3 Replies Latest reply on Apr 23, 2014 1:11 PM by rtindall

    workspace agent sign-in error "unable to get local issuer certificate"

    MMAgeek Enthusiast

      We are running Horizon Workspace 1.5 and Agents 1.5.2. The users are Windows 7 linked clones. Workspace SSL cert is a GlobalSign cert. The full chain is presented on the load balancer and connector VA including the server, intermediate and root CA certs.

      User access to the internet (ie to verify the Root CA) is via a proxy server that uses their AD credentials. IE is configured via group policy to use this proxy. proxy is bypassed for internal LAN connectivity to Workspace.

       

      If a user opens the workspace URL https://workspace.domain.org  using Internet Explorer they get no SSL certificate errors and it validates the complete SSL chain.

      When the user opens the workspace agent they get an error prior to logging on "unable to get local issuer certificate". Once they accept this error and login they never see it again - unless they log out of workspace and need to log in again

       

      Is it possible that the workspace agent is not using the IE proxy configuration initially, hence the reason it cannot validate the SSL chain?

       

      How can we resolve this? Its not breaking anything but we are getting helpdesk calls sometimes about this.