Vmware – Horizon Client for Android – User Manual

Category: Software and Application User Guides and Manuals

Download user manual for Vmware – Horizon Client for Android – User Manual 
Preview: Below is a preview of the manual as extracted from the PDF file


Using VMware Horizon Client for
Android
September 2014
VMware Horizon
This document supports the version of each product listed and
supports all subsequent versions until the document is
replaced by a new edition. To check for more recent editions
of this document, see http://www.vmware.com/support/pubs.
EN-001480-01Using VMware Horizon Client for Android
2 VMware, Inc.
You can find the most up-to-date technical documentation on the VMware Web site at:
http://www.vmware.com/support/
The VMware Web site also provides the latest product updates.
If you have comments about this documentation, submit your feedback to:
docfeedback@vmware.com
Copyright
©
2011–2014 VMware, Inc. All rights reserved. Copyright and trademark information.
VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
www.vmware.comContents
Using VMware Horizon Client for Android 5

1 Setup and Installation 7
System Requirements 7
Preparing View Connection Server for Horizon Client 8
Smart Card Authentication Requirements 9
Configure Smart Card Authentication for Mobile Clients 10
Using Embedded RSA SecurID Software Tokens 11
Configure Advanced SSL Options 12
Supported Desktop Operating Systems 13
Configure the Client Download Links Displayed in View Portal 5.2 and Earlier Releases 13
Install or Upgrade Horizon Client for Android 14
Horizon Client Data Collected by VMware 15

2 Using URIs to Configure Horizon Client 19
Syntax for Creating vmware-view URIs 19
Examples of vmware-view URIs 21

3 Managing Remote Desktop and Application Connections 23
Connect to a Remote Desktop or Application for the First Time 23
Certificate Checking Modes for Horizon Client 25
Create a Desktop or Application Shortcut for the Android Home Screen 26
Manage Server Shortcuts 26
Select a Favorite Remote Desktop or Application 27
Disconnecting from a Remote Desktop or Application 28
Log Off from a Remote Desktop 28
Manage Desktop and Application Shortcuts 29

