Disable the protocols and encryption algorithms in VMware View connection server and security

Hello

In my recent deployment, I had a customer request to disable some protocols and encryption at the Server VMware View connection and security. I read some articles and found that this has been achieved by editing the locked.properties file. But when we have edited and replaced the file, users could not connect to the virtual desktop, so came back to us backwards and desktop computers worked fine.

I found a few articles that we don't need to edit the locked.properties file in VMware view Horizon 6. If someone has done this please guide me through. Here are the details of the protocols and encryption algorithms that should be disabled

Diffie-Hellman key

Enable SSL v2/V3 and TLS 1.1 and 1.2

Disable the RC4 encryption algorithm

Select the secret of transfer (if possible)


VMware view 6 is the connection to the server and security server.


Thank you.

Hello

I implemented the following steps (from the manual):

1. update the JCE policy files to take in charge the high-strength Cipher Suites

You can add some cipher suites of high resistance for greater assurance, but first you must update the local_policy.jar and US_export_policy.jar files to each server instance and the security strategy for JRE 7 see connection to the server. You update these policy files by downloading the files to extend JCE (Java Cryptography) unlimited strength political jurisdiction from the Oracle Java SE download site 7.

If you include some high-strength cipher suites in the list and you do not replace the policy files, you cannot restart the VMware view Horizon connection to the Server service.

Policy files are located in the directory C:\Program View\Server\jre\lib\security from VMware.

For more information on the download of the JCE unlimited strength jurisdiction policy 7 files, see the Oracle Java SE download site: http://www.oracle.com/technetwork/java/javase/downloads/index.html.

After you update the policy files, you need to create backups of the files. If you upgrade the instance of the view connection server or security server, any changes you have made to these files can be replaced, and you may need to restore the backup files.

2. the changes that policies of global acceptance with ADSI Edit

  • Start the ADSI utility on your computer see connection to the server.
  • In the console tree, select Connect to
  • In the selection or type a unique name text box or a naming context, type the unique name
    DC, DC = vdi is vmware, DC = int.
  • In the type or select a text field or the server box, select or type localhost: 389 or the name of a fully qualified domain (FQDN) of the server computer to connect to port 389 followed view.

For example: localhost: 389 or mycomputer.mydomain.com:389

  • Expand the tree of the ADSI Editor, OU = properties, select OU = Global, then select OU = common in the right pane.
  • On the object CN = common, Global = UO, UO = properties, select each attribute that you want to change and enter the new list of security protocols or cipher suites.
    I used the following settings:

EAP-ServerSSLCipherSuites: \LIST:TLS_RSA_WITH_AES_128_CBC_SHA,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_256_CBC_SHA256

EAP-ServerSSLSecureProtocols_ \LIST:TLSv1.1,TLSv1.2

It is not the highest possible, but they work with all the features of our customers.

  • Restart the service of VMware view Horizon connection server (server connection and security).

This is not Activate secret transfer (if possible) , but other points are covered.

If anyone can give a tip to activate the transfer secret, I would be grateful.

Tags: VMware

Similar Questions

  • Cannot install VMWare View connection Server 5

    Hello

    In order to try the VMWare View 5, I have the program installation and 2008 R2 SP1 virtual server on which I am trying to install VMWare View connection Server 5.

    The server is a complete new installation with only the Active directory (and DNS) installed.

    Everything I try, I keep having the following error:

    This product can only be installed on Windows 2003 or Windows Server 2008 64 - bit. Other operating systems are not supported

    I went through the community forum, but the I have not found my solution to the problem of the forums.

    Kind regards

    Nick

    The broker for connections cannot be installed on a server that is running the role of AD.

    Sent from my iPhone

  • Install the server Vmware View connection

    Hello

    I have problem install vmware view connection server, my server has already joined ActiveDirectory, but I can't install vmware view connection to the server

    vm.jpg

    Help, please.

    Thank you

    Hudan

    It simply means that the client does not like your server certificate.  You should be able to click on configure SSL and change the certification autour options to make it work.

