Administrator Guide
Table Of Contents
- Dell Wyse ThinOS Version 8.5 Administrator’s Guide
- Introduction
- Getting started
- Configuring ThinOS using the First Boot Wizard
- Connecting to a remote server
- Using your desktop
- Configuring thin client settings and connection settings
- Connecting to a printer
- Connecting to a monitor
- Locking the thin client
- Signing off and shutting down
- Additional getting started details
- Classic desktop features
- Login dialog box features
- Accessing system information
- Global Connection settings
- Configuring the connectivity
- Configuring the network settings
- Configuring the remote connections
- Configuring the central configurations
- Configuring the VPN Manager
- Configuring the connection brokers
- Configuring Citrix
- Configuring the Citrix broker connection
- Citrix HDX RealTime Multimedia Engine or RealTime Optimization Pack
- Citrix icon refresh
- Using multiple audio in Citrix session
- Using Citrix NetScaler with CensorNet MFA authentication
- Configuring ICA connections
- ICA Self Service Password Reset
- QUMU or ICA Multimedia URL Redirection
- HTML5 Video Redirection
- ICA SuperCodec
- Anonymous logon
- Configuring the Citrix UPD printer
- Introduction to Flash Redirection
- Configuring VMware
- Configuring Microsoft Remote Desktop
- Configuring Dell vWorkspace
- Configuring Amazon Web Services or WorkSpaces
- Configuring Citrix
- Configuring thin client settings
- Introduction to TCX Flash Redirection
- Performing diagnostics
- BIOS management on ThinOS
- Security
- Automating updates and settings using central configuration
- Examples of common printing configurations
- Important notes
- Troubleshooting
- Firmware upgrade
- Frequently asked questions
Security
A new global security policy has been defined for ThinOS and this policy is applied to all secure connections (https/SSL
connections) with a few exceptions.
Purpose—To improve the security level by default and add the global configuration. This security policy integrates security
setting for each application.
Table 23. INI parameter
INI parameter Description
SecurityPolicy={full | warning (default) |
low}
SecuredNetworkProtocol={yes | no
(default)}
TLSMinVersion={1 (default), 2, 3}
TLSMaxVesion={1, 2, 3 (default)}
Full—SSL connection need to verify server certificate. If it is
untrusted, cancel the connection.
Warning (default)—SSL connection need to verify server
certificate. If it is untrusted, the user can continue or cancel
the connection.
Low: Server certificate is not verified– this is the value set for
a few applications.
After firmware is updated, the default value is set to warning
for all applicable applications immediately.
There is one exception for file server and WDM.
The old ini SecurityLevel | SecureProtocol from Privilege
segment is deleted.
All applications running on the default SSL security mode follow the global mode. In the global mode, the default value is
Warning. The affected applications include VMware View, Amazon Workspaces (AWS), File Server, WDMService, Caradigm
Server, and OneSign Server.
For more information about the security mode INI parameters, see Dell Wyse ThinOS INI Guide.
The following are the exceptions:
● File Server and WDM in factory reset state: Before loading any INI parameter, the SSL security mode is set to Low, and
after loading the INI parameter, the value is changed to follow the global mode value. For example, the default value is set to
Warning, if the value is not changed by the INI parameter.
System with previous settings (default value is set to Low) follows the global mode after the unit is upgraded. For example,
the default value is set to Warning, if the value is not changed by the INI parameter.
● VMware View and AWS brokers include own security settings (GUI and INI). From ThinOS 8.3 release, an additional
option is added to follow the global mode as its new default value. The security mode GUI context is updated for better
understanding.
10
156 Security