Administration

Table Of Contents
Configure Smart Card Authentication on Third-Party
Solutions
Third-party solutions such as load balancers and gateways can perform smart card authentication
by passing a SAML assertion that contains the smart card's X.590 certificate and encrypted PIN.
This topic outlines the tasks involved in setting up third-party solutions to provide the relevant
X.590 certificate to Connection Server after the certificate has been validated by the partner
device. Because this feature uses SAML authentication, one of the tasks is to create a SAML
authenticator in Horizon Administrator.
For information about configuring smart card authentication on Unified Access Gateway, see
Deploying and Configuring Unified Access Gateway
.
Procedure
1 Create a SAML authenticator for the third-party gateway or load balancer.
See Configure a SAML Authenticator in Horizon Administrator.
2 Extend the expiration period of the Connection Server metadata so that remote sessions are
not terminated after only 24 hours.
See Change the Expiration Period for Service Provider Metadata on Connection Server.
3 If necessary, configure the third-party device to use service provider metadata from
Connection Server.
See the product documentation for the third-party device.
4 Configure smart card settings on the third-party device.
See the product documentation for the third-party device.
Prepare Active Directory for Smart Card Authentication
You might need to perform certain tasks in Active Directory when you implement smart card
authentication.
n Add UPNs for Smart Card Users
Because smart card logins rely on user principal names (UPNs), the Active Directory accounts
of users and administrators that use smart cards to authenticate in Horizon 7 must have a
valid UPN.
n Add the Root Certificate to the Enterprise NTAuth Store
If you use a CA to issue smart card login or domain controller certificates, you must add
the root certificate to the Enterprise NTAuth store in Active Directory. You do not need to
perform this procedure if the Windows domain controller acts as the root CA.
Horizon 7 Administration
VMware, Inc. 60