Administration

Table Of Contents
Table 23. Global Security Settings for Client Sessions and Connections (Continued)
Setting Description
Enhanced Security Status (Read-
only)
Read-only field that appears when Message security mode is changed from
Enabled to Enhanced. Because the change is made in phases, this field shows the
progress through the phases:
n
Waiting for Message Bus restart is the first phase. This state is displayed until
you manually restart either all View Connection Server instances in the pod or
the VMware Horizon View Message Bus Component service on all View
Connection Server hosts in the pod.
n
Pending Enhanced is the next state. After all View Message Bus Component
services have been restarted, the system begins changing the message security
mode to Enhanced for all desktops and security servers.
n
Enhanced is the final state, indicating that all components are now using
Enhanced message security mode.
You can also use the vdmutil command-line utility to monitor progress. See
“Using the vdmutil Utility to Configure the JMS Message Security Mode,” on
page 30.
Use IPSec for Security Server
connections
Determines whether to use Internet Protocol Security (IPSec) for connections
between security servers and View Connection Server instances.
By default, secure connections (using IPSec) for security server connections is
enabled.
NOTE If you upgrade to View 5.1 or later from an earlier View release, the global setting Require SSL for
client connections is displayed in View Administrator, but only if the setting was disabled in your View
configuration before you upgraded. Because SSL is required for all Horizon Client connections and View
Administrator connections to View, this setting is not displayed in fresh installations of View 5.1 or later
versions and is not displayed after an upgrade if the setting was already enabled in the previous View
configuration.
After an upgrade, if you do not enable the Require SSL for client connections setting, HTTPS connections
from Horizon clients will fail, unless they connect to an intermediate device that is configured to make
onward connections using HTTP. See “Off-load SSL Connections to Intermediate Servers,” on page 34.
Message Security Mode for View Components
You can set the message security mode to specify the security mechanism used when JMS messages pass
among View components.
Table 2-4 shows the options you can select to configure the message security mode. To set an option, select it
from the Message security mode list in the Global Settings dialog window.
Table 24. Message Security Mode Options
Option Description
Disabled Message security mode is disabled.
Mixed Message security mode is enabled but not enforced.
You can use this mode to detect components in your View environment that predate View 3.0. The log
files generated by View Connection Server contain references to these components. This setting is not
recommended. Use this setting only to discover components that need to be upgraded.
Chapter 2 Configuring View Connection Server
VMware, Inc. 29