Skip to main content

May 8, 2026

Set Up True SSO for Linux Desktops

The True Single Sign-on (True SSO) feature grants users access to a Linux remote desktop after they first authenticate to Omnissa Access. Users can log in to Omnissa Access using a smart card or RSA SecurID or RADIUS authentication, and then access remote Linux resources without entering their Active Directory credentials.

Overview of True SSO

If a user authenticates by using Active Directory (AD) credentials, the True SSO feature is not necessary. However, you can configure True SSO to be used even in this case, so that the desktop can support both AD credentials and True SSO.

When connecting to a Linux remote desktop, users can select to use either the native Horizon Client or Horizon Web Client.

The /etc/omnissa/viewagent-greeter.conf configuration file allows you to configure the behavior of the Horizon greeter in cases where True SSO fails. See Edit Configuration Files on a Linux Desktop.

System Requirements for True SSO

True SSO is supported on single-session virtual desktops running any Linux distribution supported by Horizon Agent.

True SSO is supported on multi-session published desktops and applications based on the following types of farms.

  • Manual and automated instant-clone farms of Ubuntu host machines that have been integrated with Active Directory using the Samba domain-join method.
  • Manual and automated instant-clone farms of RHEL Workstation, Rocky Linux, or Debian host machines that have been integrated with Active Directory using the System Security Services Daemon (SSSD) domain-join method.

Configuring True SSO

To set up True SSO for Linux desktops, perform the following tasks.

  1. Set up and configure True SSO in your Horizon 8 environment. For more information, see the Horizon 8 Administration document.
  2. Integrate the base virtual machine with an AD domain, following the procedure for your Linux distribution.
  3. Configure True SSO on the base virtual machine, following the procedure for your Linux distribution.

Certificate Setup for Linux Agent and Active Directory Domain Controller

The following needs to be done to set up certificates for Linux Agent and AD Domain Controller.

Certificate Setup for Linux Agent

In the Linux Agent Trust store /etc/sssd/pki/sssd_auth_ca_db.pem set up KDC certificate chains (the KDC certificate, its intermediate, and root CA certificate) of the KDC that the agent is trying to establish PKINIT with. If there are multiple KDC, the KDC certificate chain setup must be completed for each.

Certificate Setup for Actove Directory KDC

Ensure the KDC Trust store has all of the intermediate CA certificates and root CA certificates for the True SSO user certificates.

If there are user certificates, intermediate CA certificates, and root CA certificates in the AD KDC Trust store, the KDC will not trust the True SSO user certificate while going through the PKINIT authorization at the time of the VDI launch in Horizon Client. The Agent /var/log/sssd/krb5_child.log may show {{Pre-authentication failed: Invalid argument]}}.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…