2. Deploying and Configuring a Horizon Server POD
This lab will guide you to install Connection Servers ( Primary and Replica) which acts a broker. If this lab is not complete, you will not able to proceed further with any other labs during the session.
In this lab we will deploy and configure the primary Management Block elements that are required to get a vSphere based Horizon Platform up and running
- We will deploy a Horizon Pod in a fictitious location called Bangalore.
- The fictitious Seattle site , which is site 2 has already been deployed and configured
- In your Skillable lab environment
- Side bar
- select the Resources tab

- In your Skillable lab environment
-
Resources tab
- scroll down and select ControlCenter.techseals.co
-
Resources tab

- In your Skillable lab environment
- under Techseals\Administrator
- in the password area
- enter Pa$$w0rd
- select the Enter Icon
- in the password area
- under Techseals\Administrator
in the Resources box, click on Pa$$w0rd and your password will be entered automatically

- On the ControlCenter server desktop
- select the Remote Desktops Folder
- In the Remote Desktops folder
- open the Site 1 Folder
- select and launch Horizon-01a.rdp and login
- open the Site 1 Folder
- In the Remote Desktops folder
- select the Remote Desktops Folder

- On the Horizon-01a server
- on the Desktop
- select the software shortcut
- in the Software folder path
- browse to > Horizon > 2412
- on the Desktop

- In the Horizon\2412 folder
- select and right-click Horizon Connection Server installer
- select Open
- In the Open File - Security Warning window
- select Run
- select and right-click Horizon Connection Server installer

- In the Horizon Connection Server deploy wizard
- select Next

- In the Horizon Connection Server deploy wizard
-
Destination Folder
- select Next
-
Destination Folder

- In the Horizon Connection Server deploy wizard
-
Installation Options
- leave all configurations as default
- select Next
-
Installation Options

- In the Horizon Connection Server deploy wizard
-
Data Recovery
- next to Enter data recovery password
- enter Pa$$w0rd
- next to Re-enter password:
- enter Pa$$w0rd
- select Next
- next to Enter data recovery password
-
Data Recovery

- In the Horizon Connection Server deploy wizard
-
Firewall Configurations
- leave all configurations as default
- select Next
-
Firewall Configurations

- In the Horizon Connection Server deploy wizard
-
Initial Horizon Administrators
- leave all configurations as default
- select Next
-
Initial Horizon Administrators

- In the Horizon Connection Server deploy wizard
-
User Experience Improvement Program
- leave all configurations as default
- select Next
-
User Experience Improvement Program

- In the Horizon Connection Server deploy wizard
-
Operational Data Collection window
- select Next
-
Operational Data Collection window

- In the Horizon Connection Server deploy wizard
-
User Experience Improvement Program
- next to General
- select the dropdown
- review the deploy platforms Horizon supports
- select the dropdown
- ensure General is selected
- select Install
- next to General
-
User Experience Improvement Program

The deployment should take about 10 minutes
- In the Horizon Connection Server deploy wizard
-
Installer Completed
- select Finish
- minimize your Horizon-01a RDP session
-
Installer Completed

Omnissa best practices recommend using Subscription based licensing using Horizon Cloud Services. In Siloed or closed environments Perpetual licensing can still be used. Due to challenges with Cloud Services and limited supported features for Horizon 8 with Horizon Cloud Services, we will using Perpetual Licensing in this environment
- On your ControlCenter server
- select your Site 1 - Bangalore Chrome shortcut

- On your Chrome Site 1 Browser
- from the Favourites Bar
- select the Horizon Site 1
- from the Favourites Bar

- On your Chrome Site 1 Browser
-
Horizon Site 1
- select Advanced
- select Proceed to horizon-01a.techseals.co (unsafe)
-
Horizon Site 1

- In the Horizon login page
- in the Username area
- enter administrator
- in the Password area
- enter Pa$$w0rd
- select SIGN IN
- enter Pa$$w0rd
- in the Username area

- In the Horizon Admin console
- In the Licensing and Usage area
- under the Licensing tab
- next to ACTIVATE
- select the drop down
- from the drop down
- select Term or Perpetual license
- next to ACTIVATE
- under the Licensing tab
- In the Licensing and Usage area

