5.2

Table Of Contents
The Log in as current user feature has the following limitations and requirements:
n
When
smart card authentication is set to Required on a View Connection Server instance, authentication
fails for users who select the Log in as current user check box when they connect to the View Connection
Server instance. These users must reauthenticate with their smart card and PIN when they log in to View
Connection Server.
n
Users cannot check out a desktop for use in local mode if they selected the Log in as current user check
box when they logged in.
n
The time on the system where the client logs in and the time on the View Connection Server host must be
synchronized.
n
If the default Access this computer from the network user-right assignments are modified on the client
system, they must be modified as described in VMware Knowledge Base (KB) article 1025691.
n
The client machine must be able to communicate with the corporate Active Directory server and not use
cached credentials for authentication. For example, if users log in to their client machines from outside
the corporate network, cached credentials are used for authentication. If the user then attempts to connect
to a security server or a View Connection Server instance without first establishing a VPN connection, the
user is prompted for credentials, and the Log in as Current User feature does not work.
Allow Users to Save Credentials
Administrators can configure View Connection Server to allow View Client mobile devices to remember a
user's user name, password, and domain information. If users choose to have their credentials saved, the
credentials are added to the login fields in View Client on subsequent connections.
On Windows-based View Clients, the feature for logging in as the current user avoids requiring users to supply
credentials multiple times. With View Client for mobile devices, such as Android and iPad, you can configure
a feature that allows a Save Password check box to appear on the login dialog boxes.
You configure a timeout limit that indicates how long to save credential information by setting a value in View
LDAP. The timeout limit is set in minutes. When you change View LDAP on a View Connection Server instance,
the change is propagated to all replicated View Connection Server instances.
Prerequisites
See the Microsoft TechNet Web site for information on how to use the ADSI Edit utility on your Windows
operating system version.
Procedure
1 Start the ADSI Edit utility on your View Connection Server host.
2 In the Connection Settings dialog box, select or connect to DC=vdi,DC=vmware,DC=int.
3 In the Computer pane, select or type localhost:389 or the fully qualified domain name (FQDN) of the
View Connection Server host followed by port 389.
For example: localhost:389 or mycomputer.mydomain.com:389
4 On the object CN=Common, OU=Global, OU=Properties, set the pae-ClientCredentialCacheTimeout
attribute.
When this attribute is not set or is set to 0, the feature is disabled. To enable this feature, you can set the
number of minutes to retain the credential information, or set a value of -1, meaning that there is no
timeout.
On View Connection Server, the new setting takes effect immediately. You do not need to restart the View
Connection Server service or the client computer.
Chapter 7 Setting Up User Authentication
VMware, Inc. 173