Administration

Table Of Contents
What to do next
n Extend the expiration period of the Connection Server metadata so that remote sessions are
not terminated after only 24 hours. See Change the Expiration Period for Service Provider
Metadata on Connection Server.
n Use the vdmutil command-line interface to configure True SSO on a connection server. See
Configure Horizon Connection Server for True SSO.
For more information about how SAML authentication works, see Using SAML Authentication.
Configure Horizon Connection Server for True SSO
You can use the vdmutil command-line interface to configure and enable or disable True SSO.
This procedure is required to be performed on only one Connection Server in the cluster.
Important This procedure uses only the commands necessary for enabling True SSO. For a list of
all the configuration options available for managing True SSO configurations, and a description of
each option, see Command-line Reference for Configuring True SSO.
Prerequisites
n Verify that you can run the command as a user who has the Administrators role. You can use
Horizon Administrator to assign the Administrators role to a user. See Chapter 6 Configuring
Role-Based Delegated Administration.
n Verify that you have the fully qualified domain name (FQDN) for the following servers:
n Connection Server
n Enrollment server
For more information, see Install and Set Up an Enrollment Server.
n Enterprise certificate authority
For more information, see Set Up an Enterprise Certificate Authority.
n Verify that you have the Netbios name or the FQDN of the domain.
n Verify that you have created a certificate template. See Create Certificate Templates Used with
True SSO.
n Verify that you have created a SAML authenticator to delegate authentication to VMware
Identity Manager. See Configure SAML Authentication to Work with True SSO.
Horizon 7 Administration
VMware, Inc. 109