Administration

Table Of Contents
Setting Up Authentication 3
View uses your existing Active Directory infrastructure for user and administrator authentication and
management. For added security, you can integrate View with smart card authentication. You can also use
biometric authentication or two-factor authentication solutions, such as RSA SecurID and RADIUS, to
authenticate remote desktop and application users.
This chapter includes the following topics:
n
“Using Two-Factor Authentication,” on page 39
n
“Using Smart Card Authentication,” on page 43
n
“Using SAML Authentication,” on page 53
n
“Using Smart Card Certificate Revocation Checking,” on page 56
n
“Using the Log In as Current User Feature Available with Windows-Based Horizon Client,” on
page 59
n
“Allow Users to Save Credentials,” on page 60
n
“Configure Biometric Authentication,” on page 61
Using Two-Factor Authentication
You can configure a View Connection Server instance so that users are required to use RSA SecurID
authentication or RADIUS (Remote Authentication Dial-In User Service) authentication.
n
RADIUS support offers a wide range of alternative two-factor token-based authentication options.
n
View also provides an open standard extension interface to allow third-party solution providers to
integrate advanced authentication extensions into View.
Because two-factor authentication solutions such as RSA SecurID and RADIUS work with authentication
managers, installed on separate servers, you must have those servers configured and accessible to the View
Connection Server host. For example, if you use RSA SecurID, the authentication manager would be RSA
Authentication Manager. If you have RADIUS, the authentication manager would be a RADIUS server.
To use two-factor authentication, each user must have a token, such as an RSA SecurID token, that is
registered with its authentication manager. A two-factor authentication token is a piece of hardware or
software that generates an authentication code at fixed intervals. Often authentication requires knowledge
of both a PIN and an authentication code.
If you have multiple View Connection Server instances, you can configure two-factor authentication on
some instances and a different user authentication method on others. For example, you can configure two-
factor authentication only for users who access remote desktops and applications from outside the corporate
network, over the Internet.
VMware, Inc.
39