This document describes the configurations required for RADIUS integration between the Octopus Authenticator and VMware Horizon.


Integration Environment

The environment used for the integration described in this document is based on the following software versions:

  • VMware Horizon 8.1

  • Octopus Authentication Server version 5.8.2

Note: The procedures detailed in this document are relevant to all versions of the Octopus Authentication Server.


Integration Workflow

VMware Horizon integration involves the following sequential phases:

Creating the VMware Horizon RADIUS Service

The following procedure explains how to create the required RADIUS service in the Octopus Management Console. The service settings will be used later in the Horizon Connection server configuration.


To add and configure the RADIUS service:

  1. From the Octopus Management Console, select the Services menu and click Add Service. In the RADIUS tile, click Add.


    image3.png


    Then, in the dialog that opens, click Create.


    image4.png


  2. Review and configure the following settings in the General Info tab:


    Setting

    Description

    Service Name

    Display name to identify the service provider (e.g., VMware Horizon).

    Issuer

    Issuer of the service (e.g., SDO).

    Description

    Enter a brief note about the service.

    Display icon

    This icon will be displayed on the Login page for the service. To change the default icon, click and upload the image of your choice (supported size 488x488 pixels).


    image5.png


    Then, click Save.

  3. Select the Parameters tab. Open the Login Identifier list and select the identifier(s) required to log into the RADIUS service. (You can select multiple identifiers to support various platforms.)


    image6.png


  4. At the bottom of the Parameters tab, click Save.

  5. Open the Sign On tab and configure the following settings:


    Setting

    Value / Notes

    Check Password

    Verify that the setting is enabled. (When enabled, users are required to enter a password for MFA authentication.)

    Two-step Authentication

    Verify that the setting is enabled. When enabled, users enter initial credentials (e.g., username and password) first, and then supply an additional identifier (e.g., OTP) in a separate step.

    Secret

    The RADIUS secret key required for communication between the RADIUS service and Octopus Authenticator.

    Port

    The port used for communication with the RADIUS server.

    Custom Message

    The message displayed to users upon successful authentication.



    image7.png


  6. At the bottom of the Sign On tab, click Save.

  7. Open the Directories tab and select the checkboxes of the directories you want to integrate with the service. Then, click Save.


    Services_DirectoriesTab_v5_8.png


  8. Open the Users tab and click Add.


    image8.png


    A popup opens, with a list of directories displayed on the left.

  9. Expand the relevant directory and select the checkboxes of the groups and users that you want to add to the service. Then, click Save to close the popup.

    The groups and users you selected are listed in the Users tab.

  10. At the bottom of the Users tab, click Save. Then, from the toolbar at the top of the page, click PUBLISH and publish your changes.

Configuring VMware Horizon Integration

The procedure below explains how to configure VMware Horizon for integration with Secret Double Octopus.

Before you begin, make sure that you have access to the following settings from the Sign on tab of the RADIUS service that you created in the Octopus Management Console:

  • Secret

  • Port


image10.png


To configure VMware Horizon integration settings:

  1. From the VMware Horizon console, navigate to Settings > Servers. Then, at the top of the Servers page, select the Connection Servers tab.

  2. Select the relevant server and click Edit.


    image11.png


    The Edit Connection Server Settings page opens.

  3. Select the Authentication tab.

  4. Scroll to the bottom of the tab. Under 2-factor authentication, select RADIUS from the list. Then, select both of the following checkboxes:

    • Enforce -factor and Windows user name matching

    • Use the same user name and password for RADIUS and Windows authentication


    image12.png


  5. In the Authenticator section (under the checkboxes), click Manage Authenticators.

  6. From the Manage Authenticators dialog, click Add.


    image13.png


    The Add RADIUS Authenticator window opens.

  7. In the Authenticator Name field, enter a name for the service. Then, click Next.

    image14.png

  8. On the page that opens, configure the following settings:

    Setting

    Value / Notes

    Hostname/Address

    Hostname/address of the RADIUS server

    Authentication Port

    The port number configured in the Octopus RADIUS service

    Authentication Type

    Select PAP

    Shared Secret

    The secret configured in the Octopus RADIUS service



    image15.png


  9. Click Next, and then click Finish.

Running the Solution

This section describes the user experience of logging into VMware Horizon via the Octopus Authenticator. The authentication process is as follows:


  1. The user opens the Horizon Client and selects the server.


    image16.png


  2. The user enters a username and AD password, and then clicks Login.


    image17.png


    Another window then opens, in which the user is prompted to enter a code.

  3. The user enters the OTP displayed in the authentication app and clicks Login.


    image18.png


    Following successful authentication, the user is logged into VMware Horizon.


    image19.png


Appendix A: Redirecting FIDO Keys for VDI Authentication

This appendix describes how to redirect a FIDO key to the VDI for VDI FIDO authentication using Secret Double Octopus. The process involves three steps, as explained in the sections below.


Step 1: Configure the VDA Agent to Support USB Redirection


To support USB Redirection, make sure you install the USB Redirection feature when installing or modifying the Agent.


image20.png


Step 2: Enable FIDO2 USB Redirection in your Group Policy


This step is generally optional. If your environment requires this redirection, refer to the documentation on Configuring FIDO2 Redirection.


Step 3: Install the SDO Agent on your VDA Machine


To support FIDO2 authentication to the VDI, install the Octopus agent as a credential provider on the VDA machine. For details, please refer to the Octopus Desk for Windows Installation Guide.

Footer - Secret Double Octopus