When you configure CRL checking, Omnissa Horizon reads a CRL to determine the revocation status of a smart card user certificate.
Prerequisites
Familiarize yourself with the locked.properties file properties for CRL checking. See Smart Card Certificate Revocation Checking Properties.
Procedure
-
Create or edit the
locked.propertiesfile in the TLS/SSL gateway configuration folder on the Omnissa Horizon Connection Server host.For example:
install_directory\View\Server\sslgateway\conf\locked.properties -
Add the
enableRevocationCheckingandcrlLocationproperties to thelocked.propertiesfile.-
Set
enableRevocationCheckingtotrueto enable smart card certificate revocation checking. -
Set
crlLocationto the location of the CRL. The value can be a URL or a file path.
-
-
Restart the Horizon Connection Server service to make your changes take effect.
Example: locked.properties File
The file shown enables smart card authentication and smart card certificate revocation checking, configures CRL checking, and specifies a URL for the CRL location.
trustKeyfile=lonqa.key
trustStoretype=jks
useCertAuth=true
enableRevocationChecking=true
crlLocation=http://root.ocsp.net/certEnroll/ocsp-ROOT_CA.crl
To specify multiple CRL location properties, add the properties as follows:
crlLocation.1=http://location1.crl
crlLocation.2=http://location2.crl
Restart the Horizon Connection Server or security server to make your changes take effect.
Was this page helpful?