Skip to main content

August 18, 2026

Adding or Modifying Enterprise Services on the Omnissa Access Connector

You can update your Omnissa Access connector installation to add or modify enterprise services at any time. Run the installer again to make any changes.

You can make the following changes:

  • Add the Directory Sync, User Auth, Kerberos Auth, or Virtual App service
  • Specify custom ports for each service
  • Configure a proxy server
  • Configure a syslog server
  • Install trusted root certificates
  • (Kerberos Auth service only) Install a trusted SSL certificate for the Kerberos Auth service
  • (Kerberos Auth and Virtual App services only) Configure the Kerberos Auth and Virtual App services to run as a domain user account
  • (Virtual App service only) Configure settings for Citrix virtual apps collections related to multi-site aggregation and keyword filtering.

Note: You can also delete a service from the connector. To delete a service, run the installer again as you cannot delete a service at the same time as adding and modifying services. See Deleting an Enterprise Service from the Omnissa Access Connector.

Prerequisites

  • Be aware that all the enterprise services in a connector installation are connected to the same Omnissa Access tenant. When you modify an existing installation to add a service, the configuration file that you downloaded from the tenant for the original installation is used automatically.
  • If you are modifying the existing configuration, suspend the enterprise services from the Omnissa Access console first. Go to the Integrations > Connectors page, select the connector, click Manage, and use the toggle next to each service name to suspend the service.

Procedure

  1. Log in to the Windows server on which the Omnissa Access connector is installed.

  2. Go to the folder containing the connector installer and double-click the executable file.

  3. On the Welcome page, click Next.

  4. On the Program Maintenance page, select the Add/Remove Services option, then click Next.

  5. On the Service Selection page, select the services you want to add, if any, then click Next.

  6. If the Specify Configuration File page appears, select the same configuration file that you downloaded from the Omnissa Access tenant for the original installation.

    The Specify Configuration File page appears only if you selected services to add.

  7. Make your changes on the appropriate pages of the wizard.

    OptionAction
    To update the ports the enterprise services run onOn the Specify Ports page, enter the port for each service. Inbound connectivity is only required for the Kerberos Auth service port. It is not required for the User Auth service and Directory Sync service ports.
    Default ports:
    • User Auth service: 8090
    • Directory Sync service: 8080
    • Kerberos Auth service: 443
    • Virtual App service: 8008
    To upload a trusted SSL certificate for the connector serverOn the Install SSL Certificates page, select the Would you like to use your own SSL certificate? check box, click Browse, and select the certificate.

    The certificate file must be in PEM or PFX format. If the file is in PEM format, also upload the key file. If the file is in PFX format, also enter the certificate password.

    For more information about certificate requirements, see Uploading an SSL Certificate for the Kerberos Auth Service.

    Important: A trusted SSL certificate is required for the Kerberos Auth service. If you do not upload a trusted SSL certificate, a self-signed certificate is auto-generated. To use this Omnissa Access generated self-signed certificate, you will need to add the root certificate generated by Omnissa Access to clients' truststores. You can get the root certificate, root_ca.cer, from INSTALLDIR\Workspace ONE Access\Kerberos Auth Service\conf after installation.

    While you can use the self-signed certificate for testing purposes, for production usage we recommend you use trusted SSL certificates signed by a public or internal CA.
    To upload or remove trusted root certificates from the truststoreOn the Install Trusted Root Certificates page:
    • To upload a certificate, click Browse and select the certificate.
      **Caution**: Make sure that the certificate paths do not contain double-byte characters, which are used in some languages. If the path contains double-byte characters, upgrade might succeed but the certificates will not be uploaded correctly.
    • To remove a certificate, select the certificate and click Remove.
    • To view an installed certificate, click View Certificate.
    The connector will be able to establish secure connections to servers whose certificate chain includes any of the certificates you add to the truststore. Scenarios for uploading certificates to the truststore include:
    • (On-premises installations only) If your on-premises Omnissa Access service instance has a self-signed certificate that you installed, you must upload its root, and, if required, intermediate certificate to establish trust between the enterprise services and the Omnissa Access service instance.
    • (Kerberos Auth service only) If you deploy multiple instances of the Kerberos Auth service behind a load balancer, you must install the load balancer's root CA certificate on the connector instances to establish trust between the connectors and the load balancer.
    • (Virtual App service only) If you create virtual apps collections to integrate with Horizon, Horizon Cloud Service on Microsoft Azure with Single-Pod Broker, or Horizon Cloud Service on IBM Cloud, and the Horizon servers have self-signed certificates, you must upload the certificate chain to the connector instances on which the Virtual App service is installed to establish trust between the connectors and the Horizon Connection servers. If the Horizon servers have certificates signed by a public CA, you do not need to upload the certificates to the connector truststore. Using certificates signed by a public CA is strongly recommended.
    To specify a proxy serverOn the Specify Proxy Server Information page, enter a proxy server if required. The enterprise services access Web services on the Internet. If your network configuration provides Internet access through an HTTP proxy, you must enter a proxy server. See Omnissa Access Connector Systems Requirements for information about supported proxies. You can also specify a list of non-proxy hosts, hosts that should be reached directly without going through the proxy server.
    1. Select the Enable Proxy check box.
    2. Enter the host name, specified as a fully qualified domain name (FQDN), or IP address of the proxy server.