  • icons not showing in the notification area. a disable the UnP and SSD without result. on the Properties tab to hide the icons inactive icon is grayed out

    My icons in the notification area continued to show. I disabled the UnP and SSDP nothing helps. The box to Hide inactive icons on the Properties tab is grayed out so I can't hide the first icon.  Any ideas?

    first of all, what is the brand and model of the pc?

    current antivirus?

    Operating system and service pack?

    Make sure that your system is clean:

    Download, install, update and scan with these full free malware detection programs:

    Malwarebytes (MMFA): http://www.malwarebytes.org/products/malwarebytes_free

    SUPERAntiSpyware: (SAS): http://www.superantispyware.com/

    http://WindowsXP.MVPs.org/TrayNotify.htm

    Read more top

    Finally, after back with the results of the analyses and the answers to the above questions, please.

  • Darkness of 8.4 (1) vpn L2L filter ASA when you specify the Protocol and port

    Hi all - I've spent many hours trying to diagnose this and have read several discussions and the Cisco docs unsuccessfully...

    Situation: two sites running Cisco ASA 5520 on 8.4 (1) with L2L IPsec on the public internet between each of them. The configuration of IPsec and associated routing works as it should and we are able to pass traffic between networks private behind each device as expected. The problem occurs when you try to block sessions using a vpn-filter group policy configuration.

    Each site has 3 private subnets that are able to communicate correctly without the vpn-filter configuration. We want to restrict access to specific protocols, hosts, and ports between each network.

    SITE A: 10.10.0.0/18, 10.10.64.0/18, 10.10.128.0/18

    SITE B: 10.20.0.0/18, 10.20.64.0/18, 10.20.128.0/18

    When we apply a filter-vpn configuration which restricted access only two guests, as follows...

    SITE A: vpn_acl_x_x_x_x list extended access permit ip host 10.20.0.1 host 10.10.0.1

    SITE b: the ip host 10.10.0.1 allowed extended access list vpn_acl_x_x_x_x host 10.20.0.1

    ... the configuration works correctly. However, when we try to lock the configuration more far and specify the protocols and ports, as follows...

    SITE A: vpn_acl_x_x_x_x list extended access permit tcp host 10.20.0.1 host 10.10.0.1 eq 22

    SITE b: vpn_acl_x_x_x_x to the list of access permit tcp host 10.10.0.1 host 10.20.0.1 eq 22

    ... and then try to establish a SSH connection between 10.10.0.1 and 10.20.0.1 or vice versa, the package is stopped on the side of the SOURCE. ..

    Mar 22 11:58:01 x.x.x.x 22 March 2011 14:34:56: % ASA-4-106103: vpn_acl_x_x_x_x of the access list refused tcp to the user "" inside-data/10.10.0.1(59112)-> outside-iptrans/10.20.0.1(22) hit - cnt 1 first success [0xd8d1c1b4, 0 x 0]

    I would really appreciate it if someone could shed some light on what is wrong with this Setup.

    SOLUTION

    The ACE must be implemented on the source and the end of the tunnel destination to facilitate this configuration.

    EXAMPLE 1: allow SSH two-way communication between hosts on each network (SITE A can connect to SITE B, SITE B can connect to SITE A)...

    SITE A:

    access-list vpn_acl_x_x_x_x extended permit tcp host 10.20.0.1 host 10.10.0.1 eq 22

    access-list vpn_acl_x_x_x_x extended permit tcp host 10.20.0.1 eq 22 host 10.10.0.1

    SITE B:

    access-list vpn_acl_x_x_x_x extended permit tcp host 10.10.0.1 host 10.20.0.1 eq 22

    access-list vpn_acl_x_x_x_x extended permit tcp host 10.10.0.1 eq 22 host 10.20.0.1

    EXAMPLE 2: allow communication one-way SSH between hosts on each network (SITE A can connect to SITE B, SITE B is unable to connect to SITE A)...

    SITE A:

    access-list vpn_acl_x_x_x_x extended permit tcp host 10.20.0.1 eq 22 host 10.10.0.1

    SITE B:

    access-list vpn_acl_x_x_x_x extended permit tcp host 10.10.0.1 host 10.20.0.1 eq 22

    Very good and thank you for this post. Please kindly marks the message as answered while others may learn from your post. I think that you have started a very good discussion on vpn-filter for tunnel L2L.

