Administration

Table Of Contents
This feature has the following limitations:
n
This feature does not work for virtual desktops that are provided by using the View Agent Direct
Connection plug-in.
n
This feature is supported only in IPv4 environments.
Following is a list tasks you must perform to set up your environment for True SSO:
1 Determining an Architecture for True SSO
2 Set Up an Enterprise Certificate Authority
3 Create Certificate Templates Used with True SSO
4 Install and Set Up an Enrollment Server
5 Export the Enrollment Service Client Certificate
6 Configure SAML Authentication to Work with True SSO
7 Configure View Connection Server for True SSO
Determining an Architecture for True SSO
To use True SSO, you must have or add a certificate authority and create an enrollment server. These
two servers communicate to create the short-lived Horizon virtual certificate that enables a password-free
Windows logon. You can use True SSO in a single domain, in a single-forest with multiple domains, and
in a multiple-forest, multiple-domain setup.
VMware recommends to have two CAs and two ESs deployed to use True SSO. The following examples
illustrate True SSO in different architectures.
The following figure illustrates a simple True SSO architecture.
View Administration
VMware, Inc. 85