User manual

Table Of Contents
n
To use two-factor authentication with Horizon View Client, such as RSA SecurID or RADIUS
authentication, you must enable this feature on View Connection Server. RADIUS authentication is
available with View 5.1 or later View Connection Server. For more information, see the topics about
two-factor authentication in the VMware Horizon View Administration documentation.
n
To allow end users to save their passwords with Horizon View Client, so that users do not always need
to supply credentials when logging in to a remote desktop, configure the policy for this feature on View
Connection Server.
This feature is available for View Client 1.5 and later connecting to remote desktops through View
Connection Server 5.1 or later . Users can save their passwords if the policy is configured to allow it and
if Horizon View Client can fully verify the server certificate that View Connection Server presents. For
instructions about configuring this policy, see the topic called "Allow Users to Save Credentials" in the
chapter called "Setting Up User Authentication," in the VMware Horizon View Administration
documentation.
n
Verify that the desktop pool is set to use the PCoIP display protocol. See the VMware Horizon View
Administration documentation.
Using Embedded RSA SecurID Software Tokens
If you create and distribute RSA SecurID software tokens to end users, they need enter only their PIN, rather
than PIN and token code, to authenticate.
Setup Requirements
NOTE This feature is available only if you are using View Client 1.2 or later.
You can use Compressed Token Format (CTF) or dynamic seed provisioning, which is also called CT-KIP
(Cryptographic Token Key Initialization Protocol), to set up an easy-to-use RSA authentication system. With
this system, you generate a URL to send to end users. To install the token, end users paste this URL directly
into Horizon View Client on their client devices. The dialog box for pasting this URL appears when end
users connect to View Connection Server with Horizon View Client.
After the software token is installed, end users enter a PIN to authenticate. With external RSA tokens, end
users must enter a PIN and the token code generated by a hardware or software authentication token.
The following URL prefixes are supported if end users will be copying and pasting the URL into
Horizon View Client when Horizon View Client is connected to an RSA-enabled View Connection Server:
n
viewclient-securid://
n
com.rsa.securid.iphone://
n
com.rsa.securid://
For end users who will be installing the token by tapping the URL, only the prefix viewclient-securid:// is
supported.
For information about using dynamic seed provisioning or file-based (CTF) provisioning, see the Web page
RSA SecurID Software Token for iPhone Devices at http://www.rsa.com/node.aspx?id=3652 or RSA SecurID
Software Token for Android at http://www.rsa.com/node.aspx?id=3832.
Chapter 1 Setup and Installation
VMware, Inc. 9