To use the derived credentials feature, you must create a virtual smart card to use when you log in to a server and connect to a remote desktop. One virtual smart card can hold multiple certificates.
Prerequisites
- Verify that the client device, remote desktops, RDS hosts, Connection Server host, and other Horizon components meet the smart card authentication requirements. See Smart Card Authentication Requirements.
- Verify that the device has a passcode. A passcode is required to create a virtual smart card.
- Use VMware Workspace ONE PIV-D Manager for iOS v22.10 or later, or a third-party mobile app such as Purebred to issue the certificate to the client device, create a derived credential and provision the credential on the client device.
If you are using Workspace ONE PIV-D Manager, you must meet these requirements:
- VMware Workspace ONE PIV-D Manager for iOS v22.10 and later.
- Devices with iOS 14 or later and iPadOS 14 or later.
- Persistent tokens enabled. To do this:
- Create a local text file named
config.txt
. - Add this line to the file and save it:
EnablePersistentTokens=True
. - Sync this file to the public folder for Horizon Client for iOS using Finder. (Horizon Client for iOS has published its Document directory).
- Create a local text file named
- Set the following Application Configuration on Workspace ONE UEM when sending Derived Credentials from the Console to iOS Devices. For details on
PersistentTokenExtensionAllowed
,UserPresenceProtection
, andPIVDPromptForPIN
and how to set them, see: Send Derived Credentials from the Console to iOS Devices in the Workspace ONE PIV-D Manager guide.- Required: Set
PersistentTokenExtensionAllowed
toTrue
to enable the Persistent token extension. This allows PIV-D Manager to act as a CTK Provider. - Optional: Set
UserPresenceProtection
andPIVDPromptForPIN
toFalse
and enable SSO to avoid redundant authentication.
- Required: Set