Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Network & Time Sync & Environment & Certificates

RTS
Lite
CTS
ETS
eCTS
Here you will find technical requirements and instructions for configuring your network environment to ensure stable app performance. This information is useful for both end users and network administrators.

Network Configuration

For the app to work on client devices, access to network resources must be provided (e.g.,
RTS
,
CTS
, calls server, etc.).


If your devices or network are managed by an organization, contact your organization’s support or system administrator for assistance with access permissions.
For Administrators: About Network Accesses for Clients & Servers, Traffic Inspection
  • If traffic inspection or filtering systems (NGFW, DPI, proxy) are used in the infrastructure, WebSocket connections must be allowed.
  • Additionally, VPN tunnel configuration, WAF rules, or proxy server settings may be required.
  • Depending on the application's architecture and the specifics of the organization's network infrastructure, the list of necessary access permissions may expand—it is recommended to consult the project documentation and test the connection in an isolated environment before deployment.

Common Issues with Traffic Inspection

What is configured How it manifests What to do
NGFW or DPI drops long-lived connections The app periodically shows Connecting, messages arrive with delay, the session drops Allow WebSocket, increase the idle TCP session timeout for eXpress traffic
TLS inspection with certificate substitution (MITM), including on DLP systems Connection errors and certificate errors, on Android — SSL error Add eXpress addresses to inspection exclusions or install the corporate root certificate on devices — learn more. The Android app uses only built-in and system certificates
WAF in front of the corporate server Some app requests are rejected with server errors Configure WAF rules for the app API, allow WebSocket upgrade
Proxy server with authentication The app doesn't connect The app does not support proxies with username and password — learn more
Media traffic is routed through inspection Calls fail to establish or drop Media traffic cannot be inspected — it is end-to-end encrypted. Exclude connections to the Media server from inspection
For more details about the required network access on the client and server side, see the networking guides (in Russian).
For Administrators: Network Requirements

Client-Server Channel Requirements

Activity Consumed Traffic
Messages2 kbit/s per user
Files100 kbit/s per user

Call and Conference Requirements

Bandwidth calculation for calls and conferences:

Traffic Formula
Incoming traffic 1.5 Mbps × number of participants
Outgoing traffic Depends on the call type:
  • Video mosaic: 140 kbps × number of tiles (max. 20)
  • Audio: 16 kbps
  • Screen sharing: from 30-50 kbps (static content) to 2 Mbps (dynamic content)

Minimum Requirements for SIP Voice Calls: 16 kbps per participant.

Recommended Network Ping

Activity Recommended Ping
Calls and conferences No more than 100 ms
Messages and files No more than 150 ms

When these values are significantly exceeded, the app may be unable to connect to the server — for example, when using satellite internet.

Client Device Bandwidth Requirements

Platform Average Traffic
PCOutgoing: 1.5 mbit/s
Incoming: 2 mbit/s
Mobile DevicesOutgoing: 1.5 mbit/s
Incoming: 1.6 mbit/s

Does the App Work When the Mobile Network in Russia Is in Whitelist Mode?

  • For
    RTS
    and
    Lite
    — yes, as these servers are included in the whitelists.
  • For
    CTS
    ,
    ETS
    /
    eCTS
    — check with your organization's support.

Where App Traffic Goes

The app uses not one connection but several independent ones. Based on what exactly stopped working, you can immediately determine which access is blocked.

What doesn't work Which connection is responsible What to check
The app doesn't connect, endless Connecting, chats and contacts don't update Client → corporate server
CTS
/
eCTS
via HTTPS and WebSocket
Whether the traffic inspection system blocks WebSocket; in the browser — access to the local network
Chats and files work, but calls and conferences don't: the call doesn't connect, there is no audio or video, participants get dropped Client → Media server, separate ports, primarily via UDP Whether the media server ports are open including UDP; whether UDP passes through the VPN tunnel — see VPN
The web app doesn't open Client → web client server via HTTPS Availability of the web app address (https://corp.express/ or your organization's address)
Files from external users don't arrive Client → cloud file storage for public users Access to the cloud — learn more
Captcha verification fails when requesting an SMS code Client → Captcha services Access to verification services, see the access list
Links to chats and calls don't open Client → short link service Access to the link service (or to your own link server)
The desktop app can't find updates Client → update server Access to the update server (for the
ETS
app — to your own)
For specific ports and addresses that need to be opened, see the list of network accesses and the networking guides.
For Administrators: Web App and Front CTS / Back CTS Topology
CTS
ETS
eCTS

Messaging and media data from the web app go directly to the corporate server and the Media server, so the web app requires exactly the same network accesses as the desktop app, plus access to the web client address.


