You must download the private key that is associated with the TLS certificate on the intermediate server. The private key must be imported with the certificate into the Horizon 7 servers.


  1. Connect to the intermediate server and find the TLS certificates that are presented to clients sending HTTPS requests.
  2. Find the certificate that is used for Horizon 7 and download its private key.

Example: Download a Private Key from a F5 BIG-IP LTM System

This example uses F5 BIG-IP Local Traffic Manager (LTM) as an intermediate server. The example is intended to give you a general idea of how you might download a private key from your own intermediate server.

Important: These steps are specific to F5 BIG-IP LTM and may not apply to new releases or other F5 products. The steps do not apply to other vendors' intermediate servers.

Before you start, verify that you are connected to the F5 BIG-IP LTM configuration utility.

  1. On the Main tab of the navigation pane, expand Local Traffic and click SSL certificates.

    The utility displays a list of certificates installed on the system.

  2. In the Name column, click the name of the certificate that is used for Horizon 7.
  3. On the menu bar, click Key.
  4. At the bottom of the screen, click Export.

    The utility displays the existing private key in the Key Text box.

  5. From the Key File setting, click Download file_name..

    The private key is downloaded as a KEY file.