Certificate issues on a Horizon Connection Server instance prevent you from connecting to Omnissa Horizon Console or cause a red health indicator to be displayed for a server.
You cannot connect to Horizon Console on the Horizon Connection Server instance with the problem. When you connect to Horizon Console on another Horizon Connection Server instance in the same pod, you see that the dashboard health indicator is red for the problem Horizon Connection Server instance.
From the other Horizon Connection Server instance, clicking the red health indicator displays SSL Certificate: Invalid and Status: (blank), indicating that a valid certificate could not be found. The Omnissa Horizon 8 log file contains a log entry of type ERROR with the following error text: No qualifying certificates in keystore.
The Horizon 8 log data is in <Drive Letter>:\ProgramData\Omnissa\Horizon\logs on the Horizon Connection Server instance.
A certificate might not be installed successfully on a Horizon 8 server for any of the following reasons:
- The certificate is not in the Personal folder in the Windows local computer certificate store.
- The certificate store does not have a private key for the certificate.
- The certificate does not have a friendly name of vdm.
- The certificate was generated from a v3 certificate template, for a Windows Server 2008 or later server. Horizon 8 cannot detect a private key, but if you use the Certificate snap-in to examine the Windows certificate store, the store indicates that there is a private key.
Procedure
-
Verify that the certificate is imported into the Personal folder in the Windows local computer certificate store.
See Import a Signed Server Certificate into a Windows Certificate Store.
-
Verify that the certificate contains a private key.
See Import a Signed Server Certificate into a Windows Certificate Store.
-
Verify that the certificate has a friendly name of vdm.
-
If the certificate was generated from a v3 certificate template, obtain a valid, signed certificate from a CA that does not use a v3 template.
Was this page helpful?