To enable smart card authentication, you must modify Connection Server configuration properties on your Connection Server.
Prerequisites
Add the CA (certificate authority) certificates for all trusted user certificates to a server truststore file. These certificates include root certificates and can include intermediate certificates if the user's smart card certificate was issued by an intermediate certificate authority.
Procedure
-
Create or edit the
locked.propertiesfile in the TLS/SSL gateway configuration folder on the Connection Server host.For example:
install_directory\View\Server\sslgateway\conf\locked.properties -
Add the
trustKeyfile,trustStoretype, anduseCertAuthproperties to thelocked.propertiesfile.-
Set
trustKeyfileto the name of your truststore file. -
Set
trustStoretypetojks. -
Set
useCertAuthtotrueto enable certificate authentication.
-
-
Restart the Connection Server service to make your changes take effect.
Example: locked.properties File
The file shown specifies that the root certificate for all trusted users is located in the file lonqa.key, sets the trust store type to jks, and enables certificate authentication.
trustKeyfile=lonqa.key
trustStoretype=jks
useCertAuth=true
What to do next
If you configured smart card authentication for a Connection Server instance, configure smart card authentication settings in Horizon Console.
Previous topic:Add the CA Certificate to a Server Truststore File
Was this page helpful?