Jump to content

UAG Cert. replacement - Horizon Client PKI vs. Thumbprint verification


Recommended Posts

Hi all,

There are 2 UAG directly connected to a 1-1 Connection server. The certificate on UAG will expire shortly. The Cert exchange went smoothly, however, to our greatest surprise, the Certificate check mode in the Horizon client had to be changed from the previously used Thumbprint verification to PKI verification. If I leave it on the Thumbprint verification used so far, the client receives the following error message after entering the credentials: "The Horizon server authentication failed. The tunnel server presented a certificate that doesn't match the expected certificate."

However, if I switch it to PKI verification, it will work again. Has anyone encountered this? What can cause this, that the certificate verification must be changed after the cert replace? The same server is signing the cert as before. We do not understand. Could the previous thumbprint be stuck somewhere, for example in ADAM?

The error also occurs through the load balancer and bypassing the load balancer, so the error may not be in the load balancer. The error does not appear when connecting directly to the connection server.

Thanks for commenting,

Mark

Link to comment
Share on other sites

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...