To specify a local acceptance policy on an individual View Connection Server instance or security server, you must add properties to the locked.properties file. If the locked.properties file does not yet exist on the View server, you must create it.

You add a secureProtocols.n entry for each security protocol that you want to configure. Use the following syntax: secureProtocols.n=security protocol.

You add an enabledCipherSuite.n entry for each cipher suite that you want to configure. Use the following syntax: enabledCipherSuite.n=cipher suite.

The variable n is an integer that you add sequentially (1, 2, 3) to each type of entry.

Make sure that the entries in the locked.properties file have the correct syntax and the names of the cipher suites and security protocols are spelled correctly. Any errors in the file can cause the negotiation between the client and server to fail.

1

Create or edit the locked.properties file in the SSL gateway configuration folder on the View Connection Server or security server computer.

For example: install_directory\VMware\VMware View\Server\sslgateway\conf\

2

Add secureProtocols.n and enabledCipherSuite.n entries, including the associated security protocols and cipher suites.

3

Save the locked.properties file.

4

Restart the VMware View Connection Server service or VMware View Security Server service to make your changes take effect.

The following example shows the entries in the locked.properties file that are needed to specify the default policies:

# The following list should be ordered with the latest protocol first:

secureProtocols.1=TLSv1.1
secureProtocols.2=TLSv1
secureProtocols.3=SSLv2Hello

# This setting must be the latest protocol given in the list above:

preferredSecureProtocol=TLSv1.1

# The order of the following list is unimportant:

enabledCipherSuite.1=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
enabledCipherSuite.2=TLS_DHE_DSS_WITH_AES_128_CBC_SHA
enabledCipherSuite.3=TLS_DHE_RSA_WITH_AES_128_CBC_SHA
enabledCipherSuite.4=TLS_RSA_WITH_AES_128_CBC_SHA
enabledCipherSuite.5=SSL_RSA_WITH_RC4_128_SHA