2.5

Table Of Contents
ACE Management Server Administrator’s Manual
48 VMware, Inc.
QueryUserDomainThedomainmustbethedomainforwhichtheLDAP
hostisadomaincontroller.
AdminGroupDNandHelpDeskGroupDN(Optional)Enterthe
distinguishednameforthesegroups,whichyoucreatedforthispurposein
ActiveDirectory(forexample,cn=Users,dc=simplecorp,dc=com).
Ifthisoptionisnotenabled,anyonewhologsintotheHelