VMware Horizon Community
BjornMoE
Contributor
Contributor

Login with smart card in VMware View 4 is not working, but it´s working with View 3.1.2 client

Hi all!

I have a concern with View 4 environment. Log in using smart cards to vmware view environment works fine with view 3.1.2 client and a third-party middleware. But it does not work with View 4 client (or 4.0.1) I set up that I require smart card logon in the view manager. Are there any known problems with View 4 client and smart card support? The test is performed on several different Windows clients (XP, XPe SP2, SP3, Win7) Are there any changes in View 4 client for PKSC #11 or CryptoAPI support?

Tags (3)
0 Kudos
6 Replies
Linjo
Leadership
Leadership

What protocol are you useing? Smart Card with PCoIP is not currently supported, RDP should work fine.

Best regards,

Linjo

If you find this information useful, please award points for "correct" or "helpful".

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
BjornMoE
Contributor
Contributor

Yes, I know that. I use the RDP protocol in View 4 client. This is the first step in the login procedure to view broker, the dispaly protocol is not involved in the process yet.

0 Kudos
Linjo
Leadership
Leadership

Ok good. Can you be a little more detaild about what is not working? Any error message? Any clues in the logs?

What CSP?

Best regards,

Linjo

If you find this information useful, please award points for "correct" or "helpful".

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
BjornMoE
Contributor
Contributor

Ok. I have´t done any in-depth troubleshooting yet, just checking if anyone have any knowledge abut this issue before I go further in troubleshooting. I have only tested the group policy object "ShowCertificateSelectDialog" set to yes, but no difference. Yes, I get a error message, I have configured View Manager with "Smart card authentication: Required" and the error message is "The View Connection Server connection faild. Smartcard or Certificate authentication is required". I think this error message is pointing to that the view client can´t find any vaild certificate in the certificate store, but there is (it´s working with view client 3.1.2) and certificate has the proper attributes. I'll go through the logs and troubleshoot more deeply and also to test the soft certificate. I will return with more info soon.

0 Kudos
BjornMoE
Contributor
Contributor

OK, now I have troubelshooted the process of the smart card logon.

I installed and did some tests with a soft certificate with the Microsoft base CSP and it appears as the same way as with the certificate on the smart card. The Smart Card logon or the logon with the soft certificate works with VMware View Client 3.1.2 towards View Manager 4.01, and not with the View Client 4.0.1 I´m doing the test on a Microsoft Windows XP SP3 English version.

I have looked through the vmware view log files and I can´t find anything about the logon process.

I installed the Microsoft tool CAPIMON to trace the CryptoAPI communication and it doesn´t gave much, maybe the View Client doesn´t use the CryptoAPI, it maybe using the PKI standard PKCS#11

Is there any more way too troubleshoot on the client?

The stange thing is when i´m running the VMware View support batch file on the system with 3:rd party middleware, the support batch file accesses the certificate on the smart card and is triggning the PIN dialogbox for the certificate on the Smart Card. Wich means that the support batch file uses the certificate.

0 Kudos
grossag
VMware Employee
VMware Employee

Can you enable TRACE logging by creating a REG_SZ: HKLM\Software\VMware, Inc.\VMware VDM\TraceEnabled and setting it to "true". Then reproduce the problem and upload the most recent debug log file under the current user's directory (on Vista/Win7 this would be C:\Users\\AppData\Local\VMware\VDM\logs). If you want, you can send it privately to me.

0 Kudos