Skip to main content

May 28, 2026

Import TLS Off-loading Servers' Certificates to Horizon 8 Servers

If you off-load TLS connections to an intermediate server, you must import the intermediate server's certificate onto the Connection Server instances that connect to the intermediate server. The same TLS server certificate must reside on both the off-loading intermediate server and each off-loaded Horizon 8 server that connects to the intermediate server.

If you have a mixed network environment with some intermediate servers and some external-facing Connection Server instances, the intermediate server and any Connection Server instances that connect to it must have the same TLS certificate.

If the intermediate server's certificate is not installed on the Connection Server instance, clients cannot validate their connections to Horizon 8. In this situation, the certificate thumbprint sent by the Horizon 8 server does not match the certificate on the intermediate server to which Horizon Client connects.

Do not confuse load balancing with TLS off-loading. The preceding requirement applies to any device that is configured to provide TLS off-loading, including some types of load balancers. However, pure load balancing does not require copying of certificates between devices.

  1. Download an TLS Certificate from the Intermediate Server
    You must download the CA-signed TLS certificate that is installed on the intermediate server so that it can be imported into the external-facing Horizon 8 servers.
  2. Download a Private Key from the Intermediate Server
    You must download the private key that is associated with the TLS certificate on the intermediate server. The private key must be imported with the certificate into the Horizon 8 servers.
  3. Convert a Certificate File to PKCS#12 Format
    If you obtained a certificate and its private key in PEM or another format, you must convert it to PKCS#12 (PFX) format before you can import the certificate into a Windows certificate store on a Horizon 8 server. PKCS#12 (PFX) format is required if you use the Certificate Import wizard in the Windows certificate store.
  4. Import a Signed Server Certificate into a Windows Certificate Store
    You must import the TLS server certificate into the Windows local computer certificate store on the Windows Server host on which Connection Server is installed.
  5. Modify the Certificate Friendly Name
    To configure a Connection Server instance to recognize and use an TLS certificate, you must modify the certificate Friendly name to vdm or vdm.ec.
  6. Import the Root and Intermediate Certificates into the Windows Certificate Store
    You must import the root certificate and any intermediate certificates in the certificate chain into the Windows local computer certificate store.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…