  • Disable the sleep and Sun on

    Is there a way to disable the sleep and Sun on an iPad in flex?

    Artour,

    You can use this to turn off sleep:

    NativeApplication.nativeApplication.systemIdleMode = SystemIdleMode.KEEP_AWAKE;

    -Jason

  • Disable the days and months to Date Pciker

    APEX 4.0
    30%

    Hello, I have a question. How to disable the months and days in the datePicker to apex? I want the year only because Im creating a school year. So, I want only one year in the date picker. How do I do that? Thank you

    You can create a dynamic LOV for use in a select list that generates values in a number of ways, depending on the requirements.

    For example, a way to get a projection of the next decade of this year with the help of a sequence of integer generator:

    select
              y l, y v
    from
              (select
                        extract(year from sysdate) + rownum - 1 y
              from
                        dual connect by rownum <= 10)
    order by
              v
    
    L                      V
    ---------------------- ----------------------
    2010                   2010
    2011                   2011
    2012                   2012
    2013                   2013
    2014                   2014
    2015                   2015
    2016                   2016
    2017                   2017
    2018                   2018
    2019                   2019                   
    

    Or another, to get a this year ± 5 years interval using the model clause:

    select
              y l, y v
    from
              (select
                        y
              from
                        dual
              model
                        return updated rows
                        dimension by (
                          0 n)
                        measures (
                          extract(year from sysdate) - 5 y)
                        rules
                          iterate (10) (
                            y[iteration_number] = y[0] + iteration_number))
    order by
              v
    
    L                      V
    ---------------------- ----------------------
    2006                   2006
    2007                   2007
    2008                   2008
    2009                   2009
    2010                   2010
    2011                   2011
    2012                   2012
    2013                   2013
    2014                   2014
    2015                   2015
    

    You might generate complex results using the clause type games. A pipeline function would be another option.

    Generate values from scratch as this is useful if your system does not have existing tables of reference/dimension of the described type of Jeff.

  • Access secure site HTTP is preventing access to the administrator and security pages.

    I'm trying to access the administrator and security settings, but when I select the option I get a message that I am connected to a secure site, and when I click OK there is a warning that tells me that I can meet with a message indicating that the certificate is not approved to continue anyway; I keep being stopped by the message: error system internal system error accompanied by what seems to be a status bar that does nothing and I can't continue after that screen. Any help would be greatly appreciated. Thank you in advance.

    Ben

    I was not able to change my URL to get changes to compatibility mode, but I found a free application of IE button on Google Chrome app site that allowed me to make the changes to the printer settings.

    Thanks for your suggestion!

    Ben

  • The view connection server connection failure - and that's it.

    Hi all

    I use a box of 10 Windows with Horizon View Client 5.4.1. Our connections are enabled smart cards. When I run the view of the Horizon, I get the login server and hit connect. I am asked to choose a certificate; I choose the right pair, enter my PIN and then get an error message saying "connection to the view connection server failed." And that's the entire message. When I choose the right certificate, get "the connection to the view connection server is not. " No user could not be found for your certificate." That tells me that it's to reach the server, but without more info, I can not find the problem.

    I opened a session with a view to the Horizon with other machines and can I use my chip card with other sites on this computer. There are ports should I open to view Horizon? What else can I try?

    I started poking around outside the view of the Horizon and found the problem, I'll leave it here in case anyone else has this problem. I had to go to Internet Options-> content in-> certificates-> Select Certificate-> advanced and enable authentication of the Client.

  • View Connection Server Manager - column 'User' not showing not connected in the accounts to the inventory of a Fund of the pool

    Hello

    I am trying to identify the point of failure in communication between a pool of related clones and the view connection server - which prevents the management console to see if-and-who is connected to a particular linked clone VM.

    He showed the status of 'User' correctly in the past, but after several re-compositions and to implement a McAfee Firewall required on the connection server, composer and each Linked-Clone - it stopped. Windows Firewall is disabled machines.

    I spent some time already tuning firewall McAfee to enable all required traffic and services and everything works - it seems fair that he is unable to take inventory on the linked clones with regard to if someone is logged in one.