- In the Activate License window
- next to License Key
- enter
- next to License Key
89095-08KTH-01PFJ-39C9K-0Z902-TWPPF
- to the right
- select VALIDATE
- In the bottom right corner
- select Save

- In the Horizon Admin Console
- in the left pane
- below Settings
- select Event Configuration
- below Settings
- in the left pane

- In the Event Configuration window
- below Event Database
- select EDIT
- below Event Database

- In the Edit Event Database window
- enter the following below
-
*Database server
- enter sql-01a.techseals.co
-
*Database Name
- enter EVENTSDB1
-
*User Name
- enter viewadmin
-
*Password
- enter Pa$$w0rd
-
*Confirm Passw0rd
- enter Pa$$w0rd
-
Table Prefix
- enter VE_
-
*Database server
-
to close the Edit Event Database window
- select OK
- enter the following below

- In the Horizon Admin Console
- In the left-pane
- expand Settings
- select Servers
- In the Servers area
- from vCenter Servers tab
- select ADD
- from vCenter Servers tab
- expand Settings
- In the left-pane

- In the Add vCenter Server wizard
- step 1 . vCenter information
- enter the following below
-
* Server address
- enter vcenter-01a.techseals.co
-
* User Name
- enter [email protected]
-
* Password
- enter Pa$$w0rd
-
* Server address
- below Deployment Type
- to the right of General
- select the dropdown
- note the various Cloud platforms a vCenter Resource Block can run on
- select the dropdown
- ensure General is selected
- to the right of General
- select NEXT
- enter the following below
- step 1 . vCenter information

- In the Invalid Certificate Detected window
- select VIEW CERTIFICATE

- In the Certificate Information window
- select ACCEPT

- In the Add vCenter Server wizard
- step 2 . Storage
- below Hosts
- next to /Region01a/host/Bangalore/esxi-01a.techseals.co
- select the radio button
- select NEXT
- next to /Region01a/host/Bangalore/esxi-01a.techseals.co
- below Hosts
- step 2 . Storage

- In the Add vCenter Server wizard
- Step 3 Ready to Complete
- select SUBMIT
- Step 3 Ready to Complete

The Horizon Administrative Console has a Certificate Admin Permissions area, before using this we need to have an admin account with the relevant permissions
- In the Horizon Admin Console
- in the left Inventory
- below Settings
- select Certificate Management
- below Settings
- in the left Inventory

- In the Certificate Management area
- Note that all configurations are greyed out
- In the Horizon Admin Console
- in the left Inventory
- below Settings
- select Administrators
- below Settings
- in the left Inventory

- In the Global Administrators View area
- select the Role Permissions tab
- to the left
- select ADD
- select the Role Permissions tab

- In the Add Role window
- below * Name
- enter CertAdmin
- below * Name

- In the Add Role window
- in the bottom right corner
- go to page 2 by selecting
- the change page Icon >
- go to page 2 by selecting
- in the bottom right corner

- In the Add Role window
- below Privilege
-
scroll down until you find
- Manage Certificates
- next to Manage Certificates
- select the Checkbox
- In the bottom right-corner
- select OK
-
scroll down until you find
- below Privilege

- In the Global Administrators View page
- select the Administrators and Groups tab
- in the Middle, down half-way
- select ADD PERMISSIONS
- in the Middle, down half-way
- select the Administrators and Groups tab

- In the Add Permissions window
- step 1 Select a role area
- scroll down until you find CertAdmin
- next to CertAdmin
- select the radio button
- in the bottom right corner
- select FINISH
- step 1 Select a role area

- In the Horizon Admin Console
- in the top right corner
- next to administrator
- select the dropdown icon
- from the dropdown
- select Log Out
- next to administrator
- in the top right corner

- In the Horizon Admin Login
- In the User Name area
- enter administrator
- in the Password area
- enter Pa$$w0rd
- select SIGN IN
- In the User Name area

- In the Horizon Admin Console
- in the left Inventory
- below Settings
- select Certificate Management
- below Settings
- in the left Inventory