In a split deployment, the corporate server is published externally through Front CTS, and the media service is located next to it, so the client always retrieves media data from the Front, not from the closed network segment. Network connectivity matrices by deployment topology:

Proxy Server

The app supports operation through an open proxy server configured in the network properties on a mobile device and a PC. The desktop app uses the system proxy settings of the operating system. Settings specified inside the browser and group proxy policies for browsers do not apply to the desktop app.

Can I Use Proxies That Require Login?

Proxy servers with authentication are not supported by the app itself. If such a proxy is used on your network, contact your network administrator — it may be necessary to use it as a system proxy, or configure an exception for eXpress traffic, or use an open proxy.

Open Proxy Server Configuration for Desktop App

  1. Close the desktop app.
  2. Launch the app via terminal or command line:
    "app_path" "--proxy-server=IP:port"
  3. It is recommended to create a shortcut to launch the desktop app with a proxy.
    For example, on Windows: "C:\Program Files\eXpress\eXpress.exe" "--proxy-server=192.168.1.1:8080"

How to Launch the Desktop App Bypassing the Proxy?

If the eXpress servers are on an internal network and no proxy is needed to access them, the app can be launched with the parameter --no-proxy-server. With it, the app does not use system proxy settings and connects to servers directly.

"C:\Program Files\eXpress\eXpress.exe" --no-proxy-server

This same method is a convenient way to check whether the proxy is to blame. If with this parameter the app connects immediately, but without it remains in the Connecting... state, the cause is proxying — check the exception list.

To the Administrator: What Proxy Settings the Desktop App Uses and How to Set Exceptions on Windows

The desktop application takes proxy settings from Windows system parameters, not from the browser. If exceptions for eXpress servers are specified only in the browser proxy group policy, the app will not see them and will continue to access the servers through the proxy. Set these exceptions in Windows system proxy settings: Internet Options > the Connections tab > LAN settings > Advanced, in the field Do not use proxy server for addresses beginning with.

What Windows Parameters Does the App Read?

The parameters are taken from the registry branch HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

Value ProxyEnable What the app uses
1 — proxy is set manually Proxy address from ProxyServer and exception list from ProxyOverride. The automatic configuration script AutoConfigURL is not applied in this case.
0 — proxy is not set manually Automatic configuration script (PAC file) from AutoConfigURL if it is specified.
⚠️ The app behaves this way starting with version 3.62. In earlier versions, the automatic configuration scenario was applied at any value of ProxyEnable.

How to Write an Exception so That It Works.

The exception is compared with the host name that the app is accessing. It must either match this name exactly, or be a subdomain mask with an asterisk.

Record in the exceptions list What does it cover? Will work for the node cts.example.ru
cts.example.ru Only the node with this name Yes
*.example.ru All nodes in the domain example.ru Yes
example.ru Only the node named example.ru is covered; subdomains are not. Not available
cts Only the node named cts Not available
⚠️ A common reason exceptions do not work is a short server name instead of the full name. The record cts does not cover the node cts.example.ru, and the record example.ru does not cover its subdomains. Specify full names of eXpress servers or a mask of the form *.example.ru.

If the Exceptions Are Set Correctly, but the App Still Does Not Connect.

Check the following.

