Administration

Table Of Contents
What to do next
n
If you installed the enrollment server on the same machine that hosts an enterprise CA, congure the
enrollment server to prefer using the local CA. See “Enrollment Server Conguration Seings,” on
page 92.
n
If you install and set up more than one enrollment server, congure connection servers to enable load
balancing between the enrollment servers. See “Connection Server Conguration Seings,” on
page 93.
n
Pair connection servers with enrollment servers. See “Export the Enrollment Service Client Certicate,”
on page 83.
Export the Enrollment Service Client Certificate
To accomplish pairing, you can use the MMC Certicates snap-in to export automatically generated, self-
signed Enrollment Service Client certicate from one connection server in the cluster. This certicate is
called a client certicate because the connection server is a client of the Enrollment Service provided by the
enrollment server.
Enrollment Service must trust the VMware Horizon View Connection Server when it prompts the
Enrollment Servers to issue the short lived certicates for Active Directory users. Hence, the VMware
Horizon View Connection Server clusters or pods must be paired with Enrollment Servers.
The Enrollment Service Client certicate is automatically created when a Horizon 7 or later connection
server is installed and the VMware Horizon View Connection Server service starts. The certicate is
distributed through View LDAP to other Horizon 7 connection servers that get added to the cluster later.
The certicate is then stored in a custom container (VMware Horizon View Certificates\Certificates) in
the Windows Certicate Store on the computer.
Prerequisites
Verify that you have a Horizon 7 or later connection server. For installation instructions, see View Installation.
For upgrade instructions, see View Upgrades.
I Customers can use their own certicates for pairing, rather than using the self-generated
certicate created by the connection server. To do so, place the preferred certicate (and the associated
private key) in the custom container (VMware Horizon View Certificates\Certificates) in the Windows
Certicate Store on the connection server machine. You must then set the friendly name of the certicate to
vdm.ec.new, and restart the server. The other servers in the cluster will fetch this certicate from LDAP. You
can then perform the steps in this procedure.
Procedure
1 On one of the connection server machines in the cluster, add the Certicates snap-in to MMC:
a Open the MMC console and select File > Add/Remove Snap-in
b Under Available snap-ins, select  and click Add.
c In the Certicates snap-in window, select Computer account, click Next, and click Finish.
d In the Add or Remove Snap-in window, click OK.
2 In the MMC console, in the left pane, expand the VMware Horizon View  folder and select
the  folder.
3 In the right pane, right-click the certicate le with the friendly name vdm.ec, and select All Tasks >
Export.
4 In the Certicate Export wizard, accept the defaults, including leaving the No, do not export the private
key radio buon selected.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 83