Administration

Table Of Contents
9 In the Enable Certicate Templates window, select Enrollment Agent Computer and click OK.
What to do next
Create an enrollment service. See “Install and Set Up an Enrollment Server,” on page 73.
Install and Set Up an Enrollment Server
You run the Connection Server installer and select the Horizon 7 Enrollment Server option to install an
enrollment server. The enrollment server requests short-lived certicates on behalf of the users you specify.
These short-term certicates are the mechanism True SSO uses for authentication to avoid prompting users
for Active Directory credentials.
You must install and set up at least one enrollment server, and the enrollment server cannot be installed on
the same host as View Connection Server. VMware recommends that you have two enrollment servers for
purposes of failover and load balancing. If you have two enrollment servers, by default one is preferred and
the other is used for failover. You can change this default, however, so that the connection server alternates
sending certicate requests to both enrollment servers.
If you install the enrollment server on the same machine that hosts the enterprise CA, you can congure the
enrollment server to prefer using the local CA. For best performance, VMware recommends combining the
conguration to prefer using the local CA with the conguration to load balance the enrollment servers. As
a result, when certicate requests arrive, the connection server will use alternate enrollment servers, and
each enrollment server will service the requests using the local CA. For information about the conguration
seings to use, see “Enrollment Server Conguration Seings,” on page 84 and “Connection Server
Conguration Seings,” on page 85.
Prerequisites
n
Create a Windows Server 2008 R2 or Windows Server 2012 R2 virtual machine with at least 4GB of
memory, or use the virtual machine that hosts the enterprise CA. Do not use a machine that is a domain
controller.
n
Verify that no other View component, including View Connection Server, View Composer, security
server, Horizon Client, or View Agent or Horizon Agent is installed on the virtual machine.
n
Verify that the virtual machine is part of the Active Directory domain for the Horizon 7 deployment.
n
Verify that you are using an IPv4 environment. This feature is currently not supported in an IPv6
environment
n
VMware recommends that the system must have a static IP address.
n
Verify that you can log in to the operating system as a domain user with Administrator privileges. You
must log in as an administrator to run the installer.
Procedure
1 On the machine that you plan to use for the enrollment server, add the Certicate snap-in to MMC:
a Open the MMC console and select File > Add/Remove Snap-in
b Under Available snap-ins, select  and click Add.
c In the Certicates snap-in window, select Computer account, click Next, and click Finish.
d In the Add or Remove Snap-in window, click OK.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 73