4 Using a Microsoft Windows Desktop or Application on a Mobile Device 31
Feature Support Matrix 31
Input Devices, Keyboards, and Keyboard Settings 32
Enable the Japanese 106/109 Keyboard Layout 33
Using the Unity Touch Sidebar with a Remote Desktop 33
Using the Unity Touch Sidebar with a Remote Application 36
Horizon Client Tools 37
Gestures 39
Multitasking 40
Saving Documents in a Remote Application 40
Screen Resolutions and Using External Displays 41
PCoIP Client-Side Image Cache 41
Internationalization and International Keyboards 42
VMware, Inc. 3
5 Troubleshooting Horizon Client 43
Collecting and Sending Logging Information 43
Enable Horizon Client Log Collection 43
Manually Retrieve and Send Horizon Client Log Files 44
Disable Horizon Client Log Collection 44
Reset a Remote Desktop or Application 45
Uninstall Horizon Client 45
Horizon Client Stops Responding or the Remote Desktop Freezes 46
Problem Establishing a Connection When Using a Proxy 46
Index 47
Using VMware Horizon Client for Android
4 VMware, Inc.Using VMware Horizon Client for Android
This guide, Using VMware Horizon Client for Android, provides information about installing and using
VMware Horizon™ Client™ software on an Android device to connect to a remote desktop or application
in the datacenter.
The information in this document includes system requirements and instructions for installing
Horizon Client for Android. This document also provides tips for improving the user experience of
navigating and using Windows desktop elements on an Android device.
This information is intended for administrators who must set up a View deployment that includes Android
client devices. The information is written for experienced system administrators who are familiar with
virtual machine technology and datacenter operations.
VMware, Inc. 5Using VMware Horizon Client for Android
6 VMware, Inc.Setup and Installation 1
Setting up a View deployment for Android clients involves using certain View Connection Server
configuration settings, meeting the system requirements for View servers and Android device clients, and
installing the VMware View app.
This chapter includes the following topics:
n “System Requirements,” on page 7
n “Preparing View Connection Server for Horizon Client,” on page 8
n “Smart Card Authentication Requirements,” on page 9
n “Configure Smart Card Authentication for Mobile Clients,” on page 10
n “Using Embedded RSA SecurID Software Tokens,” on page 11
n “Configure Advanced SSL Options,” on page 12
n “Supported Desktop Operating Systems,” on page 13
n “Configure the Client Download Links Displayed in View Portal 5.2 and Earlier Releases,” on
page 13
n “Install or Upgrade Horizon Client for Android,” on page 14
n “Horizon Client Data Collected by VMware,” on page 15
System Requirements
You can install Horizon Client on many Android devices.
The Android device on which you install Horizon Client, and the peripherals it uses, must meet certain
system requirements.
Operating systems
n Android 2.3.3 (Gingerbread)
n Android 3 (Honeycomb)
n Android 4 (Ice Cream Sandwich)
n Android 4.1, 4.2, and 4.3 (Jelly Bean)
n Android 4.4 (KitKat)
CPU architecture
n ARM
n x86
VMware, Inc. 7External keyboards (Optional) Bluetooth and docked keyboard devices. For information about
the devices that your specific device supports, see the documentation from
the device manufacturer.
Smart cards See “Smart Card Authentication Requirements,” on page 9.
View Connection
Server, Security Server,
and View Agent
Latest maintenance release of View 4.6.x and later releases.
VMware recommends that you use a security server so that your device will
not require a VPN connection.
The Unity Touch feature requires View 5.2 and later servers and desktops
and the Remote Experience Agent must be installed on the desktop.
Remote applications are available only on Horizon 6.0 with View servers.
Display protocol for
View
PCoIP
Preparing View Connection Server for Horizon Client
Administrators must perform specific tasks to enable end users to connect to remote desktops and
applications.
Before end users can connect to View Connection Server or a security server and access a remote desktop or
application, you must configure certain pool settings and security settings:
n If you are using a security server, as VMware recommends, verify that you are using the latest
maintenance releases of View Connection Server 4.6.x and View Security Server 4.6.x or later releases.
See the View Installation document.
n If you plan to use a secure tunnel connection for client devices and if the secure connection is
configured with a DNS host name for View Connection Server or a security server, verify that the client
device can resolve this DNS name.
To enable or disable the secure tunnel, in View Administrator, go to the Edit View Connection Server
Settings dialog box and use the check box called Use secure tunnel connection to desktop.
n Verify that a desktop or application pool has been created and that the user account that you plan to use
is entitled to access the pool. For View Connection Server 5.3 and earlier, see the topics about creating
desktop pools in the View Administration document. For View Connection Server 6.0 and later, see the
topics about creating desktop and application pools in the Setting Up Desktop and Application Pools in
View document.
n To use two-factor authentication with Horizon Client, such as RSA SecurID or RADIUS authentication,
you must enable this feature on View Connection Server. RADIUS authentication is available with View
5.1 or later View Connection Server. For more information, see the topics about two-factor
authentication in the View Administration document.
n To allow end users to save their passwords with Horizon Client, so that users do not always need to
supply credentials when connecting to a remote desktop or application, configure the policy for this
feature on View Connection Server.
This feature is available when connecting to View Connection Server 5.1 or later . Users can save their
passwords if the policy is configured to allow it and if Horizon Client can fully verify the server
certificate that View Connection Server presents. For instructions about configuring this policy, see the
topic called “Allow Users to Save Credentials” in the chapter called “Setting Up User Authentication,” in
the View Administration document.
n Verify that the desktop or application pool is set to use the PCoIP display protocol. For View
Connection Server 5.3 and earlier, see the View Administration document. For View Connection Server
6.0 and later, see the Setting Up Desktop and Application Pools in View document.
Using VMware Horizon Client for Android
8 VMware, Inc.Smart Card Authentication Requirements
Client systems that use a smart card for user authentication must meet certain requirements.
Horizon Client for Android supports using smart cards with remote desktops that have Windows XP,
Windows Vista, or Windows 7 guest operating systems. VMware recommends using an Android 4.0 or later
operating system. The CPU architecture must be ARM. The baiMobile 3000MP Bluetooth Smart Card reader
and baiMobile 301MP USB Smart Card reader (Horizon Client 3.1 and later) were tested with the following
smart cards:
n Oberthur ID One V5.2a DOD CAC card
n Gemalto TOPDLGX4 DOD CAC card
n ActivIdentity 64K V2C Java Card
n Gemalto ID Prime .NET (formerly .NET V2+ Orange)
Each client system that uses a smart card for user authentication must have the following software and
hardware:
n Horizon Client
n A Windows-compatible smart card reader
n Smart card middleware
The app on the Android device must support your baiMobile smart card reader. One such app is
baiMobile PCSC-Lite, whose tile name on Android devices is baiMobile PC/SC. Version 5.13 contains
support for both the baiMobile 3000MP Bluetooth and baiMobile 301MP USB smart card readers. For
example, without such an app, you can pair the Bluetooth card reader with the Android device, but you
cannot connect it. To make a connection, the app sends a connection request to the reader, and you
must tap the OK button on the reader to establish the Bluetooth connection.
n Product-specific application drivers
You must also install product-specific application drivers on the remote desktops. For example, the
following drivers were tested: ActiveClient6.2.0.50, ActivClient_7.0.1, and Gemalto.MiniDriver.NET.inf.
View supports smart cards and smart card readers that use a PKCS#11 or Microsoft CryptoAPI provider.
You can optionally install the ActivIdentity ActivClient software suite, which provides tools for interacting
with smart cards.
Users that authenticate with smart cards must have a smart card, and each smart card must contain a user
certificate.
To install certificates on a smart card, you must set up a computer to act as an enrollment station. This
computer must have the authority to issue smart card certificates for users, and it must be a member of the
domain you are issuing certificates for.
IMPORTANT When you enroll a smart card, you can choose the key size of the resulting certificate. To use
smart cards with local desktops, you must select a 1024-bit or 2048-bit key size during smart card
enrollment. Certificates with 512-bit keys are not supported.
The Microsoft TechNet Web site includes detailed information on planning and implementing smart card
authentication for Windows systems.
Chapter 1 Setup and Installation
VMware, Inc. 9In addition to meeting these requirements for Horizon Client systems, other View components must meet
certain configuration requirements to support smart cards:
n For information about configuring View servers to support smart card use, see the topic “Configure
Smart Card Authentication,” in the View Administration document.
IMPORTANT Smart cards are supported only with View 5.1.3 and 5.2 or later servers and desktops.
n For information about tasks you might need to perform in Active Directory to implement smart card
authentication, see the topics about preparing Active Directory for smart card authentication, in the
View Installation document .
Configure Smart Card Authentication for Mobile Clients
Configuration tasks include connecting and pairing the card reader with the mobile device and setting the
smart card removal policy.
Prerequisites
n Verify that you are using the correct version of the client, desktop agent, server, mobile device
operating system, smart card reader, and smart card. See “Smart Card Authentication Requirements,”
on page 9.
n Verify that smart card middleware is installed on the Android device.
n If you have not already done so, perform the tasks described in “Prepare Active Directory for Smart
Card Authentication,” in the View Installation document.
n Configure View servers to support smart card use. See the topic “Configure Smart Card
Authentication,” in the View Administration document.
Procedure
1 Install the smart card middleware app on the mobile device.
2 Pair the mobile device with the smart card reader, according to the documentation provided by the
manufacturer of the reader.
If you are using a Bluetooth smart card reader, a randomly generated number is displayed on both
devices during this process. When you confirm that the numbers match, you establish secure Bluetooth
communication.
Using VMware Horizon Client for Android
10 VMware, Inc.3 Configure the smart card removal policy.
Option Description
Set the policy on the server If you use View Administrator to set a policy, the choices are to disconnect
users from View Connection Server when they remove their smart cards or
to keep users connected to the desktop while locking the desktop screen.
In View Administrator, go to View Configuration > Servers > View
Connection Server (Edit) > Authentication > Smart card authentication >
Smart card removal policy.
If you select the Disconnect user sessions on smart card removal option in
View Administrator, what happens when a user unplugs a smart card
reader after logging in to a desktop depends on the View version running
on the server. For Horizon 6.0 with View, Horizon Client returns to the
remote desktop and application selection screen and the user can log into
the desktop again without reauthenticating. For View 5.3 and earlier, the
user must reauthenticate to log into the desktop again.
Set the policy on the desktop If you use the Group Policy Editor (gpedit.msc) you have four possible
settings: no action, lock workstation, force log off, or Disconnect if a
Remote Desktop Services session.
After you open gpedit.msc in the desktop operating system, go to
Windows settings > Security settings > Local policies > Security options >
Interactive logon: smart card removal behavior.

