SaaS License Activation for Omnissa Horizon without EDGE Gateway

In the latest versions of Horizon, it is recommended to use the SaaS subscription, which requires the installation of an EDGE Gateway component generated by the Omnissa Connect portal under Horizon in the customer section.

This involves the need to install a Linux VM on our vSphere environment; not for everyone is this feasible:

–Need not have connections with Cloud services
–Resource savings (CPU, RAM and disk space)
–Test environments and any POCs
–Or, as in my case, I must test the new versions of Horizon

For this last point and since I need to install version 2606 as a test, I decided to explain how to do it… step by step.

Installed my connection server on a Windows Server 2025. The first thing to do is access the administration console and activate the license:

.

.

.

Verify that you have received the activation email or that you have a Horizon SaaS subscription and that you have access to the Connect Omnissa portal

So you must log in to the Omnissa Connect portal (by opening a TAB from the Browser you are using to access the Horizon console) and authenticate on connect.omnissa.com and keep the tab open.

.

.

Enter accounts, passwords and if necessary, do MFA

.

.

A new tab will automatically open with the login already made

.

Now run

The following message will appear

.

.

And on the Horizon console, the license status will be as follows

.

.

Two important points

–Mark your calendar to reactivate your license (in the same way) before 90 days have passed
–You can switch to a license via the EDGE Gateway by simply installing the EDGE Gateway (Follow the specific procedure)

.

.

.

.

SaaS License Activation for Omnissa Horizon without EDGE Gateway

Replacing the Self-Signed Certificate on Omnissa Connection Server with a Microsoft CA-Issued Certificate (or replacing the certificate to end to validation date)

.

Let’s be honest — that shiny self-signed certificate your Omnissa Connection Server came with is fine… until your browser or Horizon client starts screaming “Untrusted!” at every login. 😅

A screenshot of a computer error AI-generated content may be incorrect.


It’s time to fix that properly — by replacing it with a trusted certificate issued by your internal Microsoft CA.

In this guide, we’ll walk through the process step-by-step, ending up with a PFX certificate you can deploy to all your Connection Servers.

.

Why One Certificate for All Connection Servers?

Because simplicity is beautiful.
Maintaining a single certificate across all your Connection Servers reduces management overhead and avoids those awkward “name mismatch” warnings.

In the certificate, we’ll include all relevant hostnames as Subject Alternative Names (SANs):

• The hostname and FQDN of each Connection Server
• The VIP name (if you’re using a load balancer for internal access)

Example SAN list (2 Connection Servers and 1 VIP):

connection01.company.local

connection02.company.local

horizon-vip.company.local

connection01

connection02

horizon-vip

.

.

Step 1: Require the certificate as a PFX File

1. The certificate will be exported into a PFX file with:
◦ Exporting the private key
◦ Protect it with a strong password
◦ Save it somewhere safe (seriously, treat it like a password)

.

Step 2: Deploy the Certificate on All Connection Servers

Now that you have your shiny, trusted .pfx file, it’s time to put it to work.

Repeat the following steps on each Connection Server:

1.Open MMC → Certificates (Local Computer) again.

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer program AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

In Personal, there is a self-signed certificate (or an old certificate) installed by the Connection Server installation process

A screenshot of a computer AI-generated content may be incorrect.

2. Import the .pfx file under:

Personal > CertificatesA screenshot of a computer AI-generated content may be incorrect.

.

A screenshot of a certificate AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

3. When prompted, provide the password you used during export and select “Mark this key as exportable….”

A screenshot of a computer screen AI-generated content may be incorrect.

A screenshot of a certificate AI-generated content may be incorrect.

4. Verify that the certificate appears in the list with the private key (the certificate icon has a key)

A screenshot of a computer AI-generated content may be incorrect.

5. Remove the friendly name VDM from the self-signed certificate or the old certificate

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

6.Add friendly name VDM to new certificate

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

A red lines with black text AI-generated content may be incorrect.

.

.

