Skip to main content

March 25, 2025

Troubleshooting Smart Card Certificate Revocation Checking

The Omnissa Horizon Connection Server instance that has the smart card connected cannot perform certificate revocation checking on the server's TLS certificate unless you have configured smart card certificate revocation checking.

Certificate revocation checking might fail if your organization uses a proxy server for Internet access, or if a Horizon Connection Server instance cannot reach the servers that provide revocation checking because of firewalls or other controls.

Important: Make sure the CRL file is up to date.

Omnissa Horizon supports certificate revocation checking with certificate revocation lists (CRLs) and with the Online Certificate Status Protocol (OCSP). A CRL is a list of revoked certificates published by the CA (Certificate Authority) that issued the certificates. OCSP is a certificate validation protocol that is used to get the revocation status of an X.509 certificate. The CA must be accessible from the Horizon Connection Server host. This issue can only occur if you configured revocation checking of smart card certificates. See Using Smart Card Certificate Revocation Checking.

Procedure

  1. Create your own (manual) procedure for downloading an up-to-date CRL from the CA website you use to a path on your Omnissa Horizon server.

  2. Create or edit the locked.properties file in the TLS/SSL gateway configuration folder on the Horizon Connection Server host.

    For example: install_directory\View\Server\SSLgateway\conf\locked.properties

  3. Add the enableRevocationChecking and crlLocation properties in the locked.properties file to the local path to where the CRL is stored.

  4. Restart the Horizon Connection Server service to make your changes take effect.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…