2.0

Table Of Contents
VMware, Inc. 63
Chapter 4 Installing and Configuring the ACE 2 Management Server
VMwarePlayerdoesanintegritycheckofthecertificatestoreincludedinthepackage
everytimeitcommunicateswiththeserver.
TheVMwarePlayerapplicationdoesnotuseanycertificatesstoredinthehostsystem,
becausetheirintegritycannotbeverified.
BecausethePlayerdoesnottrustanycertificatesstoredon
thehostmachinethatitis
runningonandinsteadreliesonacompletecertificationchainthatisincludedinthe
ACEpackage,theuseofselfsignedcertificatesisadequateformostsecurityneeds.
If,however,yourenterpriserequirestheuseofacertificatesignedbyacertificate
authority(internal
orcommercial),youcansetupthattypeofkey/certificatepairfor
theACEpackagestouse.Acertificateauthority,orCA,isanentitythatissuesandsigns
publickeycertificates,typicallyforafee.See“SettingUpYourOwnSelfSigned
Certificates,ThirdPartySignedCertificates,orCertificates
fromanInternalCertificate
Authority,”below,fordetails.
Setting Up Your Own Self-Signed Certificates, Third-Party
Signed Certificates, or Certificates from an Internal Certificate
Authority
IfyouwanttousecustomSSLcertificates,eitheryourownselfsignedcertificatesor
thoseofathirdpartyorinternalCA(certificateauthority),youmustprovidethe
variousneededcertificate,key,and(inthecaseofCAs)certificatechainfiles.Thesefiles
mustbePEMencoded.Afteryouhave
createdorobtainedthesefiles,youplacethem
inthecorrectdirectorybyuploadingthemfromtheCustomSSLCertificatespagein
theserversetupWebapplication.
N
OTEIfyouchangethecustomSSLcertificateforyourACE2ManagementServer,
youneedtoupdatetheResourcedirectoryforallofyourexistingACEinstances.You
candothisbycreatinganddistributingacustompackagethatcontainsonlyResources.
SeeChapter8,“CreatingPackagesandDeployingThem
toUsers,”onpage187for
moreinformation.
N
OTEACE2ManagementServeronlysupportspublickeycertificatesthathavebeen
signedusingtheSHA1algorithm.Anyotheralgorithmswillresultinanerrorwhenthe
ACEisdeployed.
NOTEWorkstationACEEditiononlysupportscertificatesignaturesthatusetheSHA1
algorithmdigest.