Skip to main content

April 20, 2026

Security-Related Settings in Horizon LDAP

Security-related settings are provided in Horizon LDAP. You can use the ADSI Edit utility to change the value of these settings on a connection broker instance. The change propagates automatically to all other connection broker instances in a group.

Name-value pairDescription
keysizeThe attribute is pae-MSGSecOptions. When the message security mode is set to Enhanced, TLS is used to secure JMS connections rather than using per-message encryption. In enhanced message security mode, validation applies to only one message type. For enhanced message mode, Omnissa recommends a key size of 2048 bits.
  • If your system is running in FIPS mode, it is already set to 2048 by default.
  • If your system is not running in FIPS mode, the default value is 512. If you are not using enhanced message security mode, Omnissa recommends not changing the default from 512 bits because increasing the key size affects performance and scalability. If you are using enhanced message security mode, Omnissa recommends increasing the value to 2048. If you want all keys to be 2048 bits, the DSA key size must be changed immediately after the first connection broker instance is installed and before additional servers and desktops are created.

Auto-renew self-signed certificates

You can set the number of days before certificate expiry to auto-renew self-signed certificates with the pae-managedCertificateAdvanceRollOver attribute.

Specify a value to replace the self-signed certificate with a future or pending certificate within the specified number of days prior to the current certificate expiration.

By default this value is not set. The valid range is 1-90.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…