When the Workspace ONE Access service is integrated with a validating gateway, such as F5, the Wrap Artifact in JWT setting must be enabled in the Workspace ONE Access service to authenticate Horizon resources assigned to users.
When Wrap Artifact in JWT is enabled to authenticate a Horizon resource launch request, the Workspace ONE Access service generates a digitally signed JWT token that includes the SAML artifact to allow for verification.
This JWT token is sent to the validating gateway in the DMZ. The gateway validates the JWT token from Workspace ONE Access and extracts the SAML artifact value from the token. The gateway forwards the request with the real SAML artifact value to the Horizon Connection Server. The Connection Server verifies the request and the user is signed in to the Horizon resource.
If Wrap Artifact in JWT is not enabled, the validating gateway does not pass the artifact to the Horizon Connection Server for validation and authentication fails.
Prerequisites
- The validating gateway must be configured with the following Workspace ONE Access details.
- SSL Certificate
- OAuth2 client ID and secret
- Workspace ONE Access validation endpoint URL
- A Super Admin role is required in Workspace ONE Access to perform this procedure.
Procedure
What to do next
The unique audience names that you add here must also be added to the validating gateway configuration.