User manual

Table Of Contents
Agent Software Requirements
A Horizon administrator must install product-specific application drivers on the agent machine (virtual
desktop or RDS host).
For Windows 7 virtual desktops, the operating system installs the related driver when you insert a smart
card reader and PIV card. For Windows XP and Windows Vista virtual desktops, you can install the
related driver by using ActivIdentify ActivClient.
The following agent drivers are supported for PIV cards:
n
Charismathics (CSTC PIV 5.2.2)
n
Microsoft minidriver
Enabling the Username Hint Field in Horizon Client
In some environments, smart card users can use a single smart card certificate to authenticate to multiple
user accounts. Users enter their user name in the Username hint field during smart card sign-in.
To make the Username hint field appear on the Horizon Client login dialog box, you must enable the
smart card user name hints feature for the Connection Server instance in Horizon Administrator. The
smart card user name hints feature is supported only with Horizon 7 version 7.0.2 and later servers and
agents. For information about enabling the smart card user name hints feature, see the View
Administration document.
If your environment uses an Unified Access Gateway appliance rather than a security server for secure
external access, you must configure the Unified Access Gateway appliance to support the smart card
user name hints feature. The smart card user name hints feature is supported only with
Unified Access Gateway 2.7.2 and later. For information about enabling the smart card user name hints
feature in Unified Access Gateway, see the Deploying and Configuring Unified Access Gateway
document.
Note Horizon Client still supports single-account smart card certificates when the smart card user name
hints feature is enabled.
Additional Smart Card Authentication Requirements
In addition to meeting the smart card requirements for Horizon Client systems, other Horizon components
must meet certain configuration requirements to support smart cards.
Connection Server and
security server hosts
An administrator must add all applicable Certificate Authority (CA)
certificates for all trusted user certificates to a server truststore file on the
Connection Server host or security server host. These certificates include
root certificates and must include intermediate certificates if the user's
smart card certificate was issued by an intermediate certificate authority.
VMware Horizon Client for Mac Installation and Setup Guide
VMware, Inc. 10