Step 3: Restart the Horizon Connection Server Service

To make the change effective:

1. Open Services.msc
2 . Restart the VMware Horizon Connection Server service.
3 . Alternatively, you can simply reboot the server if you’re feeling extra cautious.

A screenshot of a computer screen AI-generated content may be incorrect.

Once restarted, the Connection Server should automatically pick up the new certificate.

You can confirm by opening the Horizon Administrator Console in your browser and checking that your connection is now secure and trusted ✅

We need to repeat steps 4 and 5 on all Omnissa Connection servers

.

Bonus: Keeping Things Clean

• Make sure all old or expired certificates are removed from the Personal store.
• Keep a note of the certificate expiration date and plan your next renewal ahead of time (trust me, future-you will thank you).
• If the Horizon is behind the Unified Access Gateway (for external connection and network segmentation, remember to change the Thumbprint on the UAG configuration)
IMPORTANT: Once you’ve changed the certificate, always verify that it works. Especially if you have thin clients, make sure they have loaded the necessary certificates (RootCA and SubCA) to validate the new certificate.

.

Done!

You’ve successfully banished the self-signed gremlin and brought your Horizon environment into the trusted world of PKI.

From now on, your users will enjoy clean, warning-free connections — and your security team will silently thank you for doing things the right way.

.

Replacing the Self-Signed Certificate on Omnissa Connection Server with a Microsoft CA-Issued Certificate (or replacing the certificate to end to validation date)

Upgrade/Install Horizon Edge Gateway

 

The Horizon Edge Gateway allows Omnissa Horizon 8 environments to connect to the Omnissa Horizon® Cloud Service™. Deploying a Horizon Edge Gateway Appliance for Horizon 8 deployments on vSphere is accomplished by accessing the Horizon Universal Console, which is the administrative interface for the Horizon Cloud Service.

Horizon Edge Gateway Appliance is required to entitle your environment to Horizon subscription licenses, services, and management features hosted in the Horizon Control Plane Services. To enable subscription license entitlement, Horizon Edge Gateway Appliance must be deployed in each Horizon Pod.

(https://techzone.omnissa.com/resource/deploying-horizon-edge-gateway)

How any virtual appliance it is necessary to upgrade to a new version.

In my situation, I had a customer with an old version of Horizon Edge Gateway (2.3.4.1) and on the Horizon Cloud portal we saw info that said a new version of Edge

The procedure to upgrade is very simple and is like to the procedure for the first install

After click to view

A screenshot of a computer

Description automatically generated

We are redirected to the maintenance tab where it is displayed some information.

After selecting “Upgrade” we can start with the activity.

First, we need to download the last Horizon Edge Gateway Appliance.

A screen shot of a computer

Description automatically generated

We had collected the information of actual Edge deploy like

Network Configuration (such as IP Address, Gateway, NetMask and PortGroup)

Now we are ready to log in to Virtual Center where we want to deploy the Appliance with insert some information, including the fundamental paring code that we can find on this screen:

A screenshot of a computer

Description automatically generated

Shut down the old Edge Gateway.

Deploy the OVA appliance:

A screenshot of a computer

Description automatically generated

We need to insert the standard information for ova deploy and insert the paring code and the network information

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

After deploying, on the Horizon Cloud portal under Resources and Capacity, we found that the Horizon Edge is Disconnected.

A screenshot of a computer

Description automatically generated

Now it is only a question of time…. or we can force with re-validate the info by clicking on edit configuration.

The last step is to insert the information to connect the Horizon Edge to the Connection Server (on-prem deployment)

Enter on the actual Horizon Edge

A screenshot of a computer error

Description automatically generated

We need to edit the Horizon Connection Server information because it is necessary to validate the trust with the Connection Server SSL certificate and insert the password for the service User.

A screenshot of a computer

Description automatically generated

Confirm the certificate trust

A screenshot of a computer

Description automatically generated

We are waiting or forcing a refresh.

A screenshot of a computer

Description automatically generated

Upgrade/Install Horizon Edge Gateway