  • Does the list of exceptions at the time of the failure match the one you see after the connection is restored? If multiple policies with proxy settings are applied to a computer, immediately after startup the policy that doesn't have the required exceptions may take effect, and later the correct one will override it. Capture the proxy settings at the exact moment when the app cannot connect.
  • Is the certificate being replaced by an antivirus or traffic inspection tool? When substitution occurs, the app does not trust the connection, even if the proxy exceptions are set correctly. See. “Manage certificates”.
  • Isn't the list of addresses allowed on the proxy too narrow? If only CTS server addresses are open, the app will connect, but some features will not work — for example, link preview. The list of required accesses is in the network access list.
  • Does the proxy require authentication? The app does not support a proxy with a login and password prompt: you cannot connect through such a proxy, see the question above.

You can verify that the issue is indeed the proxy by launching the application with the parameter --no-proxy-server.

VPN

When connecting to the network through VPN services, message delivery delays, call drops, and server connection errors may occur. It is recommended not to use a VPN with the app, or to add eXpress to the exception list (split tunneling) of your VPN client, or to contact your organization's support for a correct corporate VPN client configuration.

⚠️ If you work in the web app, an enabled VPN additionally changes browser behavior: server addresses become local network addresses, and the browser starts requesting separate permission to access them. This is a common reason why “everything works in the office, but not over VPN.” See “Browser Restrictions in the Web App”.
For Administrators: What Are the Limitations When Routing All eXpress Traffic Through a VPN Tunnel?

eXpress has no technical restrictions on using VPN. However, in practice, performance depends heavily on the VPN channel's bandwidth and the specifics of network protocols. Experience shows that routing all traffic, including media data, through VPN can lead to call quality issues. It is recommended to avoid routing traffic through VPN to ensure stable operation.

What Must Reach the Servers Through the Tunnel

If traffic is still routed through VPN, it is not enough to allow only HTTPS to the corporate server — otherwise messaging will work, but calls will not. Connections to the Media server, including UDP, must also pass through the tunnel. For the list of ports, see the list of network accesses and the networking guides.

Common Reasons Why Media Traffic Does Not Pass Through VPN

Reason What to do
The tunnel works only over TCP (for example, a TLS tunnel on port 443), UDP is not transmitted Either route media traffic outside the tunnel, or enable the Allow TCP ICE setting in the VoEx section of the admin panel — learn more. Note that TCP for media provides worse quality than UDP
The UDP port range of the media server is not fully open Open the entire range — it is used for SRTP streams
Direct peer-to-peer (p2p) connection between clients is blocked, and TURN is not used Enable the Use relay ICE candidates only setting in the VoEx section — all media traffic will go through the TURN server
Reduced MTU in the tunnel, UDP packet fragmentation Check MTU and MSS clamping settings on the VPN gateway. Symptom: the call connects, but audio and video break up or work only in one direction
Double NAT (corporate NAT over provider NAT, CGNAT) Verify correct NAT IP-to-IP mapping for the Media server and external addresses in TURN/STUN settings

Browser Restrictions in the Web App

The web app operates according to browser rules, not operating system rules. Even if all network accesses are open, the browser may block some connections. The most common restriction is local network access.

What Is Local Network Access and Why Does It Interfere?

Modern browsers consider it dangerous when a website from the internet accesses devices inside your network and require separate permission for this. The rule is triggered by the destination address: if the site is opened via a public address but accesses a private address (10.x.x.x, 172.16–31.x.x, 192.168.x.x), localhost, or a domain in the .local zone — the browser shows a permission prompt, and if denied, drops the connection.


For eXpress, this looks like this: the web app is opened via a public address (for example, https://corp.express/), while the corporate server and Media server are located in your organization's network. This leads to the following typical symptoms:

  • everything works in the office or from home, but not when the corporate VPN is enabled (over VPN, server addresses become private);
  • chats work, but calls and conferences don't connect or have no audio or video;
  • the web app doesn't connect at all and endlessly shows “Connecting”;
  • the desktop app on the same computer and in the same network works fine.
If the desktop app works but the web app doesn't under the same network conditions, it's almost always due to browser restrictions, not the network.

