3.0.1

Table Of Contents
View Manager Administration Guide
82 VMware, Inc.
Smart Card Authentication
Someorganizationsrequirepersonneltopassmultiplestagesofauthenticationbefore
allowingthemtoconnecttotheirsystems.ViewManagerprovidessupportfor
highsecurityenvironmentsbyofferingsmartcardauthenticationofclientsessions.
Smartcardauthenticationworksbypresentingatrustedsetofclientcredentials—a
usercertificate—toViewConnectionServer.Ausercertificat
eisanencryptedsetof
authenticationcredentialsthatincludesthedigitalsignatureofthetrustedroot
CertificateAuthority(CA)thatissuedthecertificate.
Theusercertificateisstoredonthesmartcardandcanonlyberetrievedandpassedto
theserveraftertheuserhasverifiedtheirownershipbyenteringapersonal
identificatio
nnumber(PIN).Certificatesarethenauthenticatedbyusingapublickey
toverifytheincludeddigitalsignature;theexpecteddigitalsignatureiscontainedina
trustedCAcertificatethatisstoredonViewConnectionServer.
ThisfollowingsectionsdescribehowtoconfigureandenablethisfeatureonVi
ew
ConnectionServer.
Smart Card Hardware
EachclientsystemusingsmartcardauthenticationwillrequireViewClientanda
Windowscompatiblesmartcardreadertobeinstalled.
Inordertorecognizeandusethesmartcardhardware,productspecificapplication
driversmustbeinstalledonboththeclientsystemsandremotedesktops.Smartcard
profilescanvarybetweenve
ndors;refertothedocumentationthataccompaniesthe
smartcardreaderformore informationabouthowtodothis.
NOTESmartcardauthenticationisonlysupportedbyViewClient;itisnotsupported
byViewAdministrator,ViewPortal,orbyofflinedesktopinstancesaccessedthrough
ViewClientwithOfflineDesktop.