Skip to main content

August 24, 2026

Configure Omnissa Horizon Connection Server to Use a New TLS Certificate

To configure a Horizon Connection Server instance to use a TLS certificate, you must import the server certificate and the entire certificate chain into the Windows local computer certificate store on the Horizon Connection Server host.

In a pod of replicated Horizon Connection Server instances, you must import the server certificate and certificate chain on all instances in the pod.

By default, the Blast Secure Gateway (BSG) uses the TLS certificate that is configured for the Horizon Connection Server instance on which the BSG is running. If you replace the default, self-signed certificate for an Omnissa Horizon 8 server with a CA-signed certificate, the BSG also uses the CA-signed certificate.

Important: To configure Horizon Connection Server to use a certificate, you must change the certificate Friendly name to vdm. Also, the certificate must have an accompanying private key.

Omnissa strongly recommends that you configure TLS certificates for authentication of Horizon Connection Server instances.

  1. Add the Certificate Snap-In to MMC
    Before you can add certificates to the Windows Certificate Store, you must add the Certificate snap-in to the Microsoft Management Console (MMC) on the Windows Server host on which the Horizon 8 server is installed.

  2. Import a Signed Server Certificate into a Windows Certificate Store
    You must import the TLS server certificate into the Windows local computer certificate store on the Windows Server host on which Horizon Connection Server is installed.

  3. Modify the Certificate Friendly Name
    To configure a Horizon Connection Server instance to recognize and use an TLS certificate, you must modify the certificate Friendly name to vdm or vdm.ec.

  4. Import a Root Certificate and Intermediate Certificates into a Windows Certificate Store
    If the Windows Server host on which Horizon Connection Server is installed does not trust the root certificate for the signed TLS server certificate, you must import the root certificate into the Windows local computer certificate store. In addition, if the Horizon Connection Server host does not trust the root certificates of the TLS server certificates configured for vCenter Server hosts, you also must import those root certificates.

  5. Set up an Imported Certificate from Omnissa Horizon Console
    As an alternative method for importing certificates, use the Certificate Management feature in Horizon Console to import a certificate in .pem or .pfx format. This feature is supported for Horizon 8 version 2212 and later.

  6. View Security Configuration Information from Horizon Console
    The View Security Configuration option provides details regarding Broker incoming and outgoing security configurations, Secure Gateway incoming and outgoing security configurations, and certificate properties.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…