User manual

Table Of Contents
What to do next
Congure the appropriate registry key with the certicate thumbprint. See “Set the Certicate Thumbprint
in the Windows Registry,” on page 15.
Set the Certificate Thumbprint in the Windows Registry
To allow the HTML Access Agent to use a CA-signed certicate that was imported into the Windows
certicate store, you must congure the certicate thumbprint in a Windows registry key. You must take this
step on each desktop on which you replace the default certicate with a CA-signed certicate.
Prerequisites
Verify that the CA-signed certicate is imported into the Windows certicate store. See “Import a Certicate
for the HTML Access Agent into the Windows Certicate Store,” on page 13.
Procedure
1 In the MMC window on the View desktop where the HTML Access Agent is installed, navigate to the
 (Local Computer) > Personal >  folder.
2 Double-click the CA-signed certicate that you imported into the Windows certicate store.
3 In the Certicates dialog box, click the Details tab, scroll down, and select the Thumbprint icon.
4 Copy the selected thumbprint to a text le.
For example: 31 2a 32 50 1a 0b 34 b1 65 46 13 a8 0a 5e f7 43 6e a9 2c 3e
N When you copy the thumbprint, do not to include the leading space. If you inadvertently paste
the leading space with the thumbprint into the registry key (in Step 7), the certicate might not be
congured successfully. This problem can occur even though the leading space is not displayed in the
registry value text box.
5 Start the Windows Registry Editor on the desktop where the HTML Access Agent is installed.
6 Navigate to the HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc.\VMware Blast\Config registry key.
7 Modify the SslHash value and paste the certicate thumbprint into the text box.
8 Reboot Windows.
When a user connects to a desktop through HTML Access, the HTML Access Agent presents the CA-signed
certicate to the user's browser.
Configure HTML Access Agents to Use Specific Cipher Suites
You can congure the HTML Access Agent to use specic cipher suites instead of the default set of ciphers.
By default, the HTML Access Agent requires incoming SSL connections to use encryption based on certain
ciphers that provide strong protection against network eavesdropping and forgery. You can congure an
alternative list of ciphers for the HTML Access Agent to use. The set of acceptable ciphers is expressed in the
OpenSSL format. which is described at hps://www.openssl.org/docs/apps/ciphers.html.
Procedure
1 Start the Windows Registry Editor on the desktop where the HTML Access Agent is installed.
2 Navigate to the HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc.\VMware Blast\Config registry key.
3 Add a new String (REG_SZ) value, SslCiphers, and paste the cipher list in the OpenSSL format into the
text box.
Chapter 1 Setup and Installation
VMware, Inc. 15