in the previous article, I briefly introduced the How to configure Windows Single Sign-on in Horizon Workspace 1.8. In this blog, you'll continue to describe some of the ways you can configure for a large-scale virtual machine or virtual Desktop deployment. These configuration methods can ensure that the virtual machine or virtual desktop deployed with the template can realize horizonworkspace Single sign-on if the Workspace server-side configuration is complete and no longer requires manual configuration by the user .
1. Configure the settings of IE browser in the template Group Policy
by setting the appropriate policies in the management console on the template virtual machine, you can use the virtual machines that are subsequently cloned using the template machine automatically Windows Authentication Login Workspace Web page.
< Span style= "Font-size:16px;line-height:115%;font-family:arial, Helvetica, Sans-serif;" >a . Open a command-line window on the template virtual machine, enter the command gpedit.msc windows
b. select Span style= "FONT-SIZE:15PX;LINE-HEIGHT:115%;FONT-FAMILY:CALIBRI;" >windows settings > Administrative Templates >windows components >internet explore>internet Control Panel >
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/2D/EC/wKioL1OXyfvjX-lxAANfPBIM08o302.jpg "title=" 1.png " alt= "Wkiol1oxyfvjx-lxaanfpbim08o302.jpg"/> C.Double click"site-to-zone assignment list"Item, change the setting to Enabled. Click"Show... "button, in the Value Name column, enterhttps://<Newconnectorthe full domain name>. In the Value column, enter"1". And then tap"Determine"button.
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/2D/EC/wKiom1OXyqqhfOtRAAMu-hM-Hgo592.jpg "title=" 2.png " alt= "Wkiom1oxyqqhfotraamu-hm-hgo592.jpg"/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/2D/ED/wKioL1OXytqROQSfAAGmkQ51i3g171.jpg "title=" 3.png " alt= "Wkiol1oxytqroqsfaagmkq51i3g171.jpg"/>
D. Double-click Enable automatic detection of Intranet. To start Intranet automatic detection in configuration items
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/2D/EC/wKiom1OXy1rz5G-aAAKkpR_XI50588.jpg "title=" 4.png " alt= "Wkiom1oxy1rz5g-aaakkpr_xi50588.jpg"/>
2. If the newly created connector is using a self-signed certificate, add the Horizonworkspace newly created connector in the Windows management Console the certificate.
when used internally, internal configurations may use self-issued certificates instead of a formal trusted CA -Issued certificates. In this case, in order to avoid the login horizonworkspace page When prompted to change the site certificate is not trustworthy, you can add the newly created Connector certificate to the template virtual machine in a trusted certificate. This will not remind the user at logon that the certificate is not trustworthy.
A. log in to the newly createdconnectorManagement Interface ExportSSLcertificate. Loginhttps://<NewconnectorFull domain name>/hc/admin. UseWorkspaceAdministrator password to log in. Clickthe SSLCertificate".
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/2D/EC/wKiom1OXy9eyuH5RAAQK97OdN_g905.jpg "title=" 5.png " alt= "Wkiom1oxy9eyuh5raaqk97odn_g905.jpg"/>
will Ssl The certificate part of the last certificate is copied to . Cer file (-----begincertificate----- start to -----END CERTIFICATE-----. Cer file )
B. Open the command-line window in the template virtual machine. Enter the command MMC. file > add / Remove Snap -in. Select " certificates " and then click " add ".
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/2D/EC/wKiom1OXzI-hVyNWAAOhBCmr58Q977.jpg "title=" 6.png " alt= "Wkiom1oxzi-hvynwaaohbcmr58q977.jpg"/>
Select computer account as the management object.
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/2D/EC/wKiom1OXzN6x9PYIAAJ7MyTR81g493.jpg "title=" 7.png " alt= "wkiom1oxzn6x9pyiaaj7mytr81g493.jpg"/> select Local Computer
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/2D/EC/wKiom1OXzT-jieTaAAKa23VTa1A250.jpg "title=" 8.png " alt= "Wkiom1oxzt-jietaaaka23vta1a250.jpg"/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/2D/EC/wKiom1OXzbWSsZcdAAb1aQa1zYg282.jpg "title=" 9.png " alt= "Wkiom1oxzbwsszcdaab1aqa1zyg282.jpg"/>
Select certificate > recipient's Root certification Authority > Certificate . " Right-Click " All Tasks " > " import ". In the Certificate Import Wizard, select the . cer file that you just created .
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/2D/EC/wKiom1OXzkCjjzKzAAL2Xbms8mo206.jpg "title=" 10.png "alt=" Wkiom1oxzkcjjzkzaal2xbms8mo206.jpg "/>
in one step, you specify that the certificate is placed in Trusted Root certification authorities.
Once the import is complete, the self-signed certificate will be trusted by the template machine.
after two steps have been completed , the configuration of the Horizonworkspace client for the template virtual machine is basically complete. After you install the Horizon Workspace client on a template virtual machine and join a domain, you can start deploying virtual machines or virtual desktops in bulk with template virtual machines. In these virtual machines, users can use the Horizonworkspace Single sign-on feature without having to manually configure them. Using IE to access The Workspace page does not require a user password, but will log in directly with the domain user.