      Note: Do not include a scheme, such as http:// or https://, or a port in this value. Enter only a host name or IP address. For example, enter proxy.example.com or 192.0.2.10.
    3. Enter the proxy server port.
    4. If you want to specify any non-proxy hosts, hosts that should be reached directly without going through the proxy server, enter the FQDN and ports in the Non Proxy Hosts text box. Use the following format, with each entry separated by |: host1|host2
    5. If the proxy server requires authentication, select Basic and enter the user name and password for the proxy server.
    To specify an external syslog server to store application-level event messagesOn the Specify Syslog Server Information page, select the Enable Syslog check box and enter the syslog server's IP address or FQDN, and port.
    To specify a single syslog server, use the following format:
    host:port
    To specify multiple syslog servers, use the following format:
    host:port,host:port,host:port
    where host is the fully qualified domain name or IP address of the syslog server and port is the port number. For example:
    syslog1.example.com:54
    or
    syslog1.example.com:514,syslog2.example.com:601,syslog3.example.com:163
    Note: Only application-level events are exported to the syslog server. Operating system events are not exported.
    To specify or change the domain user account used to run the Kerberos Auth and Virtual App services A domain user account is required to run the Kerberos Auth and Virtual App services.

    On the Service Account page, enter the user name and password of the domain user account in the format DOMAIN\username, such as EXAMPLE\administrator. Alternatively, click Browse and select the domain and user.

    If you are unable to locate domains or users when you click Browse, type them in the text box in the format specified above.

    Important: The Kerberos Auth service only supports the following special characters in the domain user account password:
    ! ( & % @ / = ? * , . #

    If the password contains any other special characters, Kerberos Auth service installation fails.
    To configure settings for Citrix virtual apps collectionsIf you are integrating Omnissa Access with a Citrix environment that has multi-site aggregation or keyword filtering enabled, on the Citrix Configuration page select the options that apply to your scenario.
    • Enable Citrix StoreFront restricted PowerShell session
      Select this option only if your Citrix environment restricts the PowerShell commands that can be executed on StoreFront remotely. If you select this option, you must also create a PowerShell session configuration file on StoreFront to allow the Virtual App service to run the limited commands required for multi-site aggregation and keyword filtering. In the Configuration Name text box, enter the configuration name you specified while creating the session configuration file, without the extension. Only alpha-numeric characters are allowed in the name.
    • Enable Citrix keyword filtering
      Select this option if keyword filtering is enabled on StoreFront. For Omnissa Access to support keyword filtering, either your Citrix environment must not have any restrictions on the PowerShell commands that can be executed on StoreFront remotely, or you must select the Enable Citrix StoreFront restricted PowerShell session option and set up a PowerShell session configuration file to allow the Virtual App service to run limited commands.
    • Disable Citrix auto-loading of StoreFront modules
      The Virtual App service loads certain modules in StoreFront to support keyword filtering. If you do not want the Virtual App service to load the modules, select this option. The required commands will then be executed through the restricted PowerShell session configuration setup.
    See Configuring Citrix Multi-site Aggregation and Keyword Filtering in Omnissa Access in Setting up Resources in Omnissa Access for more information.
  8. In the Ready to Install the Program page, review your selections, select the Do you want to restart already installed services? check box, then click Install.

    Important: If you uploaded any certificates, you must select the option to restart all the services.

What to do next

The installation is updated. New services are registered with the Omnissa Access tenant. Refresh the Connectors page in the Omnissa Access console to view the updated list of services.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…