Administration

Table Of Contents
2 To configure Enrollment Agent Computer, on the machine that you are using for the certificate
authority, log in to the operating system as an administrator and go to Administrative Tools >
Certification Authority.
a Expand the tree in the left pane, right-click Certificate Templates and select Manage.
b Locate and open the Enrollment Agent Computer template and then make the following change
on the Security tab:
For the security group that you created for the enrollment server computer accounts, as
described in the prerequisites, provide the following permissions: Read, Enroll
1 Click Add.
2 Specify which computers to allow to enroll for certificates.
3 For these computers select the appropriate check boxes to give the computers the following
permissions: Read, Enroll.
c Right-click Certificate Templates and select New > Certificate Template to Issue.
Note This step is required for all certificate authorities that issue certificates based on this
template.
d In the Enable Certificate Templates window, select Enrollment Agent Computer and click OK.
What to do next
Create an enrollment service. See Install and Set Up an Enrollment Server.
Install and Set Up an Enrollment Server
You run the Connection Server installer and select the Horizon 7 Enrollment Server option to install an
enrollment server. The enrollment server requests short-lived certificates on behalf of the users you
specify. These short-term certificates are the mechanism True SSO uses for authentication to avoid
prompting users for Active Directory credentials.
You must install and set up at least one enrollment server, and the enrollment server cannot be installed
on the same host as View Connection Server. VMware recommends that you have two enrollment
servers for purposes of failover and load balancing. If you have two enrollment servers, by default one is
preferred and the other is used for failover. You can change this default, however, so that the connection
server alternates sending certificate requests to both enrollment servers.
If you install the enrollment server on the same machine that hosts the enterprise CA, you can configure
the enrollment server to prefer using the local CA. For best performance, VMware recommends
combining the configuration to prefer using the local CA with the configuration to load balance the
enrollment servers. As a result, when certificate requests arrive, the connection server will use alternate
enrollment servers, and each enrollment server will service the requests using the local CA. For
information about the configuration settings to use, see Enrollment Server Configuration Settings and
Connection Server Configuration Settings.
View Administration
VMware, Inc. 92