Lab 5: Apply recommended configuration to the Connection Server

Objective and Tasks

In this lab, you will apply additional recommended configuration to the Connection Server. The tasks and steps outlined here would normally be repeated on each additional Connection Server.

  1. Login to the Horizon admin console.
  2. Configure the gateway services.
  3. Replace the self‑signed certificate with signed a TLS certificate.
  4. Validate system health.
Expand or collapse content Task 1: Login to the Horizon admin console
  1. Open the Horizon admin console for horizon-01a.
    • On your ControlCenter desktop, open the Google Chrome browser.
    • Click the bookmark on the bookmark bar for Horizon-01a
    • This will connect you to the Horizon administrator console at https://horizon-01a.omnissatraining.com/admin
  2. Login to the Horizon admin console.
    • Username: administrator
    • Password: Pa$$w0rd
    • Domain: OmnissaTraining
Expand or collapse content Task 2: Configure the gateway services

The edge gateway services are enabled by default on a new Connection Server installation. Follow the steps in the Horizon admin console to disable and configure these.

  1. Edit the settings for Connection Server horizon-01a
    • Navigate to Settings > Servers
    • Select the Connection Servers tab.
    • Select the entry for HORIZON-01A and click EDIT.
  2. Configure the HTTP(s) Tunnel service.
    • Deselect the tick box next to Use Secure Tunnel connection to machine.
  3. Configure the PCoIP Security Gateway service.
    • Deselect the tick box next to Use PCoIP Security Gateway for PCoIP connections to machine.
    • This should already be deselected in the version of Horizon 8 being used in the lab.

Use PCoIP Security Gateway should already be deselected in the version of Horizon 8 being used in the lab.

  1. Configure the Blast Secure Gateway service.
  2. Click OK to save the configuration.
Expand or collapse content Task 3: Add the signed TLS certificate to the Connection Server

RDP to the Connection Server and use the Microsoft Management Console (MMC) with the Certificate Snap-in to import the signed TLS certificate, replacing the use of the self-signed one.

  1. Use RDP to connect to horizon-01a
    • On your ControlCenter desktop open the RDP folder.
    • Click the RDP shortcut to horizon-01a
    • This will automatically log you into the horizon-01a VM.
  2. Open the Microsoft Management Console (MMC) on horizon-01a, so that you can work with certificates.
    • In Windows > Start > Run > MMC
    • Use the File menu and select Add/Remove Snap-in.
    • Select Certificates and Add.
    • Select Computer account and click Next.
    • Leave the default selection of Local computer and click Finish.
    • Click OK.

A self-signed certificate is created when the Connection Server is installed. Changing the friendly name to something other than vdm means that it is no longer used. You could just delete the self-signed certificate but retaining it gives you the option of switching back to use it if you need to troubleshoot issues while importing a new certificate.

  1. Update the self-signed certificate so that it is no longer used.
    • Navigate to the Certificates > Personal > Certificates folder.
    • Right-click and view the Properties of the default self-signed certificate Horizon-01a.omnissatraining.com
    • Change the Friendly name to vdm-selfsigned
    • Click OK.

Import the new signed certificate.

  1. Start the import certificate wizard and select the certificate file.
    • Right-click on the Certificates folder, select All Tasks, and Import.
    • On the Welcome screen, click Next.
    • Browse to and select the signed certificate file at S:\SSL\omnissatraining\PFX\omnissatraining_with_pwd.pfx, and click Open.
    • Click Next.

By default the dialog only shows .cer and .crt file types. Change the file type selection to All Files (*.*) to see the pfx certificate file.

  1. On the Private key protection screen:
    • Password: Pa$$w0rd
    • Select the tick box next to Mark this key as exportable.
    • Click Next.
  2. On the Certificate Store screen:
    • Leave the default selection of Place all certificates in the following store of Personal.
    • Click Next.
  3. Complete the import certificate wizard.
    • Click Finish.
    • Click OK on the import status message the is displayed.

The Horizon Connection Server services use the certificate with the friendly name of vdm as the active certificate.

  1. Check that the imported signed certificate is the one that will be used by the Horizon Connection Server.
    • Right-click and view the Properties of the imported certificate *.omnissatraining.com
    • Ensure that the Friendly name is vdm
    • Click OK.
  2. Restart the Connection Server service.
    • Use the Windows Search bar and type services.
    • Launch the Services console.
    • Locate and select the entry for Omnissa Horizon Connection Server.
    • Right-click on the service and select Restart.

You might need to wait a few minutes for the services to restart before you can progress to the next task.

Expand or collapse content Task 4: Validate system health

Check everything is healthy on the new Connection Server.

  1. Open the Horizon admin console for horizon-01a.
    • On your ControlCenter desktop, open the Google Chrome browser.
    • Click the bookmark on the bookmark bar for Horizon-01a
    • This will connect you to the Horizon administrator console at https://horizon-01a.omnissatraining.com/admin

You might need to retry (reload) opening the console web page as the Connection Server services might still be restarting.

When the console loads, you should see that Chrome now trusts the Connection Server certificate. You can optionally use Chrome to view the details of the presented certificate.

  1. Login to the Horizon admin console.
    • Username: administrator
    • Password: Pa$$w0rd
    • Domain: OmnissaTraining
  2. View the status of the Connection Server.
    • Navigate to Monitor > Infrastructure.
    • Click View next to the entry for HORIZON-01A.
    • Review the status of the server, machine identity certificate, services, and connected services.

This concludes this lab.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.