Note: Horizon Web Client is available with Horizon 8 versions 2412 and later. For Horizon 8 versions 2406 and earlier, Horizon Web Client is called "HTML Access." This documentation page uses the name "Horizon Web Client" to refer to both Horizon Web Client and HTML Access.
After you import a server certificate into the Windows local computer certificate store, you must take additional steps to allow a Horizon 8 server to use the certificate.
Note: The MANAGE_CERTIFICATES privilege is required for successful import certificate functionality.
Procedure
-
Verify that the server certificate was imported successfully.
-
Change the "Friendly name" of the certificate to
vdmfor machine certficates orvdm.ecin the case of cluster certificates. Note that support for cluster certificates is available starting from the 2312 release and later.vdmandvdm.ecmust be lower case. Any other certificates with the Friendly namevdmorvdm.ecmust be renamed, or you must remove the Friendly name from those certificates. -
Install the root CA certificate and intermediate CA certificate in the Windows certificate store.
-
Restart the Connection Server service to allow the service to start using the new certificates.
-
If you use Horizon Web Client, restart the Blast Secure Gateway service.
Results
To perform the tasks in this procedure, see the following topics:
- Modify the Certificate Friendly Name
- Import the Root and Intermediate Certificates into the Windows Certificate Store
For more information, see "Configure Horizon Connection Server to Use a New TLS Certificate" in the Horizon 8 Installation and Upgrade document. This section also provides details on using the Certificate Management feature in Horizon Console to import certificates and view security configuration information.
Note: The Horizon 8 Installation and Upgrade topic "Import a Signed Server Certificate into a Windows Certificate Store" is not listed here because you already imported the server certificate by using the certreq utility. You should not use the Certificate Import wizard in the MMC Snap-in to import the server certificate again.
However, you can use the Certificate Import wizard to import the root CA certificate and intermediate CA certificate into the Windows certificate store.
Was this page helpful?