How to Grant Local Network Access Permission

You can wait for the browser prompt when opening the web app and click Allow. If the prompt was already denied, grant the permission manually and reload the page:

Browser How to grant permission
Google Chrome, Chromium, Microsoft Edge, Yandex Browser, Vivaldi, Opera Click the site settings icon to the left of the address bar > Site settings (in Microsoft Edge — Permissions for this site) > allow Local network (in Yandex Browser — Access to local network) > reload the page
Mozilla Firefox Click the padlock icon to the left of the address bar > Permissions > allow Local network devices. All granted permissions are listed under Settings > Privacy & Security > Permissions
Apple Safari There is no separate site prompt. On macOS, check the system permission: System Settings > Privacy & Security > Local Network
⚠️ On macOS, there are two independent permissions: a system one (for the entire browser, in the Local Network section of privacy settings) and a site permission inside the browser. Safari obtains the system permission automatically; other browsers need it to be granted manually. Check both.

Other Browser Settings That Affect Operation

  • Check other browser permissions — microphone, camera, notifications, clipboard, autoplay in Safari — and ad-blocking extensions: they are listed in the system requirements for the web app.
  • Do not use incognito mode or private windows for regular work: some permissions and session data are not preserved in them.
For Administrators: Centralized Local Network Access Deployment (Policies)

Relying on each user to respond correctly to the browser prompt is not advisable: the denial is remembered, and no error message is shown. The permission can be distributed via group policies.

Chromium-Based Browsers

The policy is called LocalNetworkAccessAllowedForUrls, type — list of strings. It contains the source addresses, that is, the eXpress web app address, not the server addresses.

Browser Windows: registry key Linux: policies directory
Google Chrome HKLM\SOFTWARE\Policies\Google\Chrome\LocalNetworkAccessAllowedForUrls /etc/opt/chrome/policies/managed/
Chromium HKLM\SOFTWARE\Policies\Chromium\LocalNetworkAccessAllowedForUrls DEB or RPM package (Astra Linux, RED OS, and others): /etc/chromium/policies/managed/
⚠️ Snap package (how Chromium is installed by default in Ubuntu): /var/snap/chromium/current/policies/managed/. Files in /etc are ignored in this case
Microsoft Edge HKLM\SOFTWARE\Policies\Microsoft\Edge\LocalNetworkAccessAllowedForUrls /etc/opt/edge/policies/managed/
Yandex Browser HKLM\SOFTWARE\Policies\YandexBrowser\LocalNetworkAccessAllowedForUrls /etc/opt/yandex/browser/policies/managed/
Vivaldi HKLM\SOFTWARE\Policies\Vivaldi\LocalNetworkAccessAllowedForUrls /etc/vivaldi/policies/managed/
Opera Not supported: policies are not applied on Windows. The permission is granted manually by the user /etc/opt/opera/policies/managed/

Each address in the Windows registry is a separate string value (REG_SZ) with a numeric name. Example:

reg add "HKLM\SOFTWARE\Policies\Google\Chrome\LocalNetworkAccessAllowedForUrls" /v 1 /t REG_SZ /d "https://corp.express" /f

Example for Linux — file /etc/opt/chrome/policies/managed/express.json:

{
  "LocalNetworkAccessAllowedForUrls": ["https://corp.express"]
}

On macOS, the same policy is distributed via a configuration profile for the preference domains com.google.Chrome, com.microsoft.Edge, and similar.

You can verify that the policy has been applied on the browser's internal page: chrome://policy, edge://policy, browser://policy, vivaldi://policy. The policy should be displayed with the status OK and indicate the source — the directory or registry key from which it was read.

Mozilla Firefox

The policy LocalNetworkAccess is used with an array of exceptions SkipDomains. The policies.json file:

{
  "policies": {
    "LocalNetworkAccess": {
      "SkipDomains": ["corp.express"],
      "Locked": true
    }
  }
}

The same via Windows group policies:

Software\Policies\Mozilla\Firefox\LocalNetworkAccess\SkipDomains\1 = "corp.express"
The pattern *.corp.express includes both the domain itself and all subdomains. An entry without *. applies only to an exact match.

Apple Safari

There is no per-site local network access policy. Management is possible only at the macOS level — through the permission in the Local Network section of privacy settings, which Safari obtains automatically.

