Reference Guide

Parameter Description
[SecurityMode={default, full, warning, low}] computer and user policy. If none of them is defined, then launch the first available
broker server from the Imprivata server.
If AutoAccess=LOCAL is set, then launch the broker from the ThinClient setting;
the broker getting from the Imprivata Server is ignored.
NOTE: AutoAccess can be set in [username].ini and wnos.ini. The
wnos.ini has priority over [username].ini.
If NetBIOSDomainName is set to yes, then Imprivata domain list will show NetBIOS
domain name and card user will authenticate to the broker server using NetBIOS
domain name. Default is no.
If SuspendAction is set to 0, then lock the terminal when you tap the card or press
the hotkey. If set to 1, then signoff the terminal. If ‘no’ is defined, then lock the
terminal in KioskMode and sign-off the terminal in none KioskMode.
If DisableHotKey is set to yes, then no action when you press the hotkey defined in
Imprivata Server. Only WebAPI 4 and later versions support the hotkey function.
Loglevel—While configuring the Imprivata server, user can view the OneSign logs
on ThinOS by enabling the Agent Logging feature. An ini configuration is needed
correspondingly. Default value is 0. If set to 0, logs are not displayed.
If DisablePromptToEnroll is set to yes, then ThinOS does not prompt you to enroll
their security answers after OneSign sign-on. Default value is yes.
SecurityMode specifies the SSL certification validation policy. If set to default, it
applies SecurityPolicy setting. If set to full, the SSL connection needs to verify
server certificate. If it is untrusted, drop the connection. If set to warning, the SSL
connection needs to verify server certificate. If it is untrusted, it is up to you to
continue or drop the connection. If set to low, the server certificate is not checked.
The value is persistent, and the default value of the setting is default.
From ThinOS version 8.3_109, ThinOS supports OneSign 5.2 RDSH broker.
Set AutoAccess=RDSHD or RDSHA to automatically launch Microsoft type broker.
Set RDSHPC to automatically launch RDP session without broker.
PasswordServer=password_server
[AccountSelfService={yes, no}]
[connect={ica, rdp}]
[encryption={Basic, 40, 56, 128,
Login-128, None}]
Specify an ica/rdp server that can be used to log on to modify password when you
sign-on with password timeout.
The PasswordServer statement can specify the connection parameters as
described in the Connect statement. If no parameter is specified, it connects with
ICA protocol.
AccountSelfService — Yes/no option to define the password server as an Account
Self Service server.
If AccountSelfService=yes follows PasswordServer, click the icon on the signon
window to do account self-service.
If Connect parameters do not follow AccountSelfService=yes, this password server
will be the account self-service server of Citrix and clicking the icon will use Citrix
protocol to unlock or change password for an account.
If Connect parameters follow AccountSelfService=yes, clicking the icon launches a
session to change password for an account.
PCoIP_Logging={yes, no}
[Broker_Logging_Level={0,1,2,3,4}]
[Session_Logging_Level={0,1,2,3,4}]
The option PCoIP_Logging can enable and disable the PCoIP client logs output in
Trouble Shooting. If you set the value to yes, then it is same as selecting the
Trouble Shooting Capture Export PCoIP Log radio button to persistent and no to
none.
The option Broker_Logging_level and Session_Logging_Level accord to PCoIP
broker log level and PCoIP session log level. The default value is 0 which means
critical log, 1 means log severity error, 2 means log severity info, 3 means log
severity debug, and 4 means log severity unrestrained.
Parameters for wnos INI files only 27