy seing takes precedence over the
command-line seing. For more information, see the -appSessionReconnectionBehavior option in
“Horizon Client Command Usage,” on page 57, or the Disconnected application session resumption
behavior group policy seing in “Scripting Denition Seings for Client GPOs,” on page 42.
Procedure
1 In the desktop and application selector window of Horizon Client, right-click a remote application and
select .
Chapter 3 Configuring Horizon Client for End Users
VMware, Inc. 41