To complete the pairing process, you use the MMC Certificates snap-in to import the Enrollment Service Client certificate into the enrollment server. You must perform this procedure on every enrollment server.
Prerequisites
- Verify that you have a enrollment server. See Install and Set Up an Enrollment Server.
- Verify that you have the correct certificate to import. You can use either your own certificate or the automatically generated, self-signed Enrollment Service Client certificate from one Connection Server in the cluster, as described in Export the Enrollment Service Client Certificate.
Important: To use your own certificates for pairing, place the preferred certificate (and the associated private key) in the custom container (
VMware Horizon View Certificates\Certificates) in the Windows Certificate Store on the Connection Server machine. You must then set the friendly name of the certificate to
vdm.ec.new, and restart the server. The other servers in the cluster will fetch this certificate from LDAP. You can then perform the steps in this procedure.
Procedure
- Copy the appropriate certificate file to the enrollment server machine.
To use the automatically generated certificate:
- Copy the Enrollment Service Client certificate from the Connection Server to the VMware Horizon Enrollment Server Trusted Roots store.
To use your own certificate:
- Copy the Enrollment Service Client certificate from the Connection Server to the VMware Horizon Enrollment Server Trusted Roots store.
- Copy the root certificate that was used to generate the client certificate to the Trusted Root Certification Authorities store on the Enrollment server.
- On the enrollment server, add the Certificates snap-in to MMC:
- Open the MMC console and select
- Under Available snap-ins, select Certificates and click Add.
- In the Certificates snap-in window, select Computer account, click Next, and click Finish.
- In the Add or Remove Snap-in window, click OK.
- In the MMC console, in the left pane, right-click the VMware Horizon Enrollment Server Trusted Roots folder and select .
- In the Certificate Import wizard, follow the prompts to browse to and open the Enrollment Client certificate file.
- Follow the prompts and accept the defaults to finish importing the certificate.
- Right-click the imported certificate and add a friendly name such as vdm.ec (for Enrollment Client certificate).
VMware recommends you use a friendly name that identifies the
Horizon 8 cluster, but you can use any name that helps you easily identify the client certificate.
What to do next
Configure the SAML authenticator used for delegating authentication to VMware Workspace ONE Access. See Configure SAML Authentication to Work with True SSO.