Administration

Table Of Contents
Following is a list tasks you must perform to set up your environment for True SSO:
1 “Determining an Architecture for True SSO,” on page 76
2 “Set Up an Enterprise Certicate Authority,” on page 78
3 “Create Certicate Templates Used with True SSO,” on page 80
4 “Install and Set Up an Enrollment Server,” on page 81
5 “Export the Enrollment Service Client Certicate,” on page 83
6 “Congure SAML Authentication to Work with True SSO,” on page 85
7 “Congure View Connection Server for True SSO,” on page 86
Determining an Architecture for True SSO
To use True SSO, you must have or add a certicate authority and create an enrollment server. These two
servers communicate to create the short-lived Horizon virtual certicate that enables a password-free
Windows logon. You can use True SSO in a single domain, in a single-forest with multiple domains, and in a
multiple-forest, multiple-domain setup.
VMware recommends to have two CAs and two ESs deployed to use True SSO. The following examples
illustrate True SSO in dierent architectures.
The following gure illustrates a simple True SSO architecture.
Certificate Authority
Very Simple True SSO Architecture
Enrollment Server
Connection Server
VMware Identity
Manager Appliance
Client
SAML Trust
AD
The following gure illustrates True SSO in a single domain architecture.
View Administration
76 VMware, Inc.