    I suppose that the Agent view handles make this info on the login server, but I can't seem to identify the communication which is apparently filtered, when everything else seems to work in the infrastructure of the view.

    I'm testing with the firewall turned off to see if I can get it working again.

    I have attached a perforated Cap where is the problem.

    Thanks in advance,

    Corey

    It may be a stretch but check the Userinit registry key located at HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogin.   You want to ensure that C:\Program VMware View\Agent\bin\wssm.exe is specified in this key as will facilitate the session/user information to the broker for the connections once connected.

  • Samsung NC-240 - Windows 7 with VMware View connection problem

    Hi all

    My Samsung NC-240 is set to connect to my server VMware View Connection Manager. I can connect to one of my Windows XP via PCoIP or RDP virtual desktop very well, but I can't connect to my virtual Windows 7 desktop. Whenever I try to connect, it will be wrong and tell them "Session Lost!"

    Research in the NC-240 event log, I see the following:

    11 d, 00:01:09.260 > ready to connect to the host

    11 d, 00:01:21.990 > connection to the host (10.3.70.110, 00-00-00-00-00-00)

    11 d, 00:01:22.020 > using resolution 1920 x 1080 at 60 Hz on DVI port 0

    11 d, 00:01:22.150 > CONNECTED (10.3.70.110, 00-00-00-00-00-00)

    11 d, 00:01:22.160 > receiving power state updated: S0

    11 d, 00:01:22.960 > CURRENT SESSION

    11 d, 00:01:23.600 > (MGMT_RDP): invalid capability length (20)

    11 d, 00:01:23.600 > connection down (RDP protocol error detected)

    11 d, 00:01:23.680 > lost Session!

    11 d, 00:01:23.680 > (MGMT_RDP): INIT: received unknown event 0 x 20!

    Here is the information of the current version of my NC-240:

    Part number of the firmware: FW010034

    Hardware version:

    Firmware Version: 3.0

    Firmware Build ID: v250

    Firmware version Date: December 7, 2009 15:55:15

    PCoIP processor revision: 1.0

    Bootloader Version: 2.1

    Bootloader version identifier: v163

    Bootloader Build Date: August 28, 2008 16:56:13

    Here is the information of the current version of my Agent and VMware View VCM:

    VMware View 4.0.0 - 210939

    I appreciate any input.

    Thank you

    Sang A

    I think it's the same than P20 then try wyse page

  • VMware View 5.1.1 Security Server LDAP errors

    Im having a serious amount of errors on my VMware View (5.1.1) security server

    Log debugging shows a large amount of LDAP errors, see below.

    2012-09 - 06T 10: 46:49.075 + 02:00 ERROR (0610-0940) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 11: 01:50.102 + 02:00 ERROR (0610-0CB8) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 11: 16:50.109 + 02:00 ERROR (0610-0FE8) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 11: 31:51.120 + 02:00 ERROR (0610-0DD8) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 11: 46:51.132 + 02:00 ERROR (0610-0244) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 12: 01:52.159 + 02:00 ERROR (0610-0F3C) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 12: 16:52.155 + 02:00 ERROR (0610-0E5C) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 12: 31:53.182 + 02:00 ERROR (0610-0F68) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 12: 46:53.194 + 02:00 ERROR (0610-092 C) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 13: 01:54.217 + 02:00 ERROR (0610-08E4) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE
    2012-09 - 06T 13: 16:54.227 + 02:00 ERROR (0610-0504) < WSAdminDomainTimerThread > [ws_admin] cannot bind to LDAP://rootDSE

    Anyone got any suggestions?

    Hello

    The plugin ws_admin trying to make field checks every 15 minutes, but given that your security server is not on the field these checks fail. It is completely harmless, but they should not run in first place, I raised this in their own country.

    Mike

    Edit:

    There is a simple solution for this in 5.1.x:

    Under the current registry key HKLM\Software\VMware, Inc. \VMware VDM\plugins\wsnm\admin, create a new key named Params, and under that a new DWORD value named InitiateDomainChecks with 0 data. Once set, you will need to restart the VMware View Security Server service for the change to take effect.

  • Download link on the standard view connection server landing page no longer works (see 5.1)

    Hello

    We noticed a problem in the last week or so when clients attempt to download the client to view the launch of our view connection server page.

