Skip to main content

July 30, 2026

Configure Advanced TLS Options

You can select the security protocols and cryptographic algorithms that are used to encrypt communications between Omnissa Horizon Client and Omnissa Horizon Connection Server or Omnissa Unified Access Gateway instances, and between Horizon Client and Horizon Agent in a remote desktop.

Supported TLS Protocols

Horizon Client supports the TLS 1.1, TLS 1.2, and TLS 1.3 security protocols. Older protocols such as TLS 1.0, SSL 2.0, and SSL 3.0 are not supported.

Omnissa Horizon 8 also uses the security options to encrypt the USB channel (communication between the USB plugin and Horizon Agent).

Default TLS Settings

Horizon Client uses the following default TLS settings:

Security ProtocolDefault Setting in Non-FIPS ModeDefault Setting in FIPS Mode
TLS 1.3EnabledNot enabled
TLS 1.2EnabledEnabled
TLS 1.1Not enabledNot enabled

The default cipher control strings are as follows:

  • TLS v1.1 or TLS v1.2 -
    • (Non-FIPS mode) !aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES
    • (FIPS mode) !aNULL:ECDHE+AES
  • TLS v1.3-
    • (Non-FIPS mode) TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
    • (FIPS mode) TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256

Guidelines for Configuring TLS Settings

Before changing any TLS settings from the defaults, review the guidelines and limitations described in this section.

If you configure security protocols for Horizon Client and none of these protocols are enabled on the Horizon Connection Server or Unified Access Gateway instance to which the client connects, a TLS error occurs and the connection fails.

For information about configuring the security protocols that Horizon Connection Server can accept, see the Horizon Security document.

Important: At least one of the protocol versions that you activate in Horizon Client must also be activated in the remote desktop for USB devices to be redirected to the remote desktop.

To configure the cipher list, specify one or more cipher strings in order of preference, separated by colons. The cipher string is case-sensitive.

Configuring Advanced TLS Settings

Note: Before changing any TLS settings from the defaults, review the "Guidelines for Configuring TLS Settings" above.

  1. Select Horizon Client > Settings from the menu bar, click Security, and click Advanced.
  2. To activate or deactivate a security protocol, select the check box next to the security protocol name.
  3. To change the cipher control string, replace the default string.
  4. (Optional) To revert to the default settings, click Restore Defaults.
  5. To save your changes, click Confirm.

Your changes take effect the next time you connect to the server.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…