Skip to main content

August 11, 2026

Set Up Cert Proxy for Omnissa Access (On Premise only)

The cert proxy settings must be configured on the Omnissa Access service to manage the Android Mobile SSO requests.

Prerequisites

Setting up cert proxy is required only for on-premises deployments of Omnissa Access for Android Mobile SSO authentication.

  • Load balancer correctly configured.
  • Certificates uploaded to the Omnissa Access service.
  • The cert proxy service running in the Omnissa Access appliance.

Procedure

  1. Log in to the Omnissa Access console and navigate to the Monitor > Resiliency page.

  2. Click VA Configuration on the service node to be configured with cert proxy.

  3. Click Mobile SSO.

  4. Enable Cert Proxy and configure the CertProxy settings for Android Mobile SSO requests to the Omnissa Access service.

    OptionDescription
    Destination ForcedWhen Destination Forced is selected, a single host name or IP address must be provided in the Destination text box. All Android SSO requests are sent to that destination. This destination is either the load balancer or the local host, depending on the Omnissa Access configuration.
    DestinationIf Destination Forced is enabled, enter the host name or IP address to use.
    If Destination Forced is not selected, enter the allow-list of approved destinations that can receive Android SSO requests. The addresses in the list can be separated by a semicolon either in CIDR format, subnet format delimited by a space, or a single IP.
    Remote IP Source From the list, select the source that is used to obtain the CertProxy instance IP from HTTP request.
    If a load balancer is between the Cert Proxy and the Omnissa Access instance, use the X-forwarded-Forheader or X-Real-Ipheader.
    If CertProxy is directly communicating with Omnissa Access, use Request remote address.
    Number of load balancersIf the Remote IP Source value is X-Forwarded-For, enter the number of load balancers that are between the CertProxy service and the Omnissa Access instance.
    Cert Proxy instance allowlist Set up a CertProxy allowlist with the IP addresses that are authorized to received authentication requests.
    Enter IP addresses of CertProxy instances separated by a semicolon, either in CIDR format, subnet format delimited by a space, or as a single IP. If destination is set to localhost, add the localhost IP address to the list. This is usually 127.0.0.1.
  5. Verify that the hash value for the Certificate Proxy Key and the Certificate Proxy Key (Identity Manager) are the same. Check the config files cert-proxy.properties and runtime-config.properties.

    These two text boxes are pre-populated with the hash value of the certificate keys of the cert proxy service and the Omnissa Access service.

    The hashes must match. If the hashes do not match, copy the value of one service to the other in the configuration files.

  6. Configure the cert proxy configuration for Android SSO through the Omnissa Access service.

    OptionDescription
    PortUsually two ports are configured for cert proxy. Port 5262 receives the external request from the Android device.
    Port 5263 receives the internal admin request from the Omnissa Access service.
    Admin Port If the port number configured in the Port text box is the port that receives the internal request from the Omnissa Access service for the certificate, enable Admin Port. The port is usually 5263.
    If this port is not used to receive the internal request, do not enable this radio button.
    SSL Certificate TypeAndroid SSO cert proxy is a separate service on the Omnissa Access appliance. Select Passthrough to reuse the pass-through certificate provisioned for Omnissa Access in the Appliance Settings > Install SSL Certificates page. If a different certificate is required, select Custom and upload the certificate in the SSL Certificate Chaintext box.
  7. To configure another port, click Add Port and configure the settings as described in step 6.

  8. To save the port configuration, click Save.

  9. When you make changes on this page that affect certificates, click Restart Cert Proxy service at the top of the page.

    Clicking Restart Cert Proxy service might require a restart of the Omnissa Access service.

What to do next

Set up the cert proxy service on each node. If cert proxy service is set up on the first appliance, when you clone the Omnissa Access service on the appliance, most of the proxy settings are configured. To verify that the cert proxy settings are set correctly, you can check the runtime-config.properties file.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…