6.0

Table Of Contents
Workspace Manager sends the SAML artifact to the Horizon client through Workspace Gateway, which in
turn sends the artifact to the View Connection Server instance. The View Connection Server instance uses
the SAML artifact to retrieve the SAML assertion from Workspace Manager through Workspace Gateway.
After a View Connection Server instance receives a SAML assertion, it validates the assertion, decrypts the
user's password, and uses the decrypted password to launch the desktop or application.
Setting up Workspace and View integration involves configuring Workspace with View information and
configuring View to delegate responsibility for authentication to Workspace.
To delegate responsibility for authentication to Workspace, you must create a SAML authenticator in View.
A SAML authenticator contains the trust and metadata exchange between View and Workspace. You
associate a SAML authenticator with a View Connection Server instance.
NOTE If you intend to provide access to your desktops and applications through Workspace, verify that you
create the desktop and application pools as a user who has the Administrators role on the root access group
in View Administrator. If you give the user the Administrators role on an access group other than the root
access group, Workspace will not recognize the SAML authenticator you configure in View, and you cannot
configure the pool in Workspace.
Configure SAML Authenticators in View Administrator
To launch remote desktops and applications from Workspace, you must create a SAML authenticator in
View Administrator. A SAML authenticator contains the trust and metadata exchange between View and
Workspace.
You associate a SAML authenticator with a View Connection Server instance. If your deployment includes
more than one View Connection Server instance, you must associate the SAML authenticator with each
instance.
Prerequisites
n
Verify that Workspace is installed and configured. See the VMware Workspace Portal Installation and
Configuration Guide.
n
Verify that the root certificate for the signing CA for the SAML server certificate is installed on the View
Connection Server host. VMware does not recommend that you configure SAML authenticators to use
self-signed certificates. For information about certificate authentication, see the View Installation
document.
n
Make a note of the FQDN or IP address of the Workspace Gateway server or external-facing load
balancer.
n
(Optional) Make a note of the URL of the Workspace Connector Web interface.
Procedure
1 In View Administrator, select View Configuration > Servers.
2 On the Connection Servers tab, select a View Connection Server instance to associate with the SAML
authenticator and click Edit.
View Administration
54 VMware, Inc.