Administration

Table Of Contents
f Right-click Certificate Templates and select New > Certificate Template to Issue.
Note This step is required for all certificate authorities that issue certificates based on this
template.
g In the Enable Certificate Templates window, select the template you just created (for
example, True SSO Template) and click OK.
2 To configure Enrollment Agent Computer, on the machine that you are using for the certificate
authority, log in to the operating system as an administrator and go to Administrative Tools >
Certification Authority.
a Expand the tree in the left pane, right-click Certificate Templates and select Manage.
b Locate and open the Enrollment Agent Computer template and then make the following
change on the Security tab:
For the security group that you created for the enrollment server computer accounts, as
described in the prerequisites, provide the following permissions: Read, Enroll
1 Click Add.
2 Specify which computers to allow to enroll for certificates.
3 For these computers select the appropriate check boxes to give the computers the
following permissions: Read, Enroll.
c Right-click Certificate Templates and select New > Certificate Template to Issue.
Note This step is required for all certificate authorities that issue certificates based on this
template.
d In the Enable Certificate Templates window, select Enrollment Agent Computer and click
OK.
What to do next
Create an enrollment service. See Install and Set Up an Enrollment Server.
Install and Set Up an Enrollment Server
You run the Connection Server installer and select the Horizon 7 Enrollment Server option to install
an enrollment server. The enrollment server requests short-lived certificates on behalf of the users
you specify. These short-term certificates are the mechanism True SSO uses for authentication to
avoid prompting users for Active Directory credentials.
You must install and set up at least one enrollment server, and the enrollment server cannot
be installed on the same host as View Connection Server. VMware recommends that you have
two enrollment servers for purposes of failover and load balancing. If you have two enrollment
servers, by default one is preferred and the other is used for failover. You can change this default,
however, so that the connection server alternates sending certificate requests to both enrollment
servers.
Horizon 7 Administration
VMware, Inc. 102