Skip to main content

April 23, 2026

Configuring Advanced TLS Options for Horizon Windows Client

You can select the security protocols and cryptographic algorithms that are used to encrypt communications between Omnissa Horizon Client and Omnissa Horizon Connection Server or Omnissa Unified Access Gateway instances, and between Horizon Client and Horizon Agent in a remote desktop.

How do I change the TLS settings used with Horizon Windows Client?

On the client system, use a group policy setting. For details, see Using Group Policy Settings to Configure Horizon Windows Client and that page's descriptions for Enable TLSv1.1 or TLSv1.2, Configures SSL protocols and cryptographic algorithms, Enable TLSv1.3 and SSLCipherSuites.

Supported TLS Protocols

Horizon Client supports the TLS 1.1, TLS 1.2, and TLS 1.3 security protocols. Older protocols such as TLS 1.0, SSL 2.0, and SSL 3.0 are not supported.

The supported protocols are also used to encrypt the USB channel.

With the default settings, cipher suites use 128-bit or 256-bit AES, remove anonymous DH algorithms, and then sort the current cipher list in order of encryption algorithm key length.

Default TLS Settings

Horizon Client uses the following default TLS settings:

Security ProtocolDefault Setting in Non-FIPS ModeDefault Setting in FIPS Mode
TLS 1.3EnabledNot enabled
TLS 1.2EnabledEnabled
TLS 1.1Not enabledNot enabled

Guidelines for Configuring TLS Settings

Before changing any TLS settings from the defaults, review the guidelines and limitations described in this section.

If you configure security protocols for Horizon Client and none of these protocols are enabled on the Horizon Connection Server or Unified Access Gateway instance to which the client connects, a TLS error occurs and the connection fails.

Important: At least one of the protocols that you enable in Horizon Client must also be enabled on the remote desktop or USB devices cannot be redirected to the remote desktop.

Configuring Advanced TLS Settings

Note: Before changing any TLS settings from the defaults, review the Guidelines for Configuring TLS Settings earlier on this page.

On the client system, you can configure security protocols and cryptographic algorithms using a group policy setting. See the following settings in Using Group Policy Settings to Configure Horizon Windows Client:

  • Enable TLSv1.1 or TLSv1.2
  • Configures SSL protocols and cryptographic algorithms
  • Enable TLSv1.3
  • SSLCipherSuites

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…