You can configure the security protocols and cipher suites that BSG's client-side listener accepts by editing the file absg.properties.
Note: The security settings for Connection Server do not apply to BSG. You must configure security for BSG separately.
The supported protocols are as follows:
| Release version | Supported protocols | Default settings |
|---|---|---|
| Horizon 8 version 2312 and later | TLS 1.1, TLS 1.2, TLS 1.3 Note: TLS 1.1 is not supported in FIPS mode. |
|
| Horizon 8 version 2309 and earlier | TLS 1.0, TLS 1.1, TLS 1.2 | TLS 1.2 is enabled. |
Older protocols such as SSLv3 and earlier are never allowed.
Two properties, localHttpsProtocolLow and localHttpsProtocolHigh, determine the range of protocols that the BSG listener will accept. For example, setting localHttpsProtocolLow=tls1.1 and localHttpsProtocolHigh=tls1.3 will configure the listener to accept TLS 1.1, TLS 1.2, and TLS 1.3. You can examine the BSG's absg.log file to discover the values that are in force for a specific BSG instance.
You must specify the list of ciphers using the format that is defined in OpenSSL. You can search for openssl cipher string in a web browser and see the cipher list format. The default cipher lists are as follows:
| Protocol | Default cipher list |
|---|---|
| TLS 1.1, TLS 1.2 | |
| TLS 1.3 | |
Note: In FIPS mode, only GCM cipher suites are enabled (ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256).
Procedure
-
On the Connection Server instance, edit the file
install_directory\Omnissa\Horizon\Server\appblastgateway\absg.properties.By default, the installed directory is %ProgramFiles%.
-
Edit the properties
localHttpsProtocolLowandlocalHttpsProtocolHighto specify a range of protocols.For example,
localHttpsProtocolLow=tls1.1 localHttpsProtocolHigh=tls1.3To enable only one protocol, specify the same protocol for both
localHttpsProtocolLowandlocalHttpsProtocolHigh. -
Edit the
localHttpsCipherSpecproperty to specify a list of cipher suites.For example,
localHttpsCipherSpec=!aNULL:kECDH+AESGCM:ECDH+AESGCM:kECDH+AES:ECDH+AES -
Restart the Windows service Horizon Blast Secure Gateway.
Was this page helpful?