You can ensure that all client connections to the PSG use the CA-signed certificate for the PSG instead of the default legacy certificate. This procedure is not required to configure a CA-signed certificate for the PSG. Take these steps only if it makes sense to force the use of a CA-signed certificate in your Omnissa Horizon 8 deployment.
In some cases, the PSG might present the default legacy certificate instead of the CA-signed certificate to a security scanner, invalidating the compliance test on the PSG port. To resolve this issue, you can configure the PSG not to present the default legacy certificate to any device that attempts to connect.
Important: Performing this procedure prevents all legacy clients from connecting to this server over PCoIP.
Prerequisites
Verify that all client devices that connect to this server, including thin clients, run Omnissa Horizon Client 5.2 for Windows or Horizon Client or later releases. You must upgrade the legacy clients.
Procedure
-
Start the Windows Registry Editor on the Omnissa Horizon Connection Server computer where the PCoIP Secure Gateway is running.
-
Navigate to the
HKEY_LOCAL_MACHINE\SOFTWARE\Teradici\SecurityGatewayregistry key. -
Add a new String (REG_SZ) value,
SSLCertPresentLegacyCertificate, to this registry key. -
Set the
SSLCertPresentLegacyCertificatevalue to 0. -
To make your changes take effect, restart the Horizon PCoIP Secure Gateway service.
Was this page helpful?