VMware Horizon Community
novell1
Enthusiast
Enthusiast

View5 SSL certificate problems on iPADs

Hi,

I have installed View5.0 and its working fine with windows clients through a F5 Big-IP Loadbalancer. I can use PCoIP on Windows-PC's. My customers is now working with iPads, and ssl is not working (with Godaddy Certificate). Now I am unsure if the problem is on the iPad, Big-IP F5 or on a configuration. The same iPad is working fine on a other View environment, therefore the problem is on the F5 Big-IP or the Viewconfiguration? Right?

Thanks for your help!!!!

Novell1

11 Replies
tidaltides
Enthusiast
Enthusiast

I am getting the similar feedback. It seems like iPad isn't compatible, but I already seen this work. I am just not sure how.

0 Kudos
Camek
Enthusiast
Enthusiast

We are using certs from Digicert and have no issue with iPad or Android client.   You can test this by going to the https://yourviewserver from the ipad browser and if you get an error make sure and check your servers have all parts the cert installed properly.

0 Kudos
cmpyx2
Enthusiast
Enthusiast

As Camek said, this is a good test, but will only be successful if you have a security server in place.  I have been working on this issue, and until VMware releases a new app in the iPad store, the best (only) solution I have found to work in the meantime is change the "certificate checking mode" in VMware View within the iPad settings.  If you try Camek's way, being that Safari is the default browser, your connection server will try to install the MAC OS version which will not work on iPads.  Hope this helps some.

0 Kudos
rgoldthwaite
Contributor
Contributor

I can also attest to this. We also have a GoDaddy cert on our F5 which works awesome on Windows clients. Just iOS devices fail to verify the cert and the only way to get it working is to change the app setting to not check certs. VMware, look into this please!!!:smileysilly:

0 Kudos
novell1
Enthusiast
Enthusiast

Hallo,

bin abwesend, kann daher auf Ihre Mails nicht antworten.

Bei dringenden Störungen wenden Sie sich bitte beim helpdesk@redit.ch

0848 000 801 zu Standard Servicezeiten

Besten Dank!

0 Kudos
rgoldthwaite
Contributor
Contributor

Another interesting fact is if i tether my iphone to my laptop. i get the same issue on my laptop!

0 Kudos
jaimetaylorpdx
Contributor
Contributor

I'm experiencing this as well.  I've worked with two clients implementing View recently, one using GoDaddy and the other using Verisign.  The GoDaddy client works fine from iOS devices.  The Verisign one produces a certificate error from the iPhone and iPad View clients.  However, browsing to https://view.company.com DOES NOT produce an error.  That indicates that iOS trusts the verisign certificate but the View Client does not. I also tried manually installing the Verisign root and intermediate certificates to no avail.  Needless to say, connections from all other device types work as expected.

Has anyone opened a case with VMware and if so, what have they said about this?

0 Kudos
Cavin
VMware Employee
VMware Employee

It's strange... As far as I know, your iPhone cannot impact the network status of your laptop.

0 Kudos
SabrinaHou
Enthusiast
Enthusiast

It seems this is the configuration error on View Connection Server because the certficate file imported on View Connection Server doesn't include the entire cert chain.

Make sure the View Connection Server imported certificate file which contains the entire certification chain. If the View Connection Server cannot return the full cert chain, the iOS client cannot verify it. This is based on the SSL standard. (The SSL server should return the whole cert chain). You may run into above error.

Please try below command to print the cert chain. Make sure it contains entire cert chain.

openssl s_client -showcerts -connect [ViewConnectionServer:443]

jaimetaylorpdx
Contributor
Contributor

Thanks for the guidance SabrinaHou, that was in fact the issue.  The key seems to be that you must include all certs in the pfx file and select the "automatically place certs in the appropriate store" when importing into the servers.  I'd manually imported the Root and Intermediate certs and it worked for everything other than the iOS View Client.  I went back and re-imported with all certs in the pfx file and it now works for iOS as well. 

0 Kudos
novell1
Enthusiast
Enthusiast

Hallo,

bin abwesend, kann daher auf Ihre Mails nicht antworten.

Bei dringenden Störungen wenden Sie sich bitte beim helpdesk@redit.ch

0848 000 801 zu Standard Servicezeiten

Besten Dank!

0 Kudos