    The link is https://www.vmware.com/info?id=1109#win

    Who then is forwarded when it lands on the vmware site at

    https://my.VMware.com/Web/VMware/info/slug/desktop_end_user_computing/vmware_horizon_view_clients/1_0#win

    Unfortunately it is no longer available then you get pushed back to the root of the VMware download page.

    After doing a little digging, I discovered that the link to the download of the client page is now

    https://my.VMware.com/Web/VMware/info/slug/desktop_end_user_computing/vmware_horizon_clients/1_0#win

    So, it seems that VMware withdrew the designation of the download page view.

    No doubt other people have this problem too?

    Now, I know that I can change the link on the launch of the connect to Server page, but I'd rather have this fixed on the side of VMware so that I don't have to worry about updating the link when VMware change their website.

    Sincere greetings

    Matt Thurston

    To solve this, had to follow the part of this guide

    http://ituda.com/how-to-customize-the-view-portal-for-client-download-with-VMware-view-5-1/

    Only the part that details how to change the link on the download page.

  • I don't have a message to tell me the image my takes up screen is set to full screen. How to disable the who and the fade slow when he goes to fs?

    In Firefox 42

    When a site like youtube when I make the video fullscreen it just melted slow useless when it does. And then tells me that it is full screen. I know that it is full screen for two reasons. One, I hit the button fullscreen. Two, the video takes up my entire screen. The message point. Use the fade. How can I disable them?

    To disable the fade, you can change these preferences of the topic: config page.

    • full-screen - api .transition - duration.enter: "0 0".
    • full-screen - api .transition - duration.leave: "0 0".

    You can open the topic: config page via the address bar.
    You can accept the warning and click on "I'll be careful" to continue.

    I do not know how to disable the warning, but it might be possible to hide this message with code to userChrome.css or elegant.
    This message is displayed for security reasons because a malicious script can switch to full screen mode and take over the entire window without noticing you (i.e. show a fake office).

  • I had access to my Bookmarks Toolbar wthat wrhen in fullscreen. Tried to disable the modules and plugins that have been updated without result. Suggestions?

    The add-on updated to date has been "Roomy Bookmarks Toolbar" to the 1.3.4 version and the plug-in has been Microsoft Siverlight to 5.1.10411.0 that were made earlier today. I don't think my daughter would have deliberately tried to change the settings without my permission. I have disabled them individually and with no positive effect. I know I have had access to him last night then in full screen (online game) when I open Facebook. Is anyone aware of a parameter which may affect this issue?

    You can use the code in userChrome.css to have the toolbar of bookmarks visible mode full-screen.

    Add code to userChrome.css below default @namespace.

    Customization files (interface) userChrome.css and userContent.css (Web sites) are located in the chrome folder in the user profile folder.

    @namespace url("http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul"); /* only needed once */
    
    #PersonalToolbar[moz-collapsed="true"] {visibility:visible!important}
    

Maybe you are looking for

  • HP Pavilion dv6700 screen went black and nothing responds

    1 HP Pavilion dv6700 2. Windows Vista I turned on my computer yesterdsay and everything went normally, I logged in but then the mouse pad or the keys for volume and all that would not answer. The screen would work normally thought, like a video youtu

  • Computer will not start normally - boots to the BIOS boot screen

    Hi, today I had problems on my computer and it will not start normally upward. This started happening today. When I turn on the monitor, the HP logo appears on a blue screen (as usual), but then, there are a lot of vertical white lines grouped perfec

  • cannot find windows media center

    After the upgrade to the RC of windows 7, I can't find Windows media center but the site of the Media Center said that it is on my computer

  • Fill the third variable according to date

    Dear all, In my database, visitdate and the variable pat_id is here. I want to fill the third variable one that went first, and then we V1, then V2, V3, V4 etc...If the patient went to the same date and same type of visit must be here (e.g.P004) type

  • Flex forum: had ZERO help here. I'm doing something wrong?

    Please do not take it wrong and please don't insult me on this thread.I had NO HELP whatsoever. hundreds of people have read my dilemma no comments yet. It's like I don't exist or my questions are complete shit f *-it hurts me so (OPK - I'm insecure