Administrator Guide

4. Click SSO&CM > Advanced Configurations , and use the following guidelines:
a) Ensure that the Enable Proximity Support check box is selected.
b) Ensure that the Enable way2care check box is selected.
5. To prepare a certificate to the Caradigm Vault Server, use the following guidelines:
The Caradigm Vault Server uses the certificate to validate the connection between the Tap Server and the thin client.
a) To raise a request for the certificate:
The certificate should be issued by your Certificate Authority.
Prepare the certificate in two formats:
PFX format which has a private key.
The other is PEM format which is text-based, Base64-encoded DER file. For Example, Caradigm.cer, Caradigm.pfx.
b) To import a certificate to the thin client, use either of the following two options:
Click System Setup > System tools > Certificates to import certificates from USB storage or file server.
Use INI file to import certificate.
AddCertificate=client_cert.pfx password=passpass
c) To add a certificate to Vault server:
Use the Thin Client Certificates page to add certificates for the thin client devices. The certificate must be a text in PEM
format, that is, a text-based Base64-encoded DER file.
Open the DER cert file on Notepad.
Log in to the Vault Server Admin Console, and then click Appliance > Thin Client Certificates.
Copy the Notepad text to the Vault server
Configuration on VDI server and desktops
Caradigm solution of ThinOS supports the multi-types of VDI server such as VMware View Horizon 6, Citrix Virtual Apps 6.5, Citrix Virtual
Apps and Desktops 5.6, and Citrix Virtual Apps and Desktops 7.6.
To configure the VDI server and desktop:
Install the Caradigm desktop components in the servers and desktops.
Indicate vault server IP, and then provide a valid security token.
Add following lines to Service section of the \programdata\sentillion\vergence\Authenticator.ini
configuration file.
TapServerIdentification=True
RemotePromptForPassword=Badge
NOTE:
The PCoIP enabled thin clients offer Caradigm SSO over PCoIP.
SSO and CM client installed on your VDI server and desktops must be upgraded to latest version 6.2.5 in order to support this feature.
Caradigm Way2Care
Way2Care is part of Caradigm Identity and Access Management (IAM) portfolio, and is designed to securely access patient information
from multiple clinical applications.
Use the INI parameter CaradigmServer=xxx UseWay2Care=yes to enable Way2Care. You can also set
DisableManualLogon=yes EGPGroup=xxx along with the Caradigm Server parameter. This feature uses Way2Care API that is
different from the TapServer API. Way2Care uses the decimal UID format.
For more information about the INI parameter, see the Dell Wyse ThinOS INI Reference Guide at www.dell.com/support.
For more information about the Caradigm Way2Care feature, go to www.caradigm.com.
Configure SECUREMATRIX
SECUREMATRIX enhances the security of enterprise and cloud-based applications while providing seamless end-user experience for a
one-time password (OTP) that can be used for authentication with desktops, Windows, VPNs, intranets, extranets, web servers, e-
commerce, and other network resources.
To configure the SECUREMATRIX server, do the following:
1. Enter either https://ip or https://FQDN values.
Configuring connectivity
53