Using Embedded RSA SecurID Software Tokens
If you create and distribute RSA SecurID software tokens to end users, they need enter only their PIN, rather
than PIN and token code, to authenticate.
Setup Requirements
You can use Compressed Token Format (CTF) or dynamic seed provisioning, which is also called CT-KIP
(Cryptographic Token Key Initialization Protocol), to set up an easy-to-use RSA authentication system. With
this system, you generate a URL to send to end users. To install the token, end users paste this URL directly
into Horizon Client on their client devices. The dialog box for pasting this URL appears when end users
connect to View Connection Server with Horizon Client.
Horizon Client for Android also supports file-based provisioning. When a file-based software token is
issued to a user, the authentication server generates an XML-format token file, which is called an SDTID file
for its .sdtid extension. Horizon Client can import the SDTID file directly. Users can also launch
Horizon Client by tapping the SDTID file in a file browser.
After the software token is installed, end users enter a PIN to authenticate. With external RSA tokens, end
users must enter a PIN and the token code generated by a hardware or software authentication token.
The following URL prefixes are supported if end users will be copying and pasting the URL into
Horizon Client when Horizon Client is connected to an RSA-enabled View Connection Server:
n viewclient-securid://
n http://127.0.0.1/securid/
End users can install the token by tapping the URL. Both prefixes viewclient-securid:// and
http://127.0.0.1/securid/ are supported. Note that not all browsers support hyperlinks that begin with
http://127.0.0.1. Also some file browsers, such as the File Manager app on the ASUS Transformer Pad,
cannot link the SDTID file with Horizon Client.
For information about using dynamic seed provisioning or file-based (CTF) provisioning, see the Web page
RSA SecurID Software Token for iPhone Devices at http://www.rsa.com/node.aspx?id=3652 or RSA SecurID
Software Token for Android at http://www.rsa.com/node.aspx?id=3832.
Chapter 1 Setup and Installation
VMware, Inc. 11Instructions to End Users
When you create a CTFString URL or CT-KIP URL to send to end users, you can generate a URL with or
without a password or activation code. You send this URL to end users in an email that must include the
following information:
n Instructions for navigating to the Install Software Token dialog box.
Tell end users to tap External Token in the Horizon Client dialog box that prompts them for RSA
SecurID credentials when they connect to View Connection Server.
n CTFString URL or CT-KIP URL in plain text.
If the URL has formatting on it, end users will get an error message when they try to use it in
Horizon Client.
n Activation code, if the CT-KIP URL that you create does not already include the activation code.
End users must enter this activation code in a text field of the dialog box.
n If the CT-KIP URL includes an activation code, tell end users that they need not enter anything in the
Password or Activation Code text box in the Install Software Token dialog box.
Configure Advanced SSL Options
You can select the security protocols that Horizon Client can use. You can also specify the cipher control
string.
Prerequisites
Verify the security protocol that the View server can use. If you configure a security protocol for
Horizon Client that is not enabled on the View server to which the client connects, an SSL error occurs and
the connection fails. For information about configuring the security protocols that are accepted by View
Connection Server instances, see the View Security document.
Horizon Client and View Connection Server support TLS v1.0 and TLS v1.1 by default. You should change
the security protocols in Horizon Client only if your View administrator instructs you to do so, or if your
View server does not support the current settings.
Procedure
1 Use the Horizon Client interface tools to display General Settings.
If you are using full-screen mode, tap the Horizon Client Tools icon and tap the settings icon. If you are
not using full-screen mode, tap the Settings icon in the upper-right corner of the screen.
2 Tap Advanced SSL Options.
3 Make sure that Use Default Settings is unchecked.
4 To enable or disable a security protocol, tap the check box next to the security protocol name.
TLS v1.0 and TLS v1.1 are enabled by default.
5 To change the cipher control string, replace the default string in the text box.
The default cipher control string (AES:!aNULL:@STRENGTH) includes cipher suites that use either 128-
bit or 256-bit AES encryption, except for anonymous DH algorithms, and sorts them by strength.
6 (Optional) If you need to revert to the default settings, tap to select the Use Default Settings option.
7 Tap OK to save your changes.
Your changes take effect the next time you connect to View Connection Server.
Using VMware Horizon Client for Android
12 VMware, Inc.Supported Desktop Operating Systems
Administrators create virtual machines with a guest operating system and install View Agent in the guest
operating system. End users can log in to these virtual machines from a client device.
For a list of the supported guest operating systems, see the “Supported Operating Systems for View Agent”
topic in the View 4.6., 5.x, or 6.x installation documentation.
Configure the Client Download Links Displayed in View Portal 5.2 and
Earlier Releases
If you use View Connection Server 5.2 or an earlier release, and you do not have HTML Access installed, by
default, when you open a browser and enter the URL of a View Connection Server instance, the portal page
that appears contains links to the VMware Download site for downloading Horizon Client. You can change
the default.
The default Horizon Client links on the portal page ensure that you are directed to the latest compatible
Horizon Client installers. In some cases, however, you might want to have the links point to an internal Web
server, or you might want to make specific client versions available on your own View Connection Server.
You can reconfigure the page to point to a different URL.
When you make links for Mac OS X, Linux, and Windows client systems, the correct operating system
specific link is shown on the portal page. For example, if you browse to the portal page from a Windows
system, only the link or links for Windows installers appear. You can make separate links for 32-bit and 64-
bit installers. You can also make links for iOS and Android systems, but these operating systems are not
automatically detected, so that if you browse to the portal page from an iPad, for example, you see the links
for both iOS and Android, if you created links for both.
IMPORTANT If you customize the portal page links, as described in this topic, and later install HTML Access
or View Connection Server 6.0 or a later release on the server, your customized portal page is replaced by a
VMware Horizon Web portal page, and an icon for using HTML Access is added. For information about
customizing that page, see Using HTML Access or see the View Upgrades 6.0 or later document.
Prerequisites
n Download the installer files for the Horizon Client types that you want to use in your environment. The
URL to the client download page is https://www.vmware.com/go/viewclients.
n Determine which HTTP server will host the installer files. The files can reside on a View Connection
Server instance or on another HTTP server.
Procedure
1 On the HTTP server where the installer files will reside, create a folder for the installer files.
For example, to place the files in a downloads folder on the View Connection Server host, in the default
installation directory, use the following path:
C:Program FilesVMwareVMware ViewServerrokerwebappsdownloads
The links to the files would then use URLs with the format https://server-name/downloads/client-
installer-file-name. For example, a server with the name view.mycompany.com might use the following
URL for Horizon Client for Windows: https://view.mycompany.com/downloads/VMware-Horizon-
Client.exe. In this example, the folder named downloads is located in the webapps root folder.
2 Copy the installer files into the folder.
If the folder resides on View Connection Server, you can replace any files in this folder without having
to restart the VMware View Connection Server service.
Chapter 1 Setup and Installation
VMware, Inc. 133 On the View Connection Server machine, copy the portal-links.properties file and the
