Administration

Table Of Contents
The following gure illustrates True SSO in a multiple-forest architecture.
True SSO Multi-Forest Architecture (non HA)
Enrollment
Server
Client
VMware
Identity
Manager
Appliance
CA
Enrollment
Server
Connection
Server
Domain #1 (Root Domain)Domain #2
CA
Forest #2 Forest #1
2-way, Forest Level,
Transitive Trust
ADAD
Set Up an Enterprise Certificate Authority
If you do not already have a certicate authority set up, you must add the Active Directory Certicate
Services (AD CS) role to a Windows server and congure the server to be an enterprise CA.
If you do already have an enterprise CA set up, verify that you are using the seings described in this
procedure.
You must have at least one enterprise CA, and VMware recommends that you have two for purposes of
failover and load balancing. The enrollment server you will create for True SSO communicates with the
enterprise CA. If you congure the enrollment server to use multiple enterprise CAs, the enrollment server
will alternate between the CAs available. If you install the enrollment server on the same machine that hosts
the enterprise CA, you can congure the enrollment server to prefer using the local CA. This conguration
is recommended for best performance.
Part of this procedure involves enabling non-persistent certicate processing. By default, certicate
processing includes storing a record of each certicate request and issued certicate in the CA database. A
sustained high volume of requests increases the CA database growth rate and could consume all available
disk space if not monitored. Enabling non-persistent certicate processing and can help reduce the CA
database growth rate and frequency of database management tasks.
Prerequisites
n
Create a Windows Server 2008 R2 or Windows Server 2012 R2 virtual machine.
n
Verify that the virtual machine is part of the Active Directory domain for the Horizon 7 deployment.
n
Verify that you are using an IPv4 environment. This feature is currently not supported in an IPv6
environment.
n
Verify that the system has a static IP address.
View Administration
78 VMware, Inc.