Replacing the Public Certificate on Your Omnissa Unified Access Gateways

.

Close-up of a screen with a lock and text

AI-generated content may be incorrect.So, you’ve got your shiny new public SSL certificate, and it’s time to make your Unified Access Gateways (UAGs) happy. Excellent choice — a properly installed certificate keeps your users safe, your browser warnings quiet, and your security team smiling.

.

In this post, I’ll walk you through how to replace or install a new public certificate on your Omnissa Unified Access Gateways.
We’ll use a
PFX (PKCS#12) certificate file, since it neatly bundles the private key, certificate, and intermediates in one convenient package.

.

My Preferred Setup

I like to keep things clean and consistent, so instead of juggling multiple certificates, I use a single public certificate for all Unified Access Gateways in my deployment.

Here’s the trick:
When generating or requesting your certificate, make sure the
Subject Alternative Name (SAN) section includes:

• The VIP used to access the UAGs through the load balancer (Normally, a public FQDN)

If you use the UAGs for internal access (for network segmentation), I suggest adding to SAN the internal UAG FQDN.

.

🔧 Step-by-Step: Installing the Certificate

(Insert screenshots of each step here)

1.Log in to the UAG admin console
Open your browser and connect to the UAG admin interface:
2.https://<UAG-FQDN>:9443/admin

A screenshot of a login form

AI-generated content may be incorrect.

Sign in with your admin credentials.

A screen shot of a computer

AI-generated content may be incorrect.

3.Go to the TLS/SSL Settings
From the left menu, navigate to:

System Configuration → TLS Server Certificate Settings

A screenshot of a computer

AI-generated content may be incorrect.

4. Prepare your PFX file
You should already have your .
pfx file ready, containing:
◦ Your public certificate
◦ Any intermediate certificates
◦ Your private key

You’ll also need the PFX password you set when exporting the file.

5 .Import the new certificate
In the TLS configuration page, click
Select PFX, browse to your certificate file, and enter the password.
Then hit
Save at the bottom of the page.

A screenshot of a computer

AI-generated content may be incorrect.

A green rectangle with black text

AI-generated content may be incorrect.

6. Wait for the magic
The Unified Access Gateway will automatically restart the Edge service to apply the new certificate.

Grab a coffee ☕ — it only takes a few seconds.
7 .Verify everything works
Once the UAG is back online, open the VIP URL in your browser
or Horizon Client and check the certificate details.
Browser

A screenshot of a computer

AI-generated content may be incorrect.

Horizon Client

A screenshot of a login screen

AI-generated content may be incorrect.

.

Bonus Tips

• Consistency is key: Replace the certificate across all your UAGs (behind the same Public FQDN).
• Backup the old cert: Always keep a copy of the previous working certificate — just in case something goes sideways.
• Keep a note of the certificate expiration date and plan your next renewal ahead of time (trust me, future-you will thank you).
IMPORTANT: Once you’ve changed the certificate, always verify that it works. Especially if you have thin clients, make sure they have loaded the necessary certificates (RootCA and SubCA) to validate the new certificate.

. That’s It!

You’ve successfully installed a new public certificate on your Omnissa Unified Access Gateways.
Your users now enjoy secure, trusted access — and you get the satisfaction of another clean green padlock in the browser.

.

Replacing the Public Certificate on Your Omnissa Unified Access Gateways