Temporarily Disabling Checks

While the infrastructure is not ready and the permission has not been distributed, checks can be disabled entirely — both centrally for all browsers in the organization and manually on a single computer for diagnostics. This should be an emergency measure, not a permanent setting.

Browser Centrally (for administrators) Manually on a single instance
Chrome, Edge, Yandex Browser, Vivaldi The same registry key or policies directory as for LocalNetworkAccessAllowedForUrls above — add the LocalNetworkAccessRestrictionsTemporaryOptOut parameter (REG_DWORD on Windows, boolean on macOS and Linux) with the value 1 / true chrome://flags/#local-network-access-check > select Disabled and restart the browser.
In Edge — edge://flags/..., in Yandex Browser — browser://flags/..., in Vivaldi — vivaldi://flags/...
Opera On Windows, it cannot be distributed centrally; on Linux — the same policies directory as above. opera://flags/#local-network-access-check > Disabled
Mozilla Firefox The same policies.json file as above — the LocalNetworkAccess policy with the parameter "Enabled": false disables all checks completely about:config > parameter network.lna.enabled > false
Apple Safari Not applicable — WebKit has not yet implemented local network access restrictions, so there is nothing to disable

The value 1 / true for LocalNetworkAccessRestrictionsTemporaryOptOut does not just hide the warning: it disables the blocking of local network requests itself — instead of blocking, the browser only outputs a warning in the developer console when a potential violation occurs.

⚠️ This policy itself is also temporary: according to current plans, Google will remove it from Chrome after version 156. It was created as an emergency valve during migration, not a permanent solution — it should not be kept enabled on all workstations permanently. The long-term way to lift the restriction for a specific site is LocalNetworkAccessAllowedForUrls.

What to Consider for the Future

  • The restriction is gradually being extended to more connection types. Initially it affected regular requests to the server, then WebSocket connections, and application to WebRTC is in development. When that happens, media connections will also stop working directly without the granted permission.
  • The restriction does not apply if the web app itself is opened via an address within your network. If the organization deploys its own instance of the web app in a closed network segment, the problem does not arise.
  • The restriction is determined by the destination IP address, not by the domain name. The same web app address may require permission in one network and not in another — this is expected behavior.

Time Synchronization Setup

For the application to work correctly, the time must be synchronized both on user devices and on servers. If the time is out of sync, sign-in errors, incorrect message timestamps, and a user status displayed with a future time are possible.

How Do I Customize the Time on My Device?

Turn on automatic date, time, and time zone: steps for each platform are in the table below. After that, you don’t need to log out or reinstall the app.

  • If the app did not let you log in, try logging in again. If that doesn’t work, restart the app and try again.
  • If you are already logged in, restart the app: on your phone, swipe it from the list of open apps; in the web and desktop apps, press Ctrl (Cmd) + R.
Platform Steps
Windows Open Settings > Time & Language > Date & Time. Turn on Set time automatically and Set time zone automatically, then click Sync now.
macOS Open System Preferences > General > Date & Time. Turn on Set date and time automatically and Set time zone automatically.
Linux Turn on automatic time synchronization in your desktop settings (date and time section). If there is no such setting, run sudo timedatectl set-ntp true in the terminal and check the result with the command timedatectl status: in the System clock synchronized line, there should be yes.
Android Turn on automatic date, time, and time zone in system settings.
iOS/iPadOS Turn on automatic time setting in the system settings. If it is already enabled, turn it off and turn it on again.
Aurora Turn on automatic date and time in system settings.

If after that the time on the device still differs from the actual time, contact your organization's Support: on the corporate network, the source of accurate time may be set by policies.

For Administrators: Time Synchronization on Servers
CTS
eCTS

On platform servers, time is synchronized by the NTP client chrony. Installation and configuration are described in the operating system preparation sections: Astra Linux, RED OS, Ubuntu and Debian.


If your company has its own exact time sources, specify them in the chrony configuration instead of the pool line and restart the service. You can check which sources the server is connected to with the chronyc sources -v command.

Remote Desktop & Virtual Desktop

When using VDI (such as VMware Horizon or Citrix) or connecting via the RDP protocol, preliminary configuration is required.

