Skip to main content

September 3, 2026

Configuring Certificate Authentication for Use with Omnissa Access

You can configure X.509 certificate authentication to allow clients to authenticate with certificates on their desktop and mobile devices or to use a smart card adapter for authentication. Certificate-based authentication is based on what the user has (the private key or smart card), and what the person knows (the password to the private key or the smart-card PIN.) An X.509 certificate uses the public key infrastructure (PKI) standard to verify that a public key contained within the certificate belongs to the user. With smart card authentication, users connect the smart card with the computer and enter a PIN.

The smart card certificates are copied to the local certificate store on the user's computer. The certificates in the local certificate store are available to all the browsers running on this user's computer, with some exceptions, and therefore, are available to an Omnissa Access instance in the browser.

Configuring certificate authentication for Omnissa Access involves several tasks:

  • Certificate authority setup: Upload the root and intermediate CA certificates to Omnissa Access, so that it can send the trusted CA list to users' browsers and validate the certificates that users present.
  • User identification: Decide whether the user principal name (UPN), email address, or subject UID from the certificate is used to match the certificate to an Active Directory account.
  • Revocation checking (optional): Configure CRL or OCSP checking so that revoked certificates can no longer be used to authenticate.
  • Certificate (cloud deployment) authentication method: Configure the authentication method.

After you configure the authentication method, associate it with the built-in identity provider and add it to an access policy rule.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…