- In the Certificate Management area
- Note that you now have permission to manage Certificates

- In the Certificate Management area
- Note that you have a certificate designated for Machine Identity
- Note that this certificate is not trusted

In the next Task we will update the self-signed certificate on your Horizon Server with a CA-signed certificate
- In the Certificate Management area
- select IMPORT

- In the Import Signed TLS Certificate window
- In line with *Certificate Type
- next to PFX
- select the radio button
- next to PFX
- In line with *Certificate File
- select BROWSE
- In line with *Certificate Type

- In the Open window
- In the Quick Access bar
- select Desktop
- in the middle area
- select the Software (horizon-01a) shortcut
- In the Quick Access bar

- In the Open window
-
Software folder
- go to certificates > Techseals
- select WildCard_2025.pfx
- go to certificates > Techseals
-
In the bottom right-corner
- select Open
-
Software folder

- In the Import Signed TLS Certificate window
- in line with * Password
- in the Box
- enter Pa$$w0rd
- in the Box
- in the bottom right corner
- select IMPORT
- in line with * Password

- In the Certificate Management area
- note that there are now two Machine Identity Certificates
- one is still In Use but the Status is Invalid
- one is not being is not In Use but its Status is Valid
- note that there are now two Machine Identity Certificates

- On the ControlCenter server
- switch back to your Horizon-01a RDP session

- On the Horizon-01a Connection Server
- on the Desktop
- select the CertsMMC
- on the Desktop

- In the Certificates CertsMMC
- below Certificates (Local Computer)
- expand Personal
- select Certificates
- expand Personal
- in the right pane
- select and right-click horizon-01a.techseals.co
- in the dropdown menu
- select Properties
-
In the Certificates window
- Rename the Friendly name: vdm-selfsigned
- Click OK
- below Certificates (Local Computer)

- In the CACertsSnapin
-
Certificates folder
- select and right-click the *.techseals.co certificate
- select Properties
- select and right-click the *.techseals.co certificate
-
Certificates folder

- In the *.techseals.co Properties window
-
General tab
- next to Friendly name:
- note that the friendly name vdm, has been added automatically
- In the past we had to manually write this in
- note that the friendly name vdm, has been added automatically
- select OK
- next to Friendly name:
-
General tab

- On the Horizon-01a server
- select and right-click the START button
- select Run
- select and right-click the START button

- In the Run window
- next to Open:
- enter services.msc
- select OK
- next to Open:

- On the Services window
- scroll down to Omnissa Horizon View Connection Server
- select and right click Omnissa Horizon Connection Server
- from the drop down
- select Restart
- from the drop down
- select and right click Omnissa Horizon Connection Server
- scroll down to Omnissa Horizon View Connection Server

- In the Services console
- Wait until all the Horizon services restart

then wait at least 3 minutes before doing the next step
- In the ControlCenter server
- Open your Site 1 browser
- from the Favourites bar
- select the Horizon Site 1 shortcut
- Notice your Server is now trusted using a CA-signed Certificate
- from the Favourites bar
- Open your Site 1 browser

We will first Deploy the Replica , then we will replace the self-signed certificate with a CA signed certificate
- On the ControlCenter server desktop
- select the Remote Desktops Folder
- In the Remote Desktops folder
- open the Site 1 Folder
- select and launch Horizon-01b.rdp and login
- open the Site 1 Folder
- In the Remote Desktops folder
- select the Remote Desktops Folder

- On the Horizon-01b server
- On the Desktop
- select the Software shortcut
- In the Software folder path
- browse to > Horizon > 2412
- On the Desktop

- In the Horizon\2412 folder
- select and right-click Horizon Connection Server installer
- select Open
- In the Open File - Security Warning window
- select Run
- select and right-click Horizon Connection Server installer

- In the Horizon Connection Server deploy wizard
- select Next

- In the Horizon Connection Server deploy wizard
-
Destination Folder
- select Next
-
Destination Folder

- In the Horizon Connection Server deploy wizard
-
Installation Options
- select Horizon Replica Server
- select Next
- select Horizon Replica Server
-
Installation Options