If you encounter performance or display issues with the desktop app in a VDI environment, try changing the performance settings.

Why Do I Have to Sign In to the App Again After Ending a VDI Session?

The sign-in screen may appear again because VDI provides a new empty browser profile or a new user folder the next time the user connects. The solution is to configure folder persistence between VDI sessions.

For Administrators: Configure Folder Persistence in VDI Sessions

You need to configure the persistence of browser and application profile folders between VDI sessions. Otherwise, users will have to sign in to the application again each time they reconnect through VDI.

⚠️ Before doing this, make sure that VDI is not configured to issue random desktops to users from a pool, otherwise folder persistence will not work at all.
OS Folders
Windows
  • Google Chrome: %LOCALAPPDATA%\Google\Chrome\User Data\Default and the %LOCALAPPDATA%\Google\Chrome\User Data\Local State file
  • Mozilla Firefox: the entire %APPDATA%\Mozilla\Firefox folder (the root of this folder contains profiles.ini and installs.ini — without them, the browser creates a new empty profile)
  • Microsoft Edge: %LOCALAPPDATA%\Microsoft\Edge\User Data\Default and the %LOCALAPPDATA%\Microsoft\Edge\User Data\Local State file
  • Opera: %APPDATA%\Opera Software\Opera Stable\Default and the %APPDATA%\Opera Software\Opera Stable\Local State file
  • Yandex Browser: %LOCALAPPDATA%\Yandex\YandexBrowser\User Data\Default and the %LOCALAPPDATA%\Yandex\YandexBrowser\User Data\Local State file
  • Desktop app: %AppData%\eXpress and %AppData%\Microsoft\Credentials and %LocalAppData%\Microsoft\Vault
macOS
  • Google Chrome: ~/Library/Application Support/Google/Chrome/Default
  • Mozilla Firefox: the entire ~/Library/Application Support/Firefox/ folder (including profiles.ini) and ~/Library/Caches/Firefox/Profiles/
  • Microsoft Edge: ~/Library/Application Support/Microsoft Edge/Default
  • Opera: ~/Library/Application Support/com.operasoftware.Opera/Default
  • Yandex Browser: ~/Library/Application Support/Yandex/YandexBrowser/Default
  • Safari: ~/Library/Safari/ and ~/Library/Containers/com.apple.Safari/Data/Library/
  • Keychain (it stores cookie encryption keys): ~/Library/Keychains/login.keychain-db
  • Desktop app: ~/Library/Application Support/eXpress
Linux
  • Google Chrome: ~/.config/google-chrome/Default
  • Chromium — the path depends on the installation method:
    • DEB/RPM package: ~/.config/chromium/Default
    • snap (default in Ubuntu): ~/snap/chromium/common/chromium/Default
  • Mozilla Firefox — the path depends on the installation method:
    • DEB/RPM package: ~/.mozilla/firefox/
    • snap (default in Ubuntu): ~/snap/firefox/common/.mozilla/firefox/
    • flatpak: ~/.var/app/org.mozilla.firefox/.mozilla/firefox/
    Persist the entire folder, including the profiles.ini file.
  • Microsoft Edge: ~/.config/microsoft-edge/Default
  • Opera: ~/.config/opera/Default
  • Yandex Browser: ~/.config/yandex-browser/Default
  • Keyring (it stores cookie encryption keys): ~/.local/share/keyrings/
  • Desktop app: ~/.config/eXpress
In the paths above, Default is the default browser profile folder. If a user works in a different profile, specify that folder instead: it is named Profile 1, Profile 2, and so on (for Firefox — (<random_code>).default(-release)). The exact path is visible in the browser itself on the chrome://version page (in Yandex Browser — browser://version) in the Profile Path field. A profile named Default might not exist at all.
Data must be copied and restored when the browser is closed.
If persisting the entire profile folder is not possible (for example, the size of the roaming profile is limited), the minimum required set within it is:
  • IndexedDB — required: this is where the eXpress web app stores the session. It is not stored in cookies; the server does not set them at all.
  • Local Storage — required along with IndexedDB: without it, the saved session will be considered outdated.
  • Network (Windows only) — cookies for other sites.
  • Local State in the root of the browser folder (Windows only) — the key used to encrypt cookies.
The Cache, Code Cache, and Service Worker folders do not need to be persisted: they will be repopulated, but they account for the bulk of the profile size — several gigabytes.
The Network subfolder within the profile exists only for Chromium-based browsers on Windows. On macOS and Linux, the same browsers store the cookies file directly in the profile folder.
The cookie encryption key is stored separately from the profile: on Windows — in the Local State file, on macOS — in the Keychain, on Linux — in GNOME Keyring or KWallet. If the profile folder is persisted without them, cookies cannot be decrypted.
You can verify the result in the browser: F12 > Application > IndexedDB > there should be an authState database with non-empty storage.

