Specifications

Table Of Contents
View Manager Administration Guide
108 VMware, Inc.
3UnderthePersonaltab,selectthecertificateyouwishtouseandclickView.
4UndertheCertificationPathtab,selectthecertificateatthetopofthetreeandclick
ViewCertificate.
5UndertheDetailstabclickCopytoFile.YouarepresentedwiththeCertificate
ExportWizard.
6ClickNext
>Next,andenteranameandlocationforthefileyouwanttoexport.
7ClickNext.Thefileissavedasarootcertificateinthelocationspecified.
Trust Hierarchies
Ausercertificatemaybesignedaspartofatrusthierarchy—thesigningcertificatemay
itselfbesignedbyanother,higherlevel,certificate.
Whileitispermittedtouseanysigningcertificatefromanywherewithinthehierarchy,
itisbestpracticetousetheparentcertificate(theonethatactuallysigned
theuser
certificate)asyourrootcertificate.
Adding a Root Certificate to Trusted Roots on Active Directory
ThissectiondescribeshowtoimportthethirdpartyrootCAcertificatesintoboth
ActiveDirectoryandtheEnterpriseNTAuthstore.
TheproceduresdescribedbelowareonlyrequiredifyouareusingathirdpartyCAto
issuesmartcardlogonordomaincontrollercertificates—theyarenotrequiredin
environmentswhere
theWindowsDomainControlleractsastheRootCA.
To add the third-party root CA to the trusted roots in an Active Directory Group
Policy object
1ClickStart>AllPrograms>AdministrativeTools>ActiveDirectoryUsersand
Computers.
2Intheleftpane,locatethedomaininwhichthepolicyyouwanttoeditisapplied.
3Rightclickthedomain,andthenclickProperties.
4Underthe
GroupPolicytab,clicktheDefaultDomainPolicyGroupPolicyobject,
andthenclickEdit.Anewwindowisdisplayed.
N
OTEIftheusercertificateisnotpresentinthelistyoumustfirstclicktheImport
buttontomanuallyimporttheusercertificate.Oncethecertificatehasbeen
imported,selectitfromthelistandclickView.