Setup Guide

Table 5. Connection Settings: wnos.ini files only (continued)
Parameter Description
If DisableHotKey is set to yes, then no action when you press the hotkey
defined in Imprivata Server. Only WebAPI 4 and later versions support the
hotkey function.
LoglevelWhile configuring the Imprivata server, user can view the OneSign
logs on ThinOS by enabling the Agent Logging feature. An ini configuration is
needed correspondingly. Default value is 0. If set to 0, logs are not displayed.
If DisablePromptToEnroll is set to yes, then ThinOS does not prompt you to
enroll their security answers after OneSign sign-on. Default value is yes.
SecurityMode specifies the SSL certification validation policy. If set to
default, it applies SecurityPolicy setting. If set to full, the SSL connection
needs to verify server certificate. If it is untrusted, drop the connection. If
set to warning, the SSL connection needs to verify server certificate. If it is
untrusted, it is up to you to continue or drop the connection. If set to low,
the server certificate is not checked. The value is persistent, and the default
value of the setting is default.
From ThinOS version 8.3_109, ThinOS supports OneSign 5.2 RDSH broker.
Set AutoAccess=RDSHD or RDSHA to automatically launch Microsoft type
broker.
Set RDSHPC to automatically launch RDP session without broker.
OneSignTimeout sets the timeout for OneSign login window. The value range
is 0 to 30 seconds. Default is 20 seconds. 0 means no timeout and the
OneSign login window stays forever.
PasswordServer=password_server
[AccountSelfService={yes, no}]
[connect={ica, rdp}]
[encryption={Basic, 40, 56, 128,
Login-128, None}]
Specify an ica/rdp server that can be used to log on to modify password
when you sign-on with password timeout.
The PasswordServer statement can specify the connection parameters as
described in the Connect statement. If no parameter is specified, it connects
with ICA protocol.
AccountSelfService Yes/no option to define the password server as an
Account Self Service server.
If AccountSelfService=yes follows PasswordServer, click the icon on the
signon window to do account self-service.
If Connect parameters do not follow AccountSelfService=yes, this password
server will be the account self-service server of Citrix and clicking the icon
will use Citrix protocol to unlock or change password for an account.
If Connect parameters follow AccountSelfService=yes, clicking the icon
launches a session to change password for an account.
PCoIP_Logging={yes, no}
[Broker_Logging_Level={0,1,2,3,4}]
[Session_Logging_Level={0,1,2,3,4}]
The option PCoIP_Logging can enable and disable the PCoIP client logs
output in Trouble Shooting. If you set the value to yes, then it is same as
selecting the Trouble Shooting Capture Export PCoIP Log radio button to
persistent and no to none.
The option Broker_Logging_level and Session_Logging_Level accord to
PCoIP broker log level and PCoIP session log level. The default value is 0
which means critical log, 1 means log severity error, 2 means log severity
info, 3 means log severity debug, and 4 means log severity unrestrained.
PlatformConfig=all
[EncryptFS=yes]
Encrypts local flash, specifically cached INI files and credentials that are
stored, if using signon=yes.
NOTE:
Event log will display new statements stating that FileSystem encryption
has been enabled.
Parameters for wnos INI files only 29