As an administrator in Horizon Cloud, you can update the Omnissa CA SSO certificate bundle, for example to replace a certificate that is about to expire or that has already expired.
Prerequisites
This procedure requires that you meet the following prerequisites:
-
Use the Horizon Universal Console to create and download a certificate authority (CA) bundle. See Add an SSO Configuration to Horizon Cloud for an Omnissa CA.
-
To run the PowerShell script extracted from the Omnissa CA bundle, as described and required for this procedure, confirm that you have the following required permissions:
- Full Control permissions on the "Public Key Services" container in Active Directory.
- Enroll permissions on the "SubCA" certificate template in Active Directory.
Note: While you can run the PowerShell script as a member of the Enterprise Admins group, it is suggested that you use less powerful permissions.
Procedure
-
Create a new Omnissa CA bundle from the Horizon Universal Console and download the bundle by clicking Integration > Identity and Access Management > SSO Configuration > Omnissa CA > Generate a new Omnissa CA bundle > Download.
-
Import the bundle on one of the domain controllers in the environment.
For information about the import process, see Prepare Active Directory for an SSO Configuration with an Omnissa CA and Applicable to Multiple Forests.
After the new certificate bundle is imported, there will be two certificate bundles, the new one that you just imported and the old one that you want to replace, installed on the system.
The next step is to run the PKIview.msc command and prepare to delete the old certificates.
-
Open Run > execute pkiview.msc and then right click Enterprise PKI > Manage AD Containers.
a) Navigate to NTAuthCertificates and remove the old certificates (certificate names include AuthEngine... near the beginning of the name) from the list.
b) Navigate to AIA Container and remove the old certificates (certificate names include AuthEngine... near the beginning of the name) from the list.
-
Open the Microsoft Management Console (MMC), click Certificate (Local Computer) and navigate to Intermediate Cert Auth > Certificates.
-
Delete the old certificates. Note that certificate names include AuthEngine... near the beginning of the name.
-
Optional: To make the certificate change take effect immediately, turn the SSO toggle option Off and On in the Edge setting, as follows:
- Log in to the Horizon Universal Console. See Log in to Horizon Cloud.
- Click Capacity and select the respective Edge.
- Click Edit, turn the SSO toggle Off, and click Save.
- Click Edit, turn the SSO toggle On, and click Save.
-
If you did not do the above Optional step, wait until the SSO status displays as "Ready" on the Edge details page. Once the SSO status displays as "Ready, verify that the certificate validity period has been updated.
Results
The new certificate bundle is applied and available for end user authentication. The previous certificate bundle is no longer present.
Was this page helpful?