To launch remote desktops and applications from Omnissa Workspace ONE Access or to connect to remote desktops and applications through a third-party load balancer or gateway, you must create a SAML authenticator in Horizon Console. A SAML authenticator contains the trust and metadata exchange between Horizon 8 and the device to which clients connect.
You associate a SAML authenticator with a Connection Server instance. If your deployment includes more than one Connection Server instance, you must associate a separate SAML authenticator with each instance.
You can allow one static authenticator and multiple dynamic authenticators to go live at a time. You can configure vIDM (Dynamic) and Unified Access Gateway (Static) authenticators and retain them in active state. You can make connections through either of these authenticators.
You can configure more than one SAML authenticator to a Connection Server and all the authenticators can be active simultaneously. However, the entity-ID of each of these SAML authenticators configured on the Connection Server must be different.
The status of the SAML authenticator in dashboard is always green as it is predefined metadata that is static in nature. The red and green toggling is only applicable for dynamic authenticators.
For information about configuring a SAML authenticator for Omnissa Unified Access Gateway appliances, see Authentication Methods for Unified Access Gateway and Third-Party Identity Provider Integration.
Prerequisites
-
Verify that Workspace ONE, Omnissa Workspace ONE Access, or a third-party gateway or load balancer is installed and configured. See the installation documentation for that product.
-
Verify that the root certificate for the signing CA for the SAML server certificate is installed on the Connection Server host. Omnissa does not recommend that you configure SAML authenticators to use self-signed certificates. For information about certificate authentication, see the Horizon 8 Installation and Upgrade document.
-
Make a note of the FQDN or IP address of the Workspace ONE server, Omnissa Workspace ONE Access server, or external-facing load balancer.
-
If you are using Workspace ONE or Omnissa Workspace ONE Access, make a note of the URL of the connector Web interface.
-
If you are creating an authenticator for a Unified Access Gateway appliance or a third-party appliance that requires you to generate SAML metadata and create a static authenticator, perform the procedure on the device to generate the SAML metadata, and then copy the metadata.
Procedure
-
In Horizon Console, navigate to Settings > Global Settings.
-
On the Authenticators tab, Click Add & select Add SAML Authenticator from the drop-down menu.
-
Configure the SAML authenticator in the Add SAML Authenticator dialog box.
Option Description Type For a Unified Access Gateway appliance or a third-party device, select Static. For Omnissa Workspace ONE Access select Dynamic. For dynamic authenticators, you can specify a metadata URL and an administration URL. For static authenticators, you must first generate the metadata on the Unified Access Gateway appliance or a third-party device, copy the metadata, and then paste it into the SAML metadata text box. Label Unique name that identifies the SAML authenticator. Description Brief description of the SAML authenticator. This value is optional. Metadata URL (For dynamic authenticators) URL for retrieving all of the information required to exchange SAML information between the SAML identity provider and the Connection Server instance. In the URL https://<YOUR HORIZON SERVER NAME>/SAAS/API/1.0/GET/metadata/idp.xml, click <YOUR HORIZON SERVER NAME> and replace it with the FQDN or IP address of the Omnissa Workspace ONE Access server or external-facing load balancer (third-party device).True SSO Trigger Mode (For dynamic authenticators) Enable or disable TrueSSO for SAML authenticators. SAML metadata (For static authenticators) Metadata text that you generated and copied from the Unified Access Gateway appliance or a third-party device. Require Encrypted Assertion (Horizon 2412 and later) Select this checkbox if you need Encrypted Assertion support. If the IDP is not able to send the Encrypted Assertion, leave this flag unchecked (the default), and the default Connection Server will allow an unencrypted SAML Assertion from the IDP. When IDP sends the Encrypted Assertion, the Connection Server will allow the encrypted assertion even when the Require Encrypted Assertion option is unchecked. Note: Add/Edit SAML Authenticator functions have this option selected by default.
Workspace ONE Mode If enabled, marks this SAML Authenticator as a Workspace ONE Authenticator. By default, Connection Server will not consider an authenticator as a Workspace ONE Authenticator. IDP Should Authenticate User Every Time If enabled, IDP (Identity Provider) should re-authenticate even if a SAML session is currently active for particular user. By default, IDP will not require users to re-authenticate when an user session is already active. -
Click OK to save the SAML authenticator configuration.
-
Select the authenticator to Enable the Delegation of Authentication settings for all selected connection servers.
Option Description Allowed SAML authentication is enabled. You can launch remote desktops and applications from both Horizon Client and Omnissa Workspace ONE Access or the third-party device. Required SAML authentication is enabled. You can launch remote desktops and applications only from Omnissa Workspace ONE Access or the third-party device. You cannot launch desktops or applications from Horizon Client manually. -
Configure Metadata Settings:
-
The Metadata Settings, lets you control how SAML metadata is shared and set up within your CPA environment. This configuration must be completed for each pod individually to enable common SAML metadata at the CPA level.
-
The Metadata Settings contains the following configuration fields:
Field Description Cluster GUID Unique identifier for the pod cluster, identifies the specific pod instance in the CPA environment. Enable Key Sharing Controls whether SAML signing and encryption keys are shared across pods. Enable Entity Sharing Controls whether SAML Entity IDs are shared across pods, determines if pods present a common identity to identity providers Shared EntityID The common SAML Entity ID used when Entity ID sharing is enabled, populated with Cluster GUID by default
What to do next
Extend the expiration period of the Connection Server metadata so that remote sessions are not terminated after only 24 hours. See Change the Expiration Period for Service Provider Metadata on Connection Server.
-
Was this page helpful?