Installation and Setup Guide

Table Of Contents
Table 35. Horizon Client Configuration Template: Security Settings (Continued)
Setting Computer User Description
Certificate verification
mode
X Configures the level of certificate checking that is performed by
Horizon Client. You can select one of these modes:
n
No Security. Horizon does not perform certificate checking.
n
Warn But Allow. A self-signed certificate is provided by
Horizon. In this case, it is acceptable if the certificate name
does not match the Connection Server name provided by the
user in Horizon Client.
If any other certificate error condition occurs, Horizon displays
an error dialog and prevents the user from connecting to
Connection Server.
Warn But Allow is the default value.
n
Full Security. If any type of certificate error occurs, the user
cannot connect to Connection Server. Horizon displays
certificate errors to the user.
When this group policy setting is configured, users can view the
selected certificate verification mode in Horizon Client but cannot
configure the setting. The SSL configuration dialog box informs
users that the administrator has locked the setting.
When this setting is disabled, Horizon Client users can select a
certificate verification mode. This setting is disabled by default.
To allow a server to perform checking of certificates provided by
Horizon Client, the client must make HTTPS connections to the
Connection Server or security server host. Certificate checking is
not supported if you off-load SSL to an intermediate device that
makes HTTP connections to the Connection Server or security
server host.
If you do not want to configure this setting as a group policy, you
can also enable certificate verification by adding the
CertCheckMode value name to one of the following registry keys
on the client computer:
n
For 32-bit Windows:
HKEY_LOCAL_MACHINE\Software\VMware, Inc.\VMware
VDM\Client\Security
n
For 64-bit Windows: HKLM\SOFTWARE\Wow6432Node\VMware,
Inc.\VMware VDM\Client\Security
Use the following values in the registry key:
n
0 implements No Security.
n
1 implements Warn But Allow.
n
2 implements Full Security.
If you configure both the group policy setting and the
CertCheckMode setting in the Windows Registry key, the group
policy setting takes precedence over the registry key value.
Note In a future release, configuring this setting using the
Windows registry might not be supported. A GPO setting must be
used.
VMware Horizon Client for Windows Installation and Setup Guide
VMware, Inc. 55