The True Single Sign-on (True SSO) feature grants users access to a Linux remote desktop after they first authenticate to Omnissa Access. Users can log in to Omnissa Access using a smart card or RSA SecurID or RADIUS authentication, and then access remote Linux resources without entering their Active Directory credentials.
Overview of True SSO
If a user authenticates by using Active Directory (AD) credentials, the True SSO feature is not necessary. However, you can configure True SSO to be used even in this case, so that the desktop can support both AD credentials and True SSO.
When connecting to a Linux remote desktop, users can select to use either the native Horizon Client or Horizon Web Client.
The /etc/omnissa/viewagent-greeter.conf configuration file allows you to configure the behavior of the Horizon greeter in cases where True SSO fails. See Edit Configuration Files on a Linux Desktop.
System Requirements for True SSO
True SSO is supported on single-session virtual desktops running any Linux distribution supported by Horizon Agent.
True SSO is supported on multi-session published desktops and applications based on the following types of farms.
- Manual and automated instant-clone farms of Ubuntu host machines that have been integrated with Active Directory using the Samba domain-join method.
- Manual and automated instant-clone farms of RHEL Workstation, Rocky Linux, or Debian host machines that have been integrated with Active Directory using the System Security Services Daemon (SSSD) domain-join method.
Configuring True SSO
To set up True SSO for Linux desktops, perform the following tasks.
- Set up and configure True SSO in your Horizon 8 environment. For more information, see the Horizon 8 Administration document.
- Integrate the base virtual machine with an AD domain, following the procedure for your Linux distribution.
- Configure True SSO on the base virtual machine, following the procedure for your Linux distribution.
Was this page helpful?