Skip to main content

April 14, 2026

Configure Advanced Security Options

You can select the security protocols and cryptographic algorithms that are used to encrypt communications between Horizon Client and Connection Server or Unified Access Gateway instances, and between Horizon Client and Horizon Agent in a remote desktop.

Supported TLS Protocols

Horizon Client supports the TLS 1.1, TLS 1.2, and TLS 1.3 security protocols. Older protocols such as TLS 1.0, SSL 2.0, and SSL 3.0 are not supported.

Default TLS Settings

Horizon Client uses the following default TLS settings:

Security ProtocolDefault Setting in Non-FIPS ModeDefault Setting in FIPS Mode
TLS 1.3EnabledNot enabled
TLS 1.2EnabledEnabled
TLS 1.1Not enabledNot enabled

The default cipher control strings are as follows:

  • TLS v1.1 or TLS v1.2 -
    • (Non-FIPS mode) !aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES
    • (FIPS mode) !aNULL:ECDHE+AES
  • TLS v1.3 -
    • (Non-FIPS mode) TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
    • (FIPS mode) TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256

Guidelines for Configuring TLS Settings

Before changing any TLS settings from the defaults, review the guidelines and limitations described in this section.

If you configure security protocols for Horizon Client and none of these protocols are enabled on the Connection Server or Unified Access Gateway instance to which the client connects, a TLS error occurs and the connection fails.

For information about configuring the security protocols that Connection Server can accept, see Horizon Security.

To configure the cipher list, specify one or more cipher strings in order of preference, separated by colons. The cipher string is case-sensitive.

Configuring Advanced TLS Settings

Note: Before changing any TLS settings from the defaults, review the "Guidelines for Configuring TLS Settings" in this topic.

  1. Open Settings and tap Security options.
    • If you are connected to a remote desktop or published application in full-screen mode, tap the Horizon Client Tools radial menu icon and tap the gear icon to access Settings.
    • If you are not using full-screen mode, tap Settings in the menu in the upper-right corner of the Horizon Client toolbar.
    • If you are not connected to a server, tap the Settings (gear) icon in the upper-right corner of the Horizon Client window.
  2. Tap Advanced Security Options.
  3. Verify that Use Default Settings is deselected.
  4. To activate or deactivate a security protocol, tap the check box next to the security protocol name.
  5. To change the cipher control string, replace the default string.
  6. Under Configures to check the revocation status of the server certificate, select one of the following options:
    • Will not connect to servers when the server certificate is revoked or unable to determine revocation status. Note that "unable to determine revocation status" includes but is not limited to the network issue that the client cannot reach the CRL endpoints. This option is the strictest certificate check of the three options.
    • Will not connect to servers when the server certificate is revoked. With this option, if unable to determine revocation status, the client can also connect to the servers.
    • Will not check certificate revocation status. Note that this option is hidden if CC Mode is enabled.
  7. Use the Configures Signature Algorithms setting to configure the Signature Algorithms Extension in the Client Hello message of the TLS handshake.
  8. Use the Configure Supported Groups setting to configure the Supported Groups Extension in the Client Hello message of the TLS handshake.
  9. (Optional) To revert to the default settings, tap to select the Use Default Settings option.
  10. To save your changes, tap OK.

Your changes take effect the next time you connect to the server.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…