Skip to main content

May 28, 2026

Set Up an Imported Certificate for a Horizon 8 Server

Note: Horizon Web Client is available with Horizon 8 versions 2412 and later. For Horizon 8 versions 2406 and earlier, Horizon Web Client is called "HTML Access." This documentation page uses the name "Horizon Web Client" to refer to both Horizon Web Client and HTML Access.

After you import a server certificate into the Windows local computer certificate store, you must take additional steps to allow a Horizon 8 server to use the certificate.

Note: The MANAGE_CERTIFICATES privilege is required for successful import certificate functionality.

Procedure

  1. Verify that the server certificate was imported successfully.

  2. Change the "Friendly name" of the certificate to vdm for machine certficates or vdm.ec in the case of cluster certificates. Note that support for cluster certificates is available starting from the 2312 release and later.

    vdm and vdm.ec must be lower case. Any other certificates with the Friendly name vdm or vdm.ec must be renamed, or you must remove the Friendly name from those certificates.

  3. Install the root CA certificate and intermediate CA certificate in the Windows certificate store.

  4. Restart the Connection Server service to allow the service to start using the new certificates.

  5. If you use Horizon Web Client, restart the Blast Secure Gateway service.

Results

To perform the tasks in this procedure, see the following topics:

For more information, see "Configure Horizon Connection Server to Use a New TLS Certificate" in the Horizon 8 Installation and Upgrade document. This section also provides details on using the Certificate Management feature in Horizon Console to import certificates and view security configuration information.

Note: The Horizon 8 Installation and Upgrade topic "Import a Signed Server Certificate into a Windows Certificate Store" is not listed here because you already imported the server certificate by using the certreq utility. You should not use the Certificate Import wizard in the MMC Snap-in to import the server certificate again.

However, you can use the Certificate Import wizard to import the root CA certificate and intermediate CA certificate into the Windows certificate store.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…