3 thoughts on ““Server certificate for metadata file URL is not trusted” – What’s going on in Horizon Agent Update?”

  1. Taomyn says:

    And what if the certificate provider is no longer providing new or renewed certificates with client EKUs? This is the case for both DigiCert and Sectigo now, and more in the industry will follow soon.

    1. Ciao I don’t know your infrastructure, but I imagine you’re using an internal repository for the agent installation executables and, since you’re using Horizon, you have an Active Directory infrastructure. What I can recommend is implementing a Microsoft PKI and using a certificate issued by that PKI’s Root CA to validate the URL. This way, you have more freedom in creating certificates.

Leave a Reply

Your email address will not be published. Required fields are marked *