3.0.1

Table Of Contents
VMware, Inc. 87
Chapter 5 Client Management
Configuring a Standard or Replica Server
Asecurityserverthathasbeenconfiguredtousesmartcardauthenticationwill
automaticallyrequiretheusertoauthenticateusingtheircardandPINduringlogin.
Standardandreplicaserverscanbeconfiguredtoaccommodateseveraldifferentsmart
cardauthenticationscenarios.
To set the smart card authentication setting on a standard or replica server
1FromwithintheViewAdministrator,clicktheConfiguration()button.
2UnderVi
ewServersselectaViewConnectionServerentryandclickEdit.
3FromtheSmartcardauthenticationdropdownmenu,selectoneofthefollowing:
Notallowed—Smartcardauthenticationisdisabled.
Optional—Usersmayusesmartcardsauthenticationtoconnect,butpassword
authenticationisalsoper mitte d.Failuretoauthenticateusingasmart card
authenticationwillrequirethatpasswordauthenticationisusedinstead.
Required—Usersmayonlyconnectusingsmartcardauthentication.
4ClickOK.
Configuring User Profiles
Auserprincipalname(UPN)isanaccountnameandadomainnameidentifyingthe
domaininwhichtheuseraccountislocated.Forausertoconnectusingsmartcard
authentication,theiruseraccountintheActiveDirectorymusthaveavalidUPN
associatedwiththeiruserPrincipalNameproperty.
TheUPNforeachus
erwhorequiressmartcardauthenticationmustbesettothe
subjectalternativename(SAN)containedwithintherootcertificateofthetrustedCA.
Youcanlocatethisinformationbyviewingthecertificateproperties,asdescribedin
“ExportingaRootCertificatefromaUserCertificate”onpage 83.
To set the UPN to the SAN on ADAM
1Onanystandardorreplicaconnectionserv
er,clickStart>AllPrograms>ADAM>
ADAMADSIEdit.
2Intheleftpane,expandthedomaininwhichtheuseryouwanttoeditislocated
andexpandCN=Users.
N
OTESmartcardauthenticationonlyreplacesWindowspasswordauthentication.
If SecurIDisenabled,userswillstillberequiredtoauthenticateusingthismechanism
aswell.