Installation and Setup Guide

Table Of Contents
Table 35. Horizon Client Configuration Template: Security Settings (Continued)
Setting Computer User Description
Enable SSL encrypted
framework channel
X X Determines whether SSL is enabled for View 5.0 and earlier
desktops. Before View 5.0, the data sent over port TCP 32111 to
the desktop was not encrypted.
n
Enable: Enables SSL, but allows fallback to the previous
unencrypted connection if the remote desktop does not have
SSL support. For example, View 5.0 and earlier desktops do
not have SSL support. Enable is the default setting.
n
Disable: Disables SSL. This setting is not recommended but
might be useful for debugging or if the channel is not being
tunneled and could potentially then be optimized by a WAN
accelerator product.
n
Enforce: Enables SSL, and refuses to connect to desktops
with no SSL support .
The equivalent Windows Registry value is EnableTicketSSLAuth.
Configures SSL protocols
and cryptographic
algorithms
X X Configures the cipher list to restrict the use of certain cryptographic
algorithms and protocols before establishing an encrypted SSL
connection. The cipher list consists of one or more cipher strings
separated by colons.
Note The cipher string is case-sensitive.
The default value is TLSv1:TLSv1.1:TLSv1.2:!aNULL:kECDH
+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH
+AES:ECDH+AES:RSA+AES.
That means that TLS v1, TLS v1.1 and TLS v1.2 are enabled. (SSL
v2.0 and v3.0 are removed.)
Cipher suites use 128- or 256-bit AES, remove anonymous DH
algorithms, and then sort the current cipher list in order of
encryption algorithm key length.
Reference link for the configuration:
http://www.openssl.org/docs/apps/ciphers.html
The equivalent Windows Registry value is SSLCipherList.
Enable Single Sign-On for
smart card authentication
X Determines whether single sign-on is enabled for smart card
authentication. When single sign-on is enabled, Horizon Client
stores the encrypted smart card PIN in temporary memory before
submitting it to Connection Server. When single sign-on is disabled,
Horizon Client does not display a custom PIN dialog.
The equivalent Windows Registry value is EnableSmartCardSSO.
VMware Horizon Client for Windows Installation and Setup Guide
VMware, Inc. 57