Specifications

Table Of Contents
VMware, Inc. 113
Chapter 5 Client Management
ThesmartcardremovalpolicydoesnotapplytouserswhoconnecttotheView
ConnectionServerinstancewiththeLoginascurrentusercheckboxselected,
eveniftheylogintotheirclientsystemwithasmartcard.
5ClickOK.
6RestarttheViewConnectionServerservice.
Configuring User Profiles
Auserprincipalname(UPN)isanaccountnameandadomainnameidentifyingthe
domaininwhichtheuseraccountislocated.TheusualformofUPNisuser@domain.
Forausertoconnectusingsmartcardauthentication,theiraccountinActiveDirectory
musthaveavalidUPNassociated
withtheiruserPrincipalNameproperty.
TheUPNforeachuserwhorequiressmartcardauthenticationmustbesettothe
subjectalternativename(SAN)containedwithintherootcertificateofthetrustedCA.
Youcanlocatethisinformationbyviewingthecertificateproperties,asdescribedin
“ExportingaRootCertificatefroma
UserCertificate”onpage 107.
ThemoststraightforwardwayofaddingthisinformationtoActiveDirectoryistouse
theADSIEditutilityprovidedwiththeWindowsSupportToolssoftwarecollection.If
itisnotalreadypresentonyourActiveDirectoryserver,youcandownloadandinstall
WindowsSupportToolsfromthe
followinglocation:
http://www.microsoft.com/downloads/details.aspx?FamilyID=96a35011fd83419d93
9b9a772ea2df90
To set the UPN to the SAN on Active Directory
1OntheActiveDirectoryserverclickStart>AllPrograms>WindowsSupport
ToolstoopenacommandpromptattheSupportToolsdirectorylocation.
2Enteradsiedit.msctostarttheADSIEditapplication.
3Intheleftpane,expandthedomaininwhichtheuser
youwanttoeditislocated
andexpandCN=Users.
NOTESmartcardauthenticationreplacesWindowspasswordauthenticationonly.
If SecurIDisenabled,usersarerequiredtoauthenticateusingthismechanismalso.
NOTEYouneedtoprovidethisinformationonlyifthecertificatewasissuedfroma
domainotherthantheoneinwhichtheuserpresentlyresides.Acharacteristicof
exportingacertificatefromaserverintheuserscurrentdomainisthattheusersUPN
androotcertificateSANwillcorrelate.