7.0

Table Of Contents
Table 54. vdmutil truesso Command Options for Managing Authenticators
Command and Options Description
--list --authenticator [--verbose]
Lists the fully qualified domain names (FQDNs) of all SAML
authenticators found in the domain. For each one, specifies whether
True SSO is enabled. If you use the --verbose option, the FQDNs of
the associated connection servers are also listed.
--list --authenticator --name label
For the specified authenticator, lists whether True SSO is enabled, and
lists the FQDNs of the associated connection servers. For label use one
of the names listed when you use the --authenticator option
without the --name option.
--edit --authenticator --name label
--truessoMode mode-value
For the specified authenticator, sets the True SSO mode to the value
you specify, where mode-value can be one of the following values:
n
ENABLED. True SSO is used only when the Active Directory
credentials of the user is not available.
n
ALWAYS. True SSO is always used even if vIDM has the AD
credentials of the user.
n
DISABLED. True SSO is disabled.
For label use one of the names listed when you use the
--authenticator option without the --name option.
Advanced Configuration Settings for True SSO
You can manage the True SSO advanced settings by using the GPO template on the Horizon Agent
machine, registry settings on the enrollment server, and LDAP entries on the connection server. These
settings include default timeout, configure load balancing, specify domains to be included, and more.
Horizon Agent Configuration Settings
You can use GPO template on the agent OS to turn off True SSO at the pool level or to change defaults for
certificate settings such as key size and count and settings for reconnect attempts.
NOTE The following table shows the settings to use for configuring the agent on individual virtual
machines, but you can alternatively use the Horizon Agent Configuration ADM template file
(vdm_agent.adm) to make these policy settings apply to all the virtual machines in a desktop or application
pool. If a policy is set the policy takes precedence over the registry settings
This ADM file is available in a bundled .zip file named VMware-Horizon-Extras-Bundle-x.x.x-yyyyyyy.zip,
which you can download from the VMware download site at
https://my.vmware.com/web/vmware/downloads. Under Desktop & End-User Computing, select the
VMware Horizon 7 download, which includes the bundled .zip file.
Table 55. Keys for Configuring True SSO on Horizon Agent
Key
Min &
Max Description
Disable True SSO
N/A
Set this key to true to disable the feature on the agent. Use this
setting in the group policy to disable True SSO at the pool level. The
default is false.
Certificate wait timeout
10
-120
Specifies timeout period of certificates to arrive on the agent, in
seconds. The default is 40.
Minimum key size
1024 -
8192
Minimum allowed size for a key. The default is 1024, meaning that
by default, if the key size is below 1024, the key cannot be used.
All key sizes
N/A Comma-separated list of key sizes that can be used. Up to 5 sizes
can be specified; for example: 1024,2048,3072,4096. The default
is 2048.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 83