Skip to main content

15 ottobre 2025

Horizon Pods - Configure Unified Access Gateway for Use with Universal Broker

This topic explains how to configure the Unified Access Gateway instances within Horizon pods for use with Universal Broker. Follow the procedure to configure the JSON Web Token settings in each Unified Access Gateway instance to support the tunnel server and protocol redirection required by Universal Broker.

Note: The following procedure is only required for Unified Access Gateway instances within Horizon pods based on Horizon Connection Server technology. For Horizon Cloud pods in Microsoft Azure, the JSON Web Token settings are automatically configured for you at the time of pod deployment. You do not need to perform any further configuration of the JSON Web Token for the Unified Access Gateway instances within Horizon Cloud pods (not based on Horizon Connection Server technology).

By its default design, Universal Broker expects to use the very same identical two-factor authentication settings with each and every pod in the tenant's pod fleet. Also by design, when Universal Broker is configured with two-factor authentication settings, it forms the authentication request and passes it to an external Unified Access Gateway instance which then communicates with the authentication server configured in that instance's settings to handle the specific authentication action. The Unified Access Gateway then relays the authentication service's response back to the Universal Broker.

Therefore, when you are want Universal Broker plus two-factor authentication, then you must configure the same identical authentication service on all of the external Unified Access Gateway instances on all of the pods in the tenant's pod fleet. For a fleet consisting solely of Horizon pods, the Universal Broker can support use of the RADIUS service or RSA SecurID service on all of the Unified Access Gateway instances.

However, please note that if your tenant has a blended pod fleet consisting of both Horizon pods and Horizon Cloud pods, the options available to you depend on whether your Horizon Cloud on Microsoft Azure deployments meet the conditions to have the RSA SecurID option available on them. If all Horizon Cloud pods are manifest 3139.x or later and in the Edit Pod wizard you see the RSA SecurID option, then you have the option to configure all of the pods to use the RSA SecurID type. Otherwise, you must use RADIUS to satisfy the requirement to have the same identical authentication service on all of the pod fleet.

Prerequisites

  • Verify that you have configured the appropriate set of Unified Access Gateway appliances on each Horizon pod in your tenant's pod fleet, according to the end-user use cases you want to support. For a short description of the use cases, see Universal Broker System Requirements for Horizon Pods.
  • Ensure those Unified Access Gateway appliances are running version 3.8 or later and have met all the other related Unified Access Gateway requirements described in Universal Broker System Requirements for Horizon Pods.
  • To validate the pairing of each Unified Access Gateway instance with its respective pod, connect directly to the Unified Access Gateway instance and verify that you can access virtual desktops.

Procedure

  1. Log in to the Unified Access Gateway administration console.

  2. In the Configure Manually section, click Select.

  3. Under Advanced Settings, click the gearbox for JWT Settings.

  4. After clicking the gearbox:

    • If your Unified Access Gateway software is a version earlier than 2209 version, click Add.
    • If your Unified Access Gateway software is 2209 or later, click Add JWT Consumer. The Unified Access Gateway Admin UI debuted changes in its version 2209.
  5. In the UI box that appears, specify the settings.

    SettingDescription
    NameEnter a descriptive name for the configuration set.
    IssuerEnter the cluster name of the Horizon pod, as displayed in Horizon Console. CAUTION: This field is case-sensitive in the Unified Access Gateway Admin UI. You must enter the cluster name precisely and exactly as you retrieve it from your Horizon Console. The Unified Access Gateway UI gives zero warnings that its fields are case-sensitive and does not validate on case sensitivity. This case sensitivity applies also to the word Cluster that is displayed in the Horizon Console. If you see the word displayed in your Horizon Console with an uppercase C and lowercase luster, then you must match that precisely in this Issuer field here, and enter Cluster in thisIssuer field. If you fail to ensure the precise case-sensitive name is entered into this Issuer field that exactly matches the name you see in your Horizon Console, that will cause problems downstream with the Universal Broker where your end users will be unable to launch their desktops and applications using the Universal Broker FQDN. To locate the pod's cluster name in your Horizon Console, navigate to the Dashboard area in your Horizon Console and look at the upper vertical area of the UI. The following is an illustration of the location of the pod's cluster name in the Horizon Console. Notice how the Cluster portion of that displayed name is a combination of a leading uppercase letter and then lowercase letters. You must ensure that you enter that displayed name precisely in this Issuer field in the Unified Access Gateway Admin UI. The Issuer field has zero validation to help ensure that you have entered the name properly. Cluster name of pod displayed in Horizon Console
    Dynamic Public key URLYou obtain the value to enter here from either the pod's Connection Server host name or from the Connection Server FQDN or from the local load balancer (if the pod has multiple gateway instances). Enter https://<Horizon pod FQDN>/broker/publicKey/protocolredirection, where <Horizon pod FQDN> is replaced with the pod's unique FQDN (fully qualified domain name). The FQDN is typically defined as follows:
    • If the pod has only one Unified Access Gateway instance, specify the address of that instance's paired Connection Server as the FQDN.
    • If the pod has multiple Unified Access Gateway instances, specify the address of the local load balancer as the FQDN.
    Public key URL thumbprintsThis field specifies using a public key URL for authentication. To use the pod's Connection Server certificate for authentication, enter the SHA1 thumbprint of the Horizon pod's Connection Server certificate for the Connection Server that you used for the preceding Dynamic Public key URL. Note: You can configure either Public key URL thumbprints or Trusted Certificates for authentication. You do not need to configure both options.
    Trusted CertificatesTo use a certificate other than the Horizon pod's certificate for authentication, click the (+) icon and add the trusted certificate. Note: You can configure either Trusted Certificates or Public key URL thumbprints for authentication. You do not need to configure both options.
    Public key refresh intervalFor best results, enter 900. This value sets the refresh interval to 900 seconds, or 15 minutes.
    Static public keysLeave this option set to its default value.
  6. Click Save and then click Close.

  7. If you want to use two-factor authentication for Universal Broker, enable the Show toggle for Authentication Settings. Then enable and configure settings for one of the two-factor authentication services supported by Universal Broker. Currently the two supported services are RADIUS and RSA SecurID.

    Note: You must configure the appropriate two-factor authentication service on the external Unified Access Gateway instance for every participating pod. The configurations of all external Unified Access Gateway instances within a participating pod must match each other and must be identical to the configurations of external Unified Access Gateway instances across every other participating pod. Otherwise, authentication to the Universal Broker service fails.

    For example, if you want to use RADIUS authentication for your Horizon pods configured with Universal Broker, you must configure the identical RADIUS service on every external Unified Access Gateway instance across all participating Horizon pods. You cannot configure RADIUS on some participating pods and RSA SecurID on other participating pods.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…