User manual

Table Of Contents
n
Is the certicate signed by an unknown or untrusted certicate authority (CA)? Self-signed certicates
are one type of untrusted CA.
To pass this check, the certicate's chain of trust must be rooted in the device's local certicate store.
N For information about distributing a self-signed root certicate and installing it on Mac client
systems, see the Advanced Server Administration document for the Mac Server that you are using, which is
available from the Apple Web site.
In addition to presenting a server certicate, the server also sends a certicate thumbprint to Horizon Client.
The thumbprint is a hash of the certicate public key and is used as an abbreviation of the public key. If the
server does not send a thumbprint, you see a warning that the connection is untrusted.
To set the certicate checking mode, start Horizon Client and select VMware Horizon Client > Preferences
from the menu bar. You have three choices:
n
Never connect to untrusted servers. If any of the certicate checks fails, the client cannot connect to the
server. An error message lists the checks that failed.
n
Warn before connecting to untrusted servers. If a certicate check fails because the server uses a self-
signed certicate, you can click Continue to ignore the warning. For self-signed certicates, the
certicate name is not required to match the server name you entered in Horizon Client.
n
Do not verify server identity . This seing means that no certicate checking occurs.
If the certicate checking mode is set to Warn, you can still connect to a server that uses a self-signed
certicate.
If an administrator later installs a security certicate from a trusted certicate authority, so that all certicate
checks pass when you connect, this trusted connection is remembered for that specic server. In the future,
if that server ever presents a self-signed certicate again, the connection fails. After a particular server
presents a fully veriable certicate, it must always do so.
Configuring Certificate Checking for End Users
You can congure the certicate verication mode so that, for example, full verication is always performed.
Certicate checking occurs for SSL connections between Connection Server and Horizon Client. You can
congure the verication mode to use one of the following strategies:
n
End users are allowed to choose the verication mode. The rest of this list describes the three
verication modes.
n
(No verication) No certicate checks are performed.
n
(Warn) End users are warned if a self-signed certicate is being presented by the server. Users can
choose whether or not to allow this type of connection.
n
(Full security) Full verication is performed and connections that do not pass full verication are
rejected.
For more information about the types of verication checks performed, see “Seing the Certicate Checking
Mode in Horizon Client,” on page 13.
You can set the verication mode so that end users cannot change it. Set the "Security Mode" key in
the /Library/Preferences/com.vmware.horizon.plist le on Mac clients to one of the following values:
n
1 implements Never connect to untrusted servers.
n
2 implements Warn before connecting to untrusted servers.
n
3 implements Do not verify server identity certificates.
VMware Horizon Client for Mac Installation and Setup Guide
14 VMware, Inc.