7.0

Table Of Contents
On View Connection Server, the new setting takes effect immediately. You do not need to restart the View
Connection Server service or the client computer.
Setting Up True SSO
With the True SSO (single sign-on) feature, after users log in to VMware Identity Manager using a smart
card or RSA SecurID or RADIUS authentication, users are not required to also enter Active Directory
credentials in order to use a remote desktop or application.
If a user authenticates by using Active Directory credentials, the True SSO feature is not necessary, but you
can configure True SSO to be used even in this case, so that the AD credentials that the user provides are
ignored and True SSO is used.
When connecting to a virtual desktop or remote application, users can select to use either the native Horizon
Client or HTML Access.
This feature has the following limitations:
n
This feature does not work for virtual desktops that are provided by using the View Agent Direct
Connection plug-in.
n
This feature is supported only in IPv4 environments.
Following is a list tasks you must perform to set up your environment for True SSO:
1 “Determining an Architecture for True SSO,” on page 67
2 “Set Up an Enterprise Certificate Authority,” on page 70
3 “Create Certificate Templates Used with True SSO,” on page 71
4 “Install and Set Up an Enrollment Server,” on page 73
5 “Export the Enrollment Service Client Certificate,” on page 74
6 “Configure SAML Authentication to Work with True SSO,” on page 76
7 “Configure View Connection Server for True SSO,” on page 78
Determining an Architecture for True SSO
To use True SSO, you must have or add a certificate authority and create an enrollment server. These two
servers communicate to create the short-lived Horizon virtual certificate that enables a password-free
Windows logon. You can use True SSO in a single domain, in a single-forest with multiple domains, and in
a multiple-forest, multiple-domain setup.
VMware recommends to have two CAs and two ESs deployed to use True SSO. The following examples
illustrate True SSO in different architectures.
The following figure illustrates a simple True SSO architecture.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 67