Eugene_K, Server Console says 16.2.4 (Build 19504). And you're right, we are currently using a self-signed certificate. I inherited the setup from my predecesssor and haven't wanted to mess with it until I properly understand what I'm doing. Are you suggesting that replacing the self-signed certificate with a proper SSL certificate might allow us to connect to the Parallels RAS HTML5 with Safari?
The Parallels Client has many excellent features and I use it myself to manage our VM environment more conveniently than the browser login allows (it lets me copy-paste files from my PC to the VM desktop instead of having to use the upload/download widget, for example). Unfortunately, at least in the Windows version, it has a serious security flaw in that if you don't set it to remember your password, it forgets your credentials before you can get in; and having set a password, unless you remember to log out manually, no password is required next time someone opens the client. Our field staff are nurses, not technicians, so for their sake and the security of their patient's personally-identifying info, their end needs to be kept as simple and fail-safe as possible. By making them use the HTML5 RAS browser we can set their browser (Chrome) to forget everything when the window is closed. They then need to log back in next time they open their browser. That sometimes means a bit of cleanup at our end when databases are left running in disconnected sessions, but it's the lesser evil.
We can do that with nurse laptops and phones because we give those devices to the nurses and can control their setup. However, in the case of the iPads, the devices are given to the nurses directly by a company whose products they support, and we have not so far had any say in the setup of those devices. (For example, I just turned the iPad on and brought Safari up and it's still logged into the session I was working with yesterday; nor does there seem to be a setting to tell it to automatically forget cached credentials - the only tool offered is manually clearing cookies or website data through Settings - and from what I read, the alternative, using Private browsing, pretty much stops RAS from working at all.) So we mostly do not have their Apple IDs, passwords, nor, when we do, any means of controlling the setup of the 2-stage verification. A few nurses are technically savvy and can manage that for themselves; the rest, not so much. This makes installing new apps such as the Parallels Client on the devices difficult, as I discovered when I tried downloading Chrome to try to work around Safari.
The nurses see the convenience of being able to enter patient data without having a bulky laptop sitting between them and the patient. We see that too, but we also see the patient privacy nightmare if we can't be confident that patient personally identifying information is secure by default.