Skip to main content

2025 年 6 月 20 日

Using Smart Card Certificate Revocation Checking

You can prevent users who have revoked user certificates from authenticating with smart cards by configuring certificate revocation checking. Certificates are often revoked when a user leaves an organization, loses a smart card, or moves from one department to another.

Omnissa Horizon supports certificate revocation checking with certificate revocation lists (CRLs) and with the Online Certificate Status Protocol (OCSP). A CRL is a list of revoked certificates published by the CA that issued the certificates. OCSP is a certificate validation protocol that is used to get the revocation status of an X.509 certificate.

You can configure certificate revocation checking on an Omnissa Horizon Connection Server instance. The CA must be accessible from the Horizon Connection Server host.

You can configure both CRL and OCSP on the same Horizon Connection Server instance. When you configure both types of certificate revocation checking, attempts to use OCSP first and falls back to CRL if OCSP fails. Omnissa Horizon does not fall back to OCSP if CRL fails.

此页面对您有帮助吗?

对本主题提供反馈

本主题对您有帮助吗?

请勿填写任何个人信息或机密信息。

正在生成链接…