6.0

Table Of Contents
Table 24. Message Security Mode Options
Option Description
Disabled Message security mode is disabled.
Mixed Message security mode is enabled but not enforced.
You can use this mode to detect components in your View environment that predate
View 3.0. The log files generated by View Connection Server contain references to
these components.
Enabled Message security mode is enabled. Unsigned messages are rejected by View
components.
Message security mode is enabled by default.
NOTE View components that predate View 3.0 are not allowed to communicate with
other View components
When you first install View on a system, the message security mode is set to Enabled. If you upgrade View,
the message security mode remains unchanged from its existing setting.
Message security mode is supported in View 3.0 and later. If you change the message security mode from
Disabled or Mixed to Enabled, you cannot launch a remote desktop with a View Agent from Virtual
Desktop Manager version 2.1 or earlier. If you then change the message security mode from Enabled to
Mixed or Disabled, the desktop still fails to launch. To launch a remote desktop after you change the
message security mode from Enabled to Mixed or Disabled, you must restart the remote desktop.
If you plan to change an active View environment from Disabled to Enabled, or from Enabled to Disabled,
change to Mixed mode for a short time before you make the final change. For example, if your current mode
is Disabled, change to Mixed mode for one day, then change to Enabled. In Mixed mode, signatures are
attached to messages but not verified, which allows the change of message mode to propagate through the
environment.
Configure the Secure Tunnel and PCoIP Secure Gateway
When the secure tunnel is enabled, Horizon Client makes a second HTTPS connection to the View
Connection Server or security server host when users connect to a remote desktop.
When the PCoIP Secure Gateway is enabled, Horizon Client makes a further secure connection to the View
Connection Server or security server host when users connect to a remote desktop with the PCoIP display
protocol.
When the secure tunnel or PCoIP Secure Gateway is not enabled, a session is established directly between
the client system and the remote desktop virtual machine, bypassing the View Connection Server or security
server host. This type of connection is called a direct connection.
IMPORTANT A typical network configuration that provides secure connections for external clients includes a
security server. To use View Administrator to enable or disable the secure tunnel and PCoIP Secure
Gateway on a security server, you must edit the View Connection Server instance that is paired with the
security server.
In a network configuration in which external clients connect directly to a View Connection Server host, you
enable or disable the secure tunnel and PCoIP Secure Gateway by editing that View Connection Server
instance in View Administrator.
Prerequisites
n
If you intend to enable the PCoIP Secure Gateway, verify that the View Connection Server instance and
paired security server are View 4.6 or later.
n
If you pair a security server to a View Connection Server instance on which you already enabled the
PCoIP Secure Gateway, verify that the security server is View 4.6 or later.
View Administration
34 VMware, Inc.