Administration

Table Of Contents
Tab Action
Server tab
Select Do not store  and requests in the CA database.
I Make sure to deselect Do not include revocation
information in issued . (This box gets selected when you select
the rst one, and you have to deselect (clear) it.)
Issuance Requirements tab
n
Select This number of authorized signatures, and type 1 in the box.
n
For Policy type, select Application Policy and set the policy to
 Request Agent.
n
For, Require the following for reenrollment, select Valid existing
.
Security tab
For the security group that you created for the enrollment server computer
accounts, as described in the prerequisites, provide the following
permissions: Read, Enroll
a Click Add.
b Specify which computers to allow to enroll for certicates.
c For these computers select the appropriate check boxes to give the
computers the following permissions: Read, Enroll.
5 Click OK in the Properties of New Template dialog box.
6 Close the Certicate Templates Console window.
7 Right-click  Templates and select New >  Template to Issue.
N This step is required for all certicate authorities that issue certicates based on this template.
8 In the Enable Certicate Templates window, select the template you just created (for example, True SSO
Template) and click OK.
9 In the Enable Certicate Templates window, select Enrollment Agent Computer and click OK.
What to do next
Create an enrollment service. See “Install and Set Up an Enrollment Server,” on page 81.
Install and Set Up an Enrollment Server
You run the Connection Server installer and select the Horizon 7 Enrollment Server option to install an
enrollment server. The enrollment server requests short-lived certicates on behalf of the users you specify.
These short-term certicates are the mechanism True SSO uses for authentication to avoid prompting users
for Active Directory credentials.
You must install and set up at least one enrollment server, and the enrollment server cannot be installed on
the same host as View Connection Server. VMware recommends that you have two enrollment servers for
purposes of failover and load balancing. If you have two enrollment servers, by default one is preferred and
the other is used for failover. You can change this default, however, so that the connection server alternates
sending certicate requests to both enrollment servers.
If you install the enrollment server on the same machine that hosts the enterprise CA, you can congure the
enrollment server to prefer using the local CA. For best performance, VMware recommends combining the
conguration to prefer using the local CA with the conguration to load balance the enrollment servers. As
a result, when certicate requests arrive, the connection server will use alternate enrollment servers, and
each enrollment server will service the requests using the local CA. For information about the conguration
seings to use, see “Enrollment Server Conguration Seings,” on page 92 and “Connection Server
Conguration Seings,” on page 93.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 81