Administration

Table Of Contents
Option Description
Metadata URL
URL for retrieving all of the information required to exchange SAML
information between the SAML identity provider and the View
Connection Server instance. In the URL https://<YOUR HORIZON SERVER
NAME>/SAAS/API/1.0/GET/metadata/idp.xml, click <YOUR
HORIZON SERVER NAME> and replace it with the FQDN of the
VMware Identity Manager server instance.
Administration URL
URL for accessing the administration console of the SAML identity
provider (VMware Identity Manager instance). This URL has the format
https://<Identity-Manager-FQDN>:8443.
6 Click OK to save the SAML authenticator conguration.
If you provided valid information, you must either accept the self-signed certicate (not recommended)
or use a trusted certicate for View and VMware Identity Manager.
The SAML 2.0 Authenticator drop-down menu displays the newly created authenticator, which is now
set as the selected authenticator.
7 In the System Health section on the View Administrator dashboard, select Other components > SAML
2.0 Authenticators, select the SAML authenticator that you added, and verify the details.
If the conguration is successful, the authenticator's health is green. An authenticator's health can
display red if the certicate is untrusted, if the VMware Identity Manager service is unavailable, or if
the metadata URL is invalid. If the certicate is untrusted, you might be able to click Verify to validate
and accept the certicate.
8 Log in to the VMware Identity Manager administration console, go to the View Pools page, and select
the Suppress Password Popup check box.
What to do next
n
Extend the expiration period of the View Connection Server metadata so that remote sessions are not
terminated after only 24 hours. See “Change the Expiration Period for Service Provider Metadata on
Connection Server,” on page 64.
n
Use the vdmutil command-line interface to congure True SSO on a connection server. See “Congure
View Connection Server for True SSO,” on page 86.
For more information about how SAML authentication works, see “Using SAML Authentication,” on
page 61.
Configure View Connection Server for True SSO
You can use the vdmutil command-line interface to congure and enable or disable True SSO.
This procedure is required to be performed on only one connection server in the cluster.
I This procedure uses only the commands necessary for enabling True SSO. For a list of all the
conguration options available for managing True SSO congurations, and a description of each option, see
“Command-line Reference for Conguring True SSO,” on page 88.
Prerequisites
n
Verify that you can run the command as a user who has the Administrators role. You can use View
Administrator to assign the Administrators role to a user. See Chapter 6, “Conguring Role-Based
Delegated Administration,” on page 99.
n
Verify that you have the fully qualied domain name (FQDN) for the following servers:
n
Connection server
View Administration
86 VMware, Inc.