User manual

Table Of Contents
Table 35. Horizon Client Configuration Template: Security Settings (Continued)
Setting Computer User Description
Configures SSL
protocols and
cryptographic
algorithms
X X Congures the cipher list to restrict the use of certain
cryptographic algorithms and protocols before establishing an
encrypted SSL connection. The cipher list consists of one or
more cipher strings separated by colons.
N The cipher string is case-sensitive.
The default value is TLSv1:TLSv1.1:TLSv1.2:!aNULL:kECDH
+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH
+AES:ECDH+AES:RSA+AES.
That means that TLS v1, TLS v1.1 and TLS v1.2 are enabled.
(SSL v2.0 and v3.0 are removed.)
Cipher suites use 128- or 256-bit AES, remove anonymous DH
algorithms, and then sort the current cipher list in order of
encryption algorithm key length.
Reference link for the conguration:
hp://www.openssl.org/docs/apps/ciphers.html
The equivalent Windows Registry value is SSLCipherList.
Enable Single Sign-On
for smart card
authentication
X Determines whether single sign-on is enabled for smart card
authentication. When single sign-on is enabled,
Horizon Client stores the encrypted smart card PIN in
temporary memory before submiing it to Connection Server.
When single sign-on is disabled, Horizon Client does not
display a custom PIN dialog.
The equivalent Windows Registry value is
EnableSmartCardSSO.
Ignore certificate
revocation problems
X X Determines whether errors associated with a revoked server
certicate are ignored.
These errors occur when the certicate that the server sends
has been revoked or the client cannot verify the certicate's
revocation status.
This seing is disabled by default.
Unlock remote sessions
when the client machine
is unlocked
X X Determines whether the Recursive Unlock feature is enabled.
The Recursive Unlock feature unlocks all remote sessions after
the client machine has been unlocked. This feature applies
only after a user logs in to the server with the Log in as
current user feature.
This seing is enabled by default.
RDP Settings for Client GPOs
You can set group policies for options such as redirection of such things as audio, printers, ports, and other
devices when you use the Microsoft RDP display protocol.
The following table describes the Remote Desktop Protocol (RDP) seings in the Horizon Client
Conguration ADMX template le. All RDP seings are User Conguration seings. The seings are in the
VMware Horizon Client  > RDP  folder in the Group Policy Management Editor.
Chapter 3 Configuring Horizon Client for End Users
VMware, Inc. 49