portal.properties file located in install-pathServerExtrasPortalExamples.
4 Create a portal folder the directory C:ProgramDataVMwareVDM, and copy the portal-
links.properties and portal.properties files into the portal folder.
5 Edit the C:ProgramDataVMwareVDMportalportal-links.properties file to point to the new location
of the installer files.
You can edit the lines in this file and add to them if you need to create more links. You can also delete
lines.
The following examples show properties for creating two links for Horizon Client for Windows and
two links for Horizon Client for Linux:
link.win=https://server-name/downloads/VMware-Horizon-Client-x86_64-y.y.y-XXXX.exe#win
link.win.1=https://server-name/downloads/VMware-Horizon-Client-y.y.y-XXXX.exe#win
link.linux=https://server-name/downloads/VMware-Horizon-Client-y.y.y-XXXX.i386.rpm#linux
link.mac=https://server-name/downloads/VMware-Horizon-Client-y.y.y-XXXX.dmg#mac
In this example, y.y.y-XXXX indicates the version and build number. The win text at the end of the line
indicates that this link should appear in the browser if the client has a Windows operating system. Use
win for Windows, linux for Linux, and mac for Mac OS X. For other operating systems, use unknown.
6 Edit the C:ProgramDataVMwareVDMportalportal.properties file to specify the text to display for the
links.
These lines appear in the section of the file called # keys based on key names in portal-
links.properties.
The following example shows the text that corresponds to the links specified for link.win and
link.win.1:
text.win=Horizon Client for Windows 32-bit client users
text.win.1=Horizon Client for Windows 64-bit client users
7 Restart the VMware View Connection Server service.
When end users enter the URL for View Connection Server, they see links with the text you specified. The
links point to the locations you specified.
Install or Upgrade Horizon Client for Android
Horizon Client for Android is an Android app, and you install it just as you do other Android apps.
Prerequisites
n If you have not already set up the device, do so. See the manufacturer`s user`s guide for your device.
n Verify that you have the URL for a download page that contains the Horizon Client installer. This URL
might be the VMware Downloads page at http://www.vmware.com/go/viewclients.
n Become familiar with your device`s procedure for installing apps.
Devices from different manufacturers use different methods for installing Android apps. See the
manufacturer`s user`s guide for your device. Depending on the device, you might have to perform the
following tasks before you can install an app:
n Install a particular driver.
n Install a file browser.
Using VMware Horizon Client for Android
14 VMware, Inc.Procedure
1 Browse to the URL for downloading the Horizon Client app, or search for the Horizon Client app in the
Google Play Store or Amazon Appstore for Android.
For some devices, you download the file to the device. For others, you download the file to a PC or a
USB device.
2 If necessary, copy the app (.apk file) to your device.
3 Install the app according to your device`s customary procedure for installing apps.
For example, on some devices, you must tap the file to install it.
4 To determine that installation succeeded, verify that the VMware View (Horizon Client 3.0) or Horizon
(Horizon Client 3.1) app icon appears on one of the desktops of your Home screen.
Horizon Client Data Collected by VMware
If your company participates in the customer experience improvement program, VMware collects data from
certain Horizon Client fields. Fields containing sensitive information are made anonymous.
NOTE This feature is available only if your View deployment uses View Connection Server 5.1 or later.
VMware collects data on the clients to prioritize hardware and software compatibility. If your company`s
administrator has opted to participate in the customer experience improvement program, VMware collects
anonymous data about your deployment in order to improve VMware`s response to customer requirements.
No data that identifies your organization is collected. Horizon Client information is sent first to View
Connection Server and then on to VMware, along with data from View servers, desktop pools, and remote
desktops.
Although the information is encrypted while in transit to View Connection Server, the information on the
client system is logged unencrypted in a user-specific directory. The logs do not contain any personally
identifiable information.
The administrator who installs View Connection Server can select whether to participate in the VMware
customer experience improvement program while running the View Connection Server installation wizard,
or an administrator can set an option in View Administrator after the installation.
Table 1 ‑1. Data Collected from Horizon Clients for the Customer Experience Improvement Program
Description
Is This Field
Made
Anonymous
? Example Value
Company that produced the
Horizon Client application
No VMware
Product name No VMware Horizon Client
Client product version No (The format is x.x.x-yyyyyy, where x.x.x is the client version
number and yyyyyy is the build number.)
Client binary architecture No Examples include the following:
n i386
n x86_64
n arm
Chapter 1 Setup and Installation
VMware, Inc. 15Table 1‑1. Data Collected from Horizon Clients for the Customer Experience Improvement Program
(Continued)
Description
Is This Field
Made
Anonymous
? Example Value
Client build name No Examples include the following:
n VMware-Horizon-View-Client-Win32-Windows
n VMware-Horizon-View-Client-Linux
n VMware-Horizon-View-Client-iOS
n VMware-Horizon-View-Client-Mac
n VMware-Horizon-View-Client-Android
n VMware-Horizon-View-Client-WinStore
Host operating system No Examples include the following:
n Windows 8.1
n Windows 7, 64-bit Service Pack 1 (Build 7601 )
n iPhone OS 5.1.1 (9B206)
n Ubuntu 10.04.4 LTS
n Mac OS X 10.8.5 (12F45)
Host operating system kernel No Examples include the following:
n Windows 6.1.7601 SP1
n Darwin Kernel Version 11.0.0: Sun Apr 8 21:52:26 PDT
2012; root:xnu-1878.11.10~1/RELEASE_ARM_S5L8945X
n Darwin 11.4.2
n Linux 2.6.32-44-generic #98-Ubuntu SMP Mon Sep 24
17:27:10 UTC 2012
n unknown (for Windows Store)
Host operating system architecture No Examples include the following:
n x86_64
n i386
n armv71
n ARM
Host system model No Examples include the following:
n Dell Inc. OptiPlex 960
n iPad3,3
n MacBookPro8,2
n Dell Inc. Precision WorkStation T3400 (A04 03/21/2008)
Host system CPU No Examples include the following:
n Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GH
n Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GH
n unknown (for iPad)
Number of cores in the host system`s
processor
No For example: 4
MB of memory on the host system No Examples include the following:
n 4096
n unknown (for Windows Store)
Number of USB devices connected No 2 (USB device redirection is supported only for Linux,
Windows, and Mac OS X clients.)
Maximum concurrent USB device
connections
No 2
Using VMware Horizon Client for Android
16 VMware, Inc.Table 1‑1. Data Collected from Horizon Clients for the Customer Experience Improvement Program
(Continued)
Description
Is This Field
Made
Anonymous
? Example Value
USB device vendor ID No Examples include the following:
n Kingston
n NEC
n Nokia
n Wacom
USB device product ID No Examples include the following:
n DataTraveler
n Gamepad
n Storage Drive
n Wireless Mouse
USB device family No Examples include the following:
n Security
n Human Interface Device
n Imaging
USB device usage count No (Number of times the device was shared)
Chapter 1 Setup and Installation
VMware, Inc. 17Using VMware Horizon Client for Android
18 VMware, Inc.Using URIs to Configure
Horizon Client 2
Using uniform resource identifiers (URIs), you can create a Web page or an email with links that end users
click to launch Horizon Client, connect to View Connection Server, and launch a specific desktop or
application with specific configuration options.
You can simplify the process of connecting to a remote desktop or application by creating Web or email
links for end users. You create these links by constructing URIs that provide some or all of the following
information, so that your end users do not need to supply it:
n View Connection Server address
n Port number for View Connection Server
n Active Directory user name
n RADIUS or RSA SecurID user name, if different from Active Directory user name
n Domain name
n Desktop or application display name
n Actions including reset, log off, and start session