- In the Horizon Connection Server deploy wizard
-
Source Server
- next to Server:
- enter horizon-01a.techseals.co
- select Next
- next to Server:
-
Source Server

- In the Horizon Connection Server deploy wizard
-
Firewall Configurations
- leave all configurations as default
- select Next
-
Firewall Configurations

- In the Horizon Connection Server deploy wizard
-
Ready to Install the Program
- select Install
-
Ready to Install the Program

The deployment should take about 10 minutes
- In the Horizon Connection Server deploy wizard
-
Installer Completed
- select Finish
-
Installer Completed

- On your ControlCenter server
- on your Site 1 browser
- in the top right corner
- select the 3 dotted Icon
- in the top right corner
- from the dropdown
- select New Incognito window
- on your Site 1 browser

- On your Site 1, Incognito Browser session
- in the address bar
- enter https://horizon-01b.techseals.co/admin
- in the address bar

- On your Site 1, Incognito Browser session
- notice Your Horizon server certificate is not trusted
- select Advanced
- select Proceed to horizon-01b.techseals.co (unsafe)
- notice Your Horizon server certificate is not trusted

- In the Horizon Login
- in the username area
- enter administrator
- in the password area
- enter Pa$$w0rd
- select SIGN IN
- in the username area

- In the Horizon admin console
- below Settings
- select Certificate Management
- below Settings

- In the Certificate Management area
- note that your Machine Identity certificate Status is Invalid

- In the Certificate Management area
- select IMPORT

- In the Import Signed TLS Certificate window
- in line with *Certificate Type
- next to PFX
- select the radio button
- next to PFX
- in line with *Certificate File
- select BROWSE
- in line with *Certificate Type

- In the Open window
- in the Quick Access bar
- select Desktop
- in the middle area
- select the Software (horizon-01a) shortcut
- in the Quick Access bar

- In the Open window
-
Software folder
- go to certificates > Techseals
- select WildCard_2025.pfx
- go to certificates > Techseals
-
in the bottom right-corner
- select Open
-
Software folder

- In the Import Signed TLS Certificate window
- in line with * Password
- in the Box
- enter Pa$$w0rd
- in the Box
- in the bottom right corner
- select IMPORT
- in line with * Password

- In the Certificate Management area
- note that there are now two Machine Identity Certificates
- one is still In Use but the Status is Invalid
- one is not being is not In Use but its Status is Valid
- note that there are now two Machine Identity Certificates

- On the Horizon-01b Connection Server
- On the Desktop
- select the MMC shortcut
- On the Desktop

- In the Certificates Snapin
- below Certificates (Local Computer)
- expand Personal
- select Certificates
- expand Personal
- In the right pane
- select and right-click horizon-01b.techseals.co
- in the dropdown menu
- select Delete
-
In the Certificates window
- select Yes
- below Certificates (Local Computer)

- In the CertsSnapin
-
Certificates folder
- select and right-click the *.techseals.co certificate
- select Properties
- select and right-click the *.techseals.co certificate
-
Certificates folder

- In the *.techseals.co Properties window
-
General tab
- next to Friendly name:
- once again note the vdm entry has already been added
- next to Friendly name:
- select OK
-
General tab

- On the Horizon-01b server
- select and right-click the START button
- select Run
- select and right-click the START button

- In the Run window
- next to Open:
- enter services.msc
- select OK
- next to Open:

- On the Services window
- scroll down to Omnissa Horizon View Connection Server
- select and right click Omnissa Horizon View Connection Server
- from the drop down
- select Restart
- from the drop down
- select and right click Omnissa Horizon View Connection Server
- scroll down to Omnissa Horizon View Connection Server

wait at least 5 minutes before doing the next step
- In the ControlCenter server
- Open your Site 1 browser
- in the address bar
- enter horizon-01b.techseals.co/admin
- with your keyboard press enter
- enter horizon-01b.techseals.co/admin
- Notice your Server is now trusted using a CA-signed Certificate
- in the address bar
- Open your Site 1 browser

If this does not work restart your Horizon Connection server services and wait another 5 minutes
0 Comments
Add your comment