To use the derived credentials feature, you must create a virtual smart card to use when you log in to a server and connect to a remote desktop. One virtual smart card can hold multiple certificates.
Prerequisites
- Verify that the client device, remote desktops, RDS hosts, Omnissa Horizon Connection Server host, and other Horizon components meet the smart card authentication requirements. See Smart Card Authentication Requirements.
- Verify that the device has a passcode. A passcode is required to create a virtual smart card.
- Use Omnissa Workspace ONE PIV-D Manager for iOS v22.10 or later, or a third-party mobile app such as Purebred to issue the certificate to the client device, create a derived credential and provision the credential on the client device.
If you are using Workspace ONE PIV-D Manager, you must meet these requirements:
- Workspace ONE PIV-D Manager for iOS v22.10 and later.
- Devices with iOS 15 or later and iPadOS 15 or later.
- Persistent tokens enabled. To do this:
- Create a local text file named
config.txt. - Add this line to the file and save it:
EnablePersistentTokens=True. - Sync this file to the public folder for Omnissa Horizon Client for iOS using Finder. (Horizon Client for iOS has published its Document directory).
- Create a local text file named
- Set the following Application Configuration on Workspace ONE UEM when sending Derived Credentials from the Console to iOS Devices. For details on
PersistentTokenExtensionAllowed,UserPresenceProtection, andPIVDPromptForPINand how to set them, see: Send Derived Credentials from the Console to iOS Devices in the Workspace ONE PIV-D Managerguide.- Required: Set
PersistentTokenExtensionAllowedtoTrueto enable the Persistent token extension. This allows PIV-D Manager to act as a CTK Provider. - Optional: Set
UserPresenceProtectionandPIVDPromptForPINtoFalseand enable SSO to avoid redundant authentication.
- Required: Set
Procedure
-
Tap Settings at the bottom of the Horizon Client window.
-
Tap Derived Credentials and then tap Create new virtual smart card.
-
Perform device authentication.
- If either Touch ID or Face ID is enabled, authenticate with Touch ID or Face ID.
- If neither Touch ID nor Face ID is enabled, authenticate with a passcode.
-
Enter and confirm a PIN for the virtual smart card.
-
Tap Continue and import the certificate.
-
Tap PIV Authentication Certificate.
-
Select the Purebred Key Chain location.
Note: If using Omnissa Workspace ONE PIV-D Manager, you can skip this step.
-
Select the certificate to import.
Note: If you cannot find the certificate in the Purebred Key Chain location, check that Purebred was configured successfully.
-
-
To import a digital signature certificate or encryption certificate after you import the PIV authentication certificate, tap Digital Signature Certificate or Encryption Certificate and follow the prompts.
-
To create the virtual smart card, tap Done.
The derived credential appears in the Settings window. The Use Derived Credentials setting is set to on.
-
To create another virtual smart card for a different Horizon environment, tap Create new virtual smartcard and repeat these steps.
What to do next
Was this page helpful?