7.1

Table Of Contents
4 Change the owner of the domain_krb.properties le to horizon and group to www using the following
command:
chown horizon:www /usr/local/horizon/conf/domain_krb.properties
5 Restart the service.
service horizon-workspace restart
Troubleshooting domain_krb.properties
Use this information to troubleshoot the domain_krb.properties le.
"Error resolving domain" error
If the domain_krb.properties le already includes an entry for a domain, and you try to create a new
directory of a dierent type for the same domain, an "Error resolving domain" error occurs. You must edit
the domain_krb.properties le and manually remove the domain entry before creating the new directory.
Domain controllers are unreachable
Once a domain entry is added to the domain_krb.properties le, it is not updated automatically. If any
domain controllers listed in the le become unreachable, edit the le manually and remove them.
Managing Access Policies
The Directories Management policies are a set of rules that specify criteria that must be met for users to
access their app portal or to launch specied Web applications.
You create the rule as part of a policy. Each rule in a policy can specify the following information.
n
The network range, where users are allowed to log in from, such as inside or outside the enterprise
network.
n
The device type that can access through this policy.
n
The order that the enabled authentication methods are applied.
n
The number of hours the authentication is valid.
n
Custom access denied message.
N The policies do not control the length of time that a Web application session lasts. They control the
amount of time that users have to launch a Web application.
The Directories Management service includes a default policy that you can edit. This policy controls access
to the service as a whole. See Applying the Default Access Policy,” on page 113. To control access to specic
Web applications, you can create additional policies. If you do not apply a policy to a Web application, the
default policy applies.
Configuring Access Policy Settings
A policy contains one or more access rules. Each rule consists of seings that you can congure to manage
user access to their application portals as a whole or to specied Web applications.
Network Range
For each rule, you determine the user base by specifying a network range. A network range consists of one
or more IP ranges. You create network ranges from the Identity & Access Management tab, Setup > Network
Ranges page prior to conguring access policy sets.
Configuring vRealize Automation
96 VMware, Inc.