6.3
Table Of Contents
- VMware vRealize Operations for Horizon Security
- Contents
- VMware vRealize Operations for Horizon Security
- Managing RMI Communication in vRealize Operations for Horizon
- Changing the Default TLS Configuration in vRealize Operations for Horizon
- Managing Authentication in vRealize Operations for Horizon
- Index
Managing Authentication in
vRealize Operations for Horizon 4
RMI servers provide a certicate that the agents use to authenticate the Horizon adapter. Broker agents use
SSL/TLS client authentication with a certicate that the Horizon adapter uses to authenticate the broker
agents. Desktop agents provide tokens that the Horizon adapter uses to authenticate the desktop agents.
To increase security, you can replace the default self-signed certicates that the Horizon adapter and broker
agents use. You can also reissue desktop authentication tokens.
This chapter includes the following topics:
n
“Understanding Authentication for Each Component,” on page 15
n
“Certicate and Trust Store Files,” on page 16
n
“Replacing the Default Certicates,” on page 18
n
“Certicate Pairing,” on page 21
n
“Reissue Horizon Desktop Authentication Tokens,” on page 21
n
“SSL/TLS and Authentication-Related Log Messages,” on page 21
Understanding Authentication for Each Component
Each vRealize Operations for Horizon component handles authentication dierently.
Horizon Adapter Authentication
When an RMI connection is established between the desktop message server and a desktop agent, or
between the broker message server and a broker agent, the agent requests a certicate from the server to
perform authentication. This certicate is validated against the agent's trust store before proceeding with the
connection. If the server does not provide a certicate, or the server certicate cannot be validated, the
connection is rejected.
When the Horizon adapter is rst installed, a self-signed certicate is generated. The desktop message
server and broker message server use this self-signed certicate by default to authenticate to their agents.
Because this certicate is generated dynamically, you must manually pair the Horizon adapter and broker
agent before the agents can communicate with the Horizon adapter. For more information, see “Certicate
Pairing,” on page 21.
VMware, Inc.
15