You can select the security protocols and cryptographic algorithms that are used to encrypt communications between Horizon Client and Horizon servers and between Horizon Client and the agent in the remote desktop.

By default, TLSv1.0, TLSv1.1, and TLSv1.2 are enabled. SSL v2.0 and 3.0 are not supported. The default cipher control string is "!aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES".

If you configure a security protocol for Horizon Client that is not enabled on the Horizon server to which the client connects, a TLS/SSL error occurs and the connection fails.

For information about configuring the security protocols that are accepted by Connection Server instances, see the View Security document.


  1. Tap Settings at the bottom of the Horizon Client screen.
  2. Tap Advanced SSL Options.
  3. Make sure that the Reset to Default Settings option is set to off.
  4. To enable or disable a security protocol, tap the On or Off toggle next to the security protocol name.
  5. To change the cipher control string, replace the default string.
  6. (Optional) If you need to revert to the default settings, tap Reset in the upper right corner of the screen.


Your changes take effect the next time you connect to the server.