Calls and Conferences via VDI/RDP

Why do calls via VDI work worse than on a physical computer?

⚠️ We cannot guarantee that audio/video calls will work correctly over VDI, and the following recommendations may not help in all cases. Developers are continuing to optimize app performance in VDI environments.
For Administrators: Blocking Calls in VDI for the Desktop App If your VDI environment does not support calls, you can forcibly disable them in the application. The application does not always correctly detect a VDI environment, so this mode must be set separately:
Desktop Platform Steps
Windows
  • Add Vdi="true" to AppConfig.ini in the application folder, under the [AppConfig] section, and restart the application.
  • There is also a special MSI installation key.
macOS
  1. Add Vdi="true" to AppConfig.json in the folder /Users/username/Library/Application Support/app_name:
    {
    "Vdi": true
    }
  2. Restart the application.
    Linux
    1. Add Vdi="true" to AppConfig.json in the folder /home/username/.config/app_name:
      {
      "Vdi": true
      }
    2. Restart the application.
      Requires version 3.64 or higher. After enabling, when attempting to call, the user will see a notification “Calls are not available on this device” or “Conferences are not available on this device”.
      For Administrators: Configure Sound in VMware Remote Console

      You can use VMware Remote Console to add and remove sound cards on Windows and Linux Horizon virtual machines. To add a sound card:

      1. Go to the required virtual machine in VMware Remote Console and open its settings:
        • In Windows, select VMRC > Manage > Virtual Machine Settings.
        • In Linux, select Virtual Machine > Virtual Machine Settings.
      2. Open the Hardware tab and click Add.
      3. Select Sound Card and click the Finish button.

      Configure Sound in the VMware Horizon Client

      In the Horizon client settings, you need to select specific audio and video input/output devices. If you don't do this, some devices might not work in the desktop application.


      How to select devices:

      1. In the VMware Horizon client, select Settings.
      2. In the Real-Time Audio-Video section, instead of All in the fields, select the devices that will be used for communication.

      Select devices in the settings of the desktop application installed on the virtual machine:

      1. Microphone: Microphone array (VMware Virtual Microphone).
        You might need to switch to another device and then select this one again for it to work (the indicator "comes alive").
      2. Output device: Specify the default device used in the system.
      3. Camera: There might be several options, but only one will work.
      For Administrators: Configure Sound on the RDP Server (Windows)

      In the Group Policy Editor under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection, enable the following policies:

      • Allow audio and video playback redirection
      • Allow audio recording redirection

      Configure Sound in the RDP Client

      For sound to work in conferences when connecting via RDP, allow access to your computer's audio devices in the connection settings:

      OS and Client Steps
      Windows
      (Remote Desktop Connection)
      1. 1. In the connection properties, on the Local Resources tab, in the Remote Desktop Audio group, click the Settings button.
      2. 2. In the Sound Playback group, select Play on this computer; in the Sound Recording group, select Record from this computer.
      macOS
      (Microsoft Remote Desktop)
      1. 1. In the remote computer properties, open the Devices & Audio tab.
      2. 2. Select the Microphone checkbox and choose On this computer for the Play sound parameter.
      Linux
      (Remmina)
      1. 1. Create or open a saved connection.
      2. 2. On the Settings tab, find the Sound group.
      3. 3. For Output Sound, select Locally.
      4. 4. For Input Sound, select Local Microphone.