To construct a URI, you use the vmware-view URI scheme with Horizon Client specific path and query parts.
NOTE You can use URIs to launch Horizon Client only if the client software is already installed on end
users` client computers.
This chapter includes the following topics:
n “Syntax for Creating vmware-view URIs,” on page 19
n “Examples of vmware-view URIs,” on page 21
Syntax for Creating vmware-view URIs
Syntax includes the vmware-view URI scheme, a path part to specify the desktop or application, and,
optionally, a query to specify desktop or application actions or configuration options.
URI Specification
Use the following syntax to create URIs for launching Horizon Client:
vmware-view://[authority-part][/path-part][?query-part]
VMware, Inc. 19The only required element is the URI scheme, vmware-view. For some versions of some client operating
systems, the scheme name is case-sensitive. Therefore, use vmware-view.
IMPORTANT In all parts, non-ASCII characters must first be encoded according to UTF-8 [STD63], and then
each octet of the corresponding UTF-8 sequence must be percent-encoded to be represented as URI
characters.
For information about encoding for ASCII characters, see the URL encoding reference at
http://www.utf8-chartable.de/.
authority-part Specifies the server address and, optionally, a user name, a non-default port
number, or both. Note that underscores (_) are not supported in server
names. Server names must conform to DNS syntax.
To specify a user name, use the following syntax:
user1@server-address
Note that you cannot specify a UPN address, which includes the domain. To
specify the domain, you can use the domainName query part in the URI.
To specify a port number, use the following syntax:
server-address:port-number
path-part Specifies the desktop or application. Use the desktop display name or
application display name. This name is the one specified in View
Administrator when the desktop or application pool was created. If the
display name has a space in it, use the %20 encoding mechanism to represent
the space.
query-part Specifies the configuration options to use or the desktop or application
actions to perform. Queries are not case-sensitive. To use multiple queries,
use an ampersand (&) between the queries. If queries conflict with each
other, the last query in the list is used. Use the following syntax:
query1=value1[&query2=value2…]
Supported Queries
This topic lists the queries that are supported for this type of Horizon Client. If you are creating URIs for
multiple types of clients, such as desktop clients and mobile clients, see the Using VMware Horizon Client
guide for each type of client system.
action
Table 2 ‑1. Values That Can Be Used with the action Query
Value Description
browse Displays a list of available desktops and applications hosted on the
specified server. You are not required to specify a desktop or
application when using this action.
If you use the browse action and specify a desktop or application,
the desktop or application is highlighted in the list of available
items.
start-session Launches the specified desktop or application. If no action query is
provided and the desktop or application name is provided,
start-session is the default action.
Using VMware Horizon Client for Android
20 VMware, Inc.Table 2‑1. Values That Can Be Used with the action Query (Continued)
Value Description
reset Shuts down and restarts the specified desktop. Unsaved data is
lost. Resetting a remote desktop is the equivalent of pressing the
Reset button on a physical PC. Specifying an application is not
supported. If you specify an application, an error message appears.
In Horizon Client 3.1, if you do not specify a desktop or
application, Horizon Client quits all remote applications.
logoff Logs the user out of the guest operating system in the remote
desktop. If you specify an application, the action will be ignored or
the end user will see the warning message “Invalid URI action.”
domainName The domain associated with the user who is connecting to the remote
desktop or application.
tokenUserName Specifies the RSA or RADIUS user name. Use this query only if the RSA or
RADIUS user name is different from the Active Directory user name. If you
do not specify this query and RSA or RADIUS authentication is required, the
Windows user name is used. The syntax is tokenUserName=name.
Examples of vmware-view URIs
You can create hypertext links or buttons with the vmware-view URI scheme and include these links in email
or on a Web page. Your end users can click these links to, for example, launch a particular remote desktop
with the startup options you specify.
URI Syntax Examples
Each URI example is followed by a description of what the end user sees after clicking the URI link.
1 vmware-view://view.mycompany.com/Primary%20Desktop?action=start-session
Horizon Client is launched and connects to the view.mycompany.com server. The login box prompts the
user for a user name, domain name, and password. After a successful login, the client connects to the
desktop whose display name is displayed as Primary Desktop, and the user is logged in to the guest
operating system.
NOTE The default display protocol and window size are used. The default display protocol is PCoIP.
The default window size is full screen.
2 vmware-view://view.mycompany.com:7555/Primary%20Desktop
This URI has the same effect as the previous example, except that it uses the nondefault port of 7555 for
View Connection Server. (The default port is 443.) Because a desktop identifier is provided, the desktop
is launched even though the start-session action is not included in the URI.
3 vmware-view://fred@view.mycompany.com/Finance%20Desktop?desktopProtocol=PCoIP
Horizon Client is launched and connects to the view.mycompany.com server. In the login box, the User
name text box is populated with the name fred. The user must supply the domain name and password.
After a successful login, the client connects to the desktop whose display name is displayed as Finance
Desktop, and the user is logged in to the guest operating system. The connection uses the PCoIP
display protocol.
4 vmware-view://fred@view.mycompany.com/Finance%20Desktop?domainName=mycompany
Chapter 2 Using URIs to Configure Horizon Client
VMware, Inc. 21Horizon Client is launched and connects to the view.mycompany.com server. In the login box, the User
name text box is populated with the name fred, and the Domain text box is populated with
mycompany. The user must supply only a password. After a successful login, the client connects to the
desktop whose display name is displayed as Finance Desktop, and the user is logged in to the guest
operating system.
5 vmware-view://view.mycompany.com/
Horizon Client is launched, and the user is taken to the login prompt for connecting to the
view.mycompany.com server.
6 vmware-view://view.mycompany.com/Primary%20Desktop?action=reset
Horizon Client is launched and connects to the view.mycompany.com server. The login box prompts the
user for a user name, domain name, and password. After a successful login, Horizon Client displays a
dialog box that prompts the user to confirm the reset operation for Primary Desktop. After the reset
occurs, depending on the type of client, the user might see a message indicating whether the reset was
successful.
NOTE This action is available only if the View administrator has enabled this feature for end users.
7 vmware-view://view.mycompany.com?action=reset
Horizon Client is launched and connects to the view.mycompany.com server. The login box prompts the
user for a user name, domain name, and password. After a successful login, Horizon Client displays a
dialog box that prompts the user to confirm the reset operation for all remote applications. After the
reset occurs, the user sees a message that indicates whether the reset was successful.
8 vmware-view://
If the client is already running, the Horizon Client app comes to the foreground. If the client is not
already running, Horizon Client is launched and the user sees the Recent Connections list, the Servers
list, or the Welcome page, depending on whether the user has ever used Horizon Client on the device
and whether the client has previously connected to a server or a remote desktop.
HTML Code Examples
You can use URIs to make hypertext links and buttons to include in emails or on Web pages. The following
examples show how to use the URI from the first URI example to code a hypertext link that says, Test Link,
and a button that says, TestButton.


