Skip to content

BIOLNX

vmvirtual.blog

Menu

  • EUC
vExpert Badge
vExpert Badge

Recent Posts

  • Converge vSphere 8 to VMware vSphere Foundation 9.1.x
  • Register VCF Operations and Your License Server in Connected Mode
  • Start a New vSphere Foundation Deployment by Using the VCF Installer Deployment Wizard
  • SaaS License Activation for Omnissa Horizon without EDGE Gateway
  • App Volumes: VHD in-Guest vs Standard Mode

Recent Comments

  • fabio1975 on Migrating Horizon from VMware to Omnissa: Why a Parallel Connection Server Deployment Is Often the Safest Approach
  • Chris on Migrating Horizon from VMware to Omnissa: Why a Parallel Connection Server Deployment Is Often the Safest Approach
  • fabio1975 on Replacing the Self-Signed Certificate on Omnissa Connection Server with a Microsoft CA-Issued Certificate (or replacing the certificate to end to validation date)
  • Pete on Replacing the Self-Signed Certificate on Omnissa Connection Server with a Microsoft CA-Issued Certificate (or replacing the certificate to end to validation date)
  • Taomyn on “Server certificate for metadata file URL is not trusted” – What’s going on in Horizon Agent Update?

Archives

  • September 2026
  • August 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • August 2023
  • July 2023
  • May 2023
  • April 2023
  • March 2023
  • January 2023
  • December 2022
  • November 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • November 2017
  • October 2017
  • April 2017
  • May 2016
  • March 2016
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • May 2015
  • April 2015
  • February 2015
  • January 2015
  • June 2014
  • April 2014
  • November 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • August 2011
  • July 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • October 2010
  • September 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • December 2009
  • June 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007

Categories

  • APP VOLUMES
  • EUC
  • NSX ALB
  • SCRIPT
  • SSL
  • Uncategorized
  • VMware
  • vSAN

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Server certificate for metadata file URL is not trusted

“Server certificate for metadata file URL is not trusted” – What’s going on in Horizon Agent Update?

October 2, 2025 fabio1975Agent, Agent Update, Client Authentication, Horizon, Horizon Agent Upgrade, OMNISSA, Powershell Script, Server certificate for metadata file URL is not trusted, Trust Certificate3 Comments

.

If you’ve ever tried to configure Horizon Agent Update in your Omnissa Horizon Connection Server, you might have run into this not-so-friendly error message:

“Server certificate for metadata file URL is not trusted.”

At first sight, it sounds like your Connection Server simply doesn’t like your certificate – but the truth is a little more subtle. Let’s dig in.

.

What happens

You configure your metadata file URL, you make sure HTTPS is in place, you test the connection… and boom, Horizon refuses to trust your certificate. You double-check:

• The certificate is valid ✅
• Issued by a trusted CA ✅
• The chain looks perfectly fine in your browser ✅

So why is Horizon being so picky?

.

Missing Certificate Usage

Here’s the trick: Horizon Agent Update doesn’t just expect a server certificate with the classic “Server Authentication” usage. Nope, it also expects the certificate to include “Client Authentication” in its Enhanced Key Usage (EKU).

That’s right – your poor certificate is standing at the door with only the “Server Authentication” pass, while the bouncer (Horizon Connection Server) insists it needs both passes to get in.

.

.

The Fix

The solution is simple once you know it:

1. Make sure the SSL certificate you’re using on the web server hosting the metadata file has both:
◦ Server Authentication (1.3.6.1.5.5.7.3.1)
◦ Client Authentication (1.3.6.1.5.5.7.3.2)
2. Reissue or regenerate the certificate with the proper EKU values. (For example, a normal WebServer template certificate doesn’t have Client Authentication)
3 . Install it on the server and restart services if needed.
4. Retry the configuration in Horizon Connection Server – this time, it should work like a charm.

.

Message Error

Where are the EKU values when enrolling for a certificate from Microsoft CA

A screenshot of a computer

AI-generated content may be incorrect.

 

A screenshot of a computer

AI-generated content may be incorrect.

How to verify the EKU

You can use this powershell script

#Check EKUs of a certificate in the Local Machine\My store
# Replace "yourcert.domain.com" with your certificate subject

$cert = Get-ChildItem -Path Cert:\LocalMachine\My | Where-Object { $_.Subject -like "*yourcert.domain.com*" }
if (-not $cert) {
    Write-Host "Certificate not found!" -ForegroundColor Red
    return
}

Write-Host "Checking EKUs for certificate:" $cert.Subject -ForegroundColor Cyan
$requiredEKUs = @(
"1.3.6.1.5.5.7.3.1", # Server Authentication
"1.3.6.1.5.5.7.3.2" # Client Authentication
)

$certEKUs = $cert.EnhancedKeyUsageList | ForEach-Object { $_.ObjectId }
foreach ($eku in $requiredEKUs) {
   if ($certEKUs -contains $eku) {
      Write-Host "✅ Found EKU: $eku" -ForegroundColor Green
      } else {
      Write-Host "❌ Missing EKU: $eku" -ForegroundColor Red
    }
}

.

.

.

Conclusion

So the next time Horizon Agent Update gives you the “not trusted” cold shoulder, don’t just stop at the usual certificate checks. Verify the Enhanced Key Usage and make sure your certificate is dressed up for both server and client roles.

Sometimes, even certificates need a little multitasking spirit! 😉

.

“Server certificate for metadata file URL is not trusted” – What’s going on in Horizon Agent Update?
Proudly powered by WordPress | Theme: Minnow by WordPress.com.