Administration

Table Of Contents
What to do next
Extend the expiration period of the Connection Server metadata so that remote sessions are not terminated
after only 24 hours. See “Change the Expiration Period for Service Provider Metadata on Connection
Server,” on page 64.
Configure Proxy Support for VMware Identity Manager
Horizon 7 provides proxy support for the VMware Identity Manager (vIDM) server. The proxy details such
as hostname and port number can be congured in the ADAM database and the HTTP requests are routed
through the proxy.
This feature supports hybrid deployment where the on-premise Horizon 7 deployment can communicate
with a vIDM server that is hosted in the cloud.
Prerequisites
Procedure
1 Start the ADSI Edit utility on your Connection Server host.
2 Expand the ADAM ADSI tree under the object path:
cd=vdi,dc=vmware,dc=int,ou=Properties,ou=Global,cn=Common Attributes.
3 Select Action > Properties, and under the pae-NameValuePair aribute, add the new entries
pae-SAMLProxyName and pae-SAMLProxyPort.
Change the Expiration Period for Service Provider Metadata on Connection
Server
If you do not change the expiration period, Connection Server will stop accepting SAML assertions from the
SAML authenticator, such as Unied Access Gateway or a third-party identity provider, after 24 hours, and
the metadata exchange must be repeated.
Use this procedure to specify the number of days that can elapse before Connection Server stops accepting
SAML assertions from the identity provider. This number is used when the current expiration period ends.
For example, if the current expiration period is 1 day and you specify 90 days, after 1 day elapses,
Connection Server generates metadata with an expiration period of 90 days.
Prerequisites
See the Microsoft TechNet Web site for information on how to use the ADSI Edit utility on your Windows
operating system version.
Procedure
1 Start the ADSI Edit utility on your Connection Server host.
2 In the console tree, select Connect to.
3 In the Select or type a Distinguished Name or Naming Context text box, type the distinguished name
DC=vdi, DC=vmware, DC=int.
4 In the Computer pane, select or type localhost:389 or the fully qualied domain name (FQDN) of the
Connection Server host followed by port 389.
For example: localhost:389 or mycomputer.example.com:389
5 Expand the ADSI Edit tree, expand OU=Properties, select OU=Global, and double-click CN=Common
in the right pane.
View Administration
64 VMware, Inc.