Test
Link



Using VMware Horizon Client for Android
22 VMware, Inc.Managing Remote Desktop and
Application Connections 3
Use Horizon Client to connect to View Connection Server or a security server, edit the list of servers you
connect to, log in to or off of remote desktops, and use remote applications. For troubleshooting purposes,
you can also reset remote desktops and applications.
Depending on how the administrator configures policies for remote desktops, end users might be able to
perform many operations on their desktops.
This chapter includes the following topics:
n “Connect to a Remote Desktop or Application for the First Time,” on page 23
n “Certificate Checking Modes for Horizon Client,” on page 25
n “Create a Desktop or Application Shortcut for the Android Home Screen,” on page 26
n “Manage Server Shortcuts,” on page 26
n “Select a Favorite Remote Desktop or Application,” on page 27
n “Disconnecting from a Remote Desktop or Application,” on page 28
n “Log Off from a Remote Desktop,” on page 28
n “Manage Desktop and Application Shortcuts,” on page 29
Connect to a Remote Desktop or Application for the First Time
To connect to a remote desktop or application, you must provide the name of a View server and supply
credentials for your user account.
To use remote applications, you must connect to View Connection Server 6.0 or later.
NOTE Before you have end users access their remote desktops, test that you can log in to a remote desktop
from a client device.
Prerequisites
n Obtain the credentials you need to log in, such as a user name and password, RSA SecurID user name
and passcode, RADIUS authentication user name and passcode, or smart card personal identification
number (PIN).
n Obtain the domain name for logging in.
n Perform the administrative tasks described in “Preparing View Connection Server for Horizon Client,”
on page 8.
VMware, Inc. 23n If you are outside the corporate network and are not using a security server to access the remote
desktop, verify that your client device is set up to use a VPN connection and turn that connection on.
IMPORTANT VMware recommends using a security server rather than a VPN.
If your company has an internal wireless network to provide routable access to remote desktops that
your device can use, you do not have to set up a View security server or VPN connection.
n Verify that you have the fully qualified domain name (FQDN) of the server that provides access to the
remote desktop or application. Note that underscores (_) are not supported in server names. You also
need the port number if the port is not 443.
n If you plan to use embedded RSA SecurID software, verify that you have the correct CT-KIP URL and
activation code. See “Using Embedded RSA SecurID Software Tokens,” on page 11.
n Configure the certificate checking mode for the SSL certificate presented by View Connection Server.
See “Certificate Checking Modes for Horizon Client,” on page 25.
Procedure
1 Tap the VMware View (Horizon Client 3.0) or Horizon (Horizon Client 3.1) app icon on the Home
screen.
2 Connect to a View server.
Option Action
Horizon Client 3.0 Tap Add Server, type the name of a View server, and tap Connect.
Horizon Client 3.1 Type the name of a View server, type a description (optional), and tap
Connect.

Connections between Horizon Client and View servers always use SSL. The default port for SSL
connections is 443. If the View server is not configured to use the default port, use the format shown in
this example: view.company.com:1443.
3 If a smart card is required or optional, select the smart card certificate to use and enter your PIN.
If your smart card has only one certificate, that certificate is already selected. If there are many
certificates, you can scroll through them if necessary.
4 If you are prompted for RSA SecurID credentials or RADIUS authentication credentials, either enter
your credentials or, if you plan to use an embedded RSA SecurID token, install an embedded token.
Option Action
Existing token If you use a hardware authentication token or software authentication
token on a smart phone, enter your user name and passcode. The passcode
might include both a PIN and the generated number on the token.
Install software token Click External Token. In the Install Software Token dialog box, paste the
CT-KIP URL or CTFString URL that your administrator sent to you in
email. If the URL contains an activation code, you do not need to enter
anything in the Password or Activation Code text box.