      Certificate Management

      CTS
      ETS
      eCTS
      Additional SSL certificate management may be required for corporate users only if their organization uses its own corporate certificates — their installation and renewal are handled through their organization's support. Users of the public server or corporate users who do not use custom corporate certificates do not need to do anything — the necessary standard certificates are already installed on the servers and are embedded in the app and operating systems.
      For Administrators: About SSL Certificates & Diagnostics
      CTS
      ETS
      eCTS

      Client Certificates

      Most corporate servers use standard certificates included in popular client operating systems, which do not require manual installation. When using organization's own certificates, install the certificate in the device's OS.

      The Android app only supports system certificates and certificates built into the app itself (starting from app version 3.24). Therefore, the organization's custom certificate will need to be “embedded” into the app (this is typically done on request by developers for ETS branded apps).

      Server Certificates

      Installation instructions: administrator documentation.

      Certificate Verification

      Refer to SSL Certificates Diagnostics.


      Ministry of Digital Development National Certification Authority Certificates

      CTS
      ETS
      eCTS

      If your organization's server has switched to a TLS certificate from the Ministry of Digital Development National Certification Authority (Russian Trusted Root CA and Russian Trusted Sub CA), some devices will require manual installation of this authority's certificates — otherwise the app will not be able to connect to the server.


      Whether any action is needed depends on the operating system:

      Platform What to do
      Russian operating systems:
      Astra Linux, RED OS, Aurora
      Russian browsers:
      Yandex Browser, Chromium GOST, Atom

      No action needed. The Ministry of Digital Development certificates are included in the operating system or browser, and the app uses them.

      Android

      No action needed. Starting from version 3.24, the app uses developer-built-in certificates — the Ministry of Digital Development certificates are among them.

      ETS

      Exception — branded ETS apps and builds with SSL Pinning: their built-in certificate set may differ, and after the server switches to the Ministry of Digital Development certificates, the app stops connecting for all employees at once. This is resolved on the build side — contact your organization's support.


      ⚠️ If your organization's server uses a certificate from a different certification authority whose root is not built into the app, the connection on Android will not work: installing the certificate in the system on versions 3.24 and later has no effect. In this case, contact your organization's support — the issue is resolved on the app build side.

      Windows

      Install both certificates manually following the instructions.

      macOS

      Install both certificates manually and be sure to enable trust for them following the instructions.

      iOS / iPadOS

      Install both certificates manually and enable trust for them following the instructions.

      Other Linux:
      Debian, Ubuntu, Linux Mint, and derivatives

      Install both certificates manually. ⚠️ On these systems, installing the certificate in the system-wide store is not enough for the desktop app — see the instructions.

      After installing the certificates, fully quit the app and start it again. On Windows, macOS, and Linux, the app keeps running in the background after the window is closed — close it using the icon in the notification area (system tray).

      Where to Get Ministry of Digital Development Certificates

      The root and intermediate certificates are published on the Gosuslugi portal: gosuslugi.ru/crt. Both are needed.

      If the organization's server uses a regular (non-GOST) certificate, take the non-GOST option. GOST certificates require a separate cryptographic provider on each device and are not suitable here.

      For Administrators: How to Verify the Result and Mass Deployment

      How to Check That the Server Has Switched to Ministry of Digital Development Certificates

      Open a link like https://your_server_address/system/settings/version in the browser and check the certificate details using the padlock icon in the address bar. The issuer field will show Russian Trusted Sub CA.


      If the browser reports that the certificate is untrusted, the Ministry of Digital Development certificates have not yet been installed on this device.

      Yandex Browser, Chromium GOST, and “Atom” have Russian CA certificates built in, including those of the Ministry of Digital Development, so they cannot be used to check whether the certificates are installed in the system. In addition, if Kaspersky antivirus or other security software is installed on the PC, their certificate may be displayed instead of the server certificate.

      Mass Deployment

      On Windows, certificates are distributed via group policies to the local computer store. On macOS and iOS — only through a mobile device management (MDM) system or a configuration profile: only the user at the computer can manually set trust for a certificate — this cannot be done by script or remotely.