3.0.1
Table Of Contents
- Administration Guide
- Contents
- About This Book
- Introduction
- Installation
- View Administrator
- Virtual Desktop Deployment
- Client Management
- View Client and View Portal
- Client Connections from the Internet
- Creating SSL Server Certificates
- Using Existing SSL Certificates
- Smart Card Authentication
- RSA SecurID Authentication
- View Client Command Line Options
- Virtual Printing
- View Composer
- Offline Desktop
- Component Policies
- Unified Access
- Troubleshooting
- Glossary
- Index
View Manager Administration Guide
82 VMware, Inc.
Smart Card Authentication
Someorganizationsrequirepersonneltopassmultiplestagesofauthenticationbefore
allowingthemtoconnecttotheirsystems.ViewManagerprovidessupportfor
high‐securityenvironmentsbyofferingsmartcardauthenticationofclientsessions.
Smartcardauthenticationworksbypresentingatrustedsetofclientcredentials—a
usercertificate—toViewConnectionServer.Ausercertificat
eisanencryptedsetof
authenticationcredentialsthatincludesthedigitalsignatureofthetrustedroot
CertificateAuthority(CA)thatissuedthecertificate.
Theusercertificateisstoredonthesmartcardandcanonlyberetrievedandpassedto
theserveraftertheuserhasverifiedtheirownershipbyenteringapersonal
identificatio
nnumber(PIN).Certificatesarethenauthenticatedbyusingapublickey
toverifytheincludeddigitalsignature;theexpecteddigitalsignatureiscontainedina
trustedCAcertificatethatisstoredonViewConnectionServer.
ThisfollowingsectionsdescribehowtoconfigureandenablethisfeatureonVi
ew
ConnectionServer.
Smart Card Hardware
EachclientsystemusingsmartcardauthenticationwillrequireViewClientanda
Windows‐compatiblesmartcardreadertobeinstalled.
Inordertorecognizeandusethesmartcardhardware,product‐specificapplication
driversmustbeinstalledonboththeclientsystemsandremotedesktops.Smartcard
profilescanvarybetweenve
ndors;refertothedocumentationthataccompaniesthe
smartcardreaderformore informationabouthowtodothis.
NOTESmartcardauthenticationisonlysupportedbyViewClient;itisnotsupported
byViewAdministrator,ViewPortal,orbyofflinedesktopinstancesaccessedthrough
ViewClientwithOfflineDesktop.