5 If you are prompted a second time for RSA SecurID credentials or RADIUS authentication credentials,
enter the next generated number on the token.
Do not enter your PIN and do not enter the same generated number entered previously. If necessary,
wait until a new number is generated.
If this step is required, it is required only when you mistype the first passcode or when configuration
settings in the RSA server change.
Using VMware Horizon Client for Android
24 VMware, Inc.6 If prompted, supply Active Directory credentials.
a Type the user name and password of a user who is entitled to use at least one desktop or
application pool.
b Select a domain.
c Tap to select the Save Password check box if your administrator has enabled this feature and if the
server certificate can be fully verified.
If this is the first time you are saving a password, you are prompted to activate the device
administrator, which is required in order to save a password on Android devices.
d Tap Connect.
The desktop and application selector screen appears.
7 Tap a desktop or application to connect to it.
If you are using smart card authentication, you are not prompted to supply your PIN again, but the
login process takes longer than if you use Active Directory authentication.
If you are connecting to a session-based remote desktop, which is hosted on a Microsoft RDS host, and
if the desktop is already set to use the Microsoft RDP display protocol, you will not be able to connect
immediately. You will be prompted to have the system log you off of the remote operating system so
that a connection can be made with the PCoIP display protocol from VMware.
After you connect to a desktop or application for the first time, a shortcut for the desktop or application is
saved to the Recent Connections screen (Horizon Client 3.0) or Recent tab (Horizon Client 3.1). The next
time you want to connect to the remote desktop or application, you can tap the shortcut instead of typing
the server`s name.
Certificate Checking Modes for Horizon Client
Administrators and sometimes end users can configure whether client connections are rejected if any or
some server certificate checks fail.
Certificate checking occurs for SSL connections between View Connection Server and Horizon Client.
Certificate verification includes the following checks:
n Is the certificate intended for a purpose other than verifying the identity of the sender and encrypting
server communications? That is, is it the correct type of certificate?
n Has the certificate expired, or is it valid only in the future? That is, is the certificate valid according to
the computer clock?
n Does the common name on the certificate match the host name of the server that sends it? A mismatch
can occur if a load balancer redirects Horizon Client to a server that has a certificate that does not match
the host name entered in Horizon Client. Another reason a mismatch can occur is if you enter an IP
address rather than a host name in the client.
n Is the certificate signed by an unknown or untrusted certificate authority (CA)? Self-signed certificates
are one type of untrusted CA.
To pass this check, the certificate`s chain of trust must be rooted in the device`s local certificate store.
IMPORTANT For instructions about distributing a self-signed root certificate that users can install on their
Android devices, as well as instructions for installing a certificate on an Android device, see documentation
on the Google Web site, such as the Android 3.0 User`s Guide.
Chapter 3 Managing Remote Desktop and Application Connections
VMware, Inc. 25To set the security mode, tap the Settings icon in the upper-right corner of the Horizon Client screen, tap
General Settings, and tap Security Mode. You have three choices:
n Never connect to untrusted servers. If any of the certificate checks fails, the client cannot connect to the
server. An error message lists the checks that failed.
n Warn before connecting to untrusted servers. If a certificate check fails because the server uses a self-
signed certificate, you can click Continue to ignore the warning. For self-signed certificates, the
certificate name is not required to match the View Connection Server name you entered in
Horizon Client.
n Do not verify server identity certificates. This setting means that View does not perform any certificate
checking.
If the certificate checking mode is set to Warn, you can still connect to a View Connection Server instance
that uses a self-signed certificate.
If an administrator later installs a security certificate from a trusted certificate authority, so that all certificate
checks pass when you connect, this trusted connection is remembered for that specific server. In the future,
if that server ever presents a self-signed certificate again, the connection fails. After a particular server
presents a fully verifiable certificate, it must always do so.
Create a Desktop or Application Shortcut for the Android Home
Screen
You can use a desktop or application shortcut to create a shortcut for your Android Home screen.
NOTE This feature is not available on Kindle Fire devices.
Prerequisites
Connect to the remote desktop or application at least once from the device so that a shortcut for the desktop
or application appears on the Recent Connections screen (Horizon Client 3.0) or Recent tab (Horizon Client
3.1).
If you have not logged in at least once, familiarize yourself with the procedure “Connect to a Remote
Desktop or Application for the First Time,” on page 23.
Procedure
1 On the Recent Connections screen (Horizon Client 3.0) or Recent tab (Horizon Client 3.1), touch and
hold the shortcut.
Add To Home appears at the bottom of the screen.
2 Drag the shortcut to Add To Home.
3 Type a name for the shortcut and tap OK.
If the name is longer than 12 characters, the extra characters do not appear on the Android Home
screen.
Manage Server Shortcuts
After you connect to a server, Horizon Client creates a server shortcut. You can edit and remove server
shortcuts.
Horizon Client saves the server name or IP address in a shortcut, even if you mistype the server name or
type the wrong IP address. You can delete or change this information by editing the server name or IP
address. If you do not type a server description, the server name or IP address becomes the server
description.
Using VMware Horizon Client for Android
26 VMware, Inc.Server shortcuts can appear on multiple pages and you can swipe across pages to see more shortcuts.
Horizon Client creates new pages, as needed, to accommodate all of your server shortcuts.
Procedure
n In Horizon Client 3.0, perform these steps.
a On the Recent Connections screen, tap the Cloud icon in the upper-right corner of the screen.
b Touch and hold a server name or IP address until the context menu appears.
c Use the menu to delete the server or edit the server name, server description, or user name.
n In Horizon Client 3.1, perform these steps.
a On the Servers tab, touch and hold the server shortcut until the context menu appears.
b Use the menu to delete the server or edit the server name, server description, or user name.
Select a Favorite Remote Desktop or Application
You can select remote desktops and applications as favorites. Favorites are identified by a star. The star
helps you quickly find your favorite desktops and applications. Your favorite selections are saved, even
after you log off from the server.
Prerequisites
Obtain the credentials you need to connect to the server, such as a user name and password or RSA SecurID
and passcode.
Procedure
1 Connect to the View server.
Option Description
Horizon Client 3.0 On the Recent Connections screen, tap the Cloud icon in the upper-right
corner and tap the server name.
Horizon Client 3.1 On the Servers tab, tap the server shortcut.

2 If prompted, supply your RSA user name and passcode, your Active Directory user name and
password, or both.
3 Perform these steps to select or deselect a desktop or application as a favorite.
Option Action
Select a favorite Horizon Client 3.0: Touch and hold the desktop or application name until
the context menu appears and tap Mark as Favorite. A star appears in the
upper right corner of the name.
Horizon Client 3.1: Touch and hold the desktop or application name until
the context menu appears and tap Mark as Favorite. A star appears in the
upper right corner of the name and the name appears on the Favorites tab.
Deselect a favorite Horizon Client 3.0: Touch and hold the desktop or application name until
the context menu appears and tap Unmark Favorite.
Horizon Client 3.1: On the All or Favorites tab, touch and hold the desktop
or application name until the context menu appears and tap Unmark
Favorite. A star no longer appears in the upper right corner of the name
and the name disappears from the Favorites tab.

4 (Optional) In Horizon Client 3.1, tap the Favorites tab to display only favorite desktops or applications.
You can tap the All tab to display all the available desktops and applications.
Chapter 3 Managing Remote Desktop and Application Connections
VMware, Inc. 27Disconnecting from a Remote Desktop or Application
You can disconnect from a remote desktop without logging off, so that applications remain open on the
remote desktop. You can also disconnect from a remote application so that the remote application remains
open.
When you are connected to the remote desktop or application and are not using full screen mode, you can
disconnect by tapping the Menu button in the upper-right corner of the screen and selecting Disconnect. If
you are using full screen mode, you can disconnect by tapping the Horizon Client Tools icon and tapping
the Disconnect icon. For pictures of the icons, see “Horizon Client Tools,” on page 37.
NOTE A View administrator can configure your desktop to automatically log off when disconnected. In that
case, any open programs in your desktop are stopped.
Log Off from a Remote Desktop
You can log off from a remote desktop operating system, even if you do not have a desktop open in
Horizon Client.
If you are currently connected to and logged in to a remote desktop, you can use the Windows Start menu
to log off. After Windows logs you off, the desktop is disconnected.
NOTE Any unsaved files that are open on the remote desktop are closed during the logoff operation.
Prerequisites
n Obtain the credentials that you need to log in, such as Active Directory user name and password, RSA
SecurID user name and passcode, or RADIUS authentication user name and passcode.
n If you have not logged in at least once, become familiar with the procedure “Connect to a Remote
Desktop or Application for the First Time,” on page 23.
Procedure
1 Connect to the View server.
Option Description
Horizon Client 3.0 On the Recent Connections screen, tap the Cloud icon in the upper-right
corner and tap the server name.
Horizon Client 3.1 On the Servers tab, tap the server shortcut.

2 If prompted, supply your RSA user name and passcode, your Active Directory user name and
password, or both.
3 Touch and hold the desktop name until the context menu appears.
In Horizon Client 3.1, you can perform this step from either the All or Favorites tab.
4 Tap Log Off in the context menu.
What to do next
Tap the Android Back button or the Disconnect icon in the upper-right corner of the screen and tap Log Out
to disconnect from the server.
Using VMware Horizon Client for Android
28 VMware, Inc.Manage Desktop and Application Shortcuts
After you connect to a remote desktop or application, Horizon Client saves a shortcut for the recently used
desktop or application. You can rearrange and remove these shortcuts.
Desktop and application shortcuts can appear on multiple pages and you can swipe across pages to see
more shortcuts. Horizon Client creates new pages, as needed, to accommodate all of your shortcuts.
Procedure
n Perform these steps to remove a desktop or application shortcut from the Recent Connections screen
(Horizon Client 3.0) or Recent tab (Horizon Client 3.1).
a Touch and hold the shortcut until Remove Shortcut appears at the bottom of the screen.
b Drag the shortcut to Remove Shortcut.
n To move a desktop or application shortcut, touch and hold the shortcut and drag it to the new location.
You cannot drag a shortcut to another page unless that page already exists.
Chapter 3 Managing Remote Desktop and Application Connections
VMware, Inc. 29Using VMware Horizon Client for Android
30 VMware, Inc.Using a Microsoft Windows Desktop
or Application on a Mobile Device 4
On mobile devices, Horizon Client includes additional features to aid in navigation.
This chapter includes the following topics:
n “Feature Support Matrix,” on page 31
n “Input Devices, Keyboards, and Keyboard Settings,” on page 32
n “Enable the Japanese 106/109 Keyboard Layout,” on page 33
n “Using the Unity Touch Sidebar with a Remote Desktop,” on page 33
n “Using the Unity Touch Sidebar with a Remote Application,” on page 36
n “Horizon Client Tools,” on page 37
n “Gestures,” on page 39
n “Multitasking,” on page 40
n “Saving Documents in a Remote Application,” on page 40
n “Screen Resolutions and Using External Displays,” on page 41
n “PCoIP Client-Side Image Cache,” on page 41
n “Internationalization and International Keyboards,” on page 42
Feature Support Matrix
Some features are supported on one type of Horizon Client but not on another.
Table 4‑1. Features Supported on Windows Desktops for Android Horizon Clients
Feature
Windows
8.x Desktop
Windows 7
Desktop
Windows
Vista
Desktop
Windows
XP Desktop
Windows Server
2008 R2 Desktop
RSA SecurID or RADIUS X X X X X
Single sign-on X X X X X
RDP display protocol
PCoIP display protocol X X X X X
USB access
Real-Time Audio-Video (RTAV)
Wyse MMR
Windows 7 MMR
VMware, Inc. 31Table 4‑1. Features Supported on Windows Desktops for Android Horizon Clients (Continued)
Feature
Windows
8.x Desktop
Windows 7
Desktop
Windows
Vista
Desktop
Windows
XP Desktop
Windows Server
2008 R2 Desktop
Virtual printing
Location-based printing X X X X X
Smart cards X X X X X
Multiple monitors
Features that are supported on Windows desktops for Horizon Client for Android have the following
restrictions.
n Windows 8.x desktops are supported only if you have View 5.2 or later servers and desktops.
n Windows Server 2008 R2 desktops are supported only if you have View 5.3 or later servers and
desktops.
n Location-based printing is supported for Windows Server 2008 R2 desktops, RDS desktops (on virtual
machine RDS hosts), and remote applications only in Horizon Client 3.1 and later and Horizon 6.0.1
with View and later servers.
NOTE You can also use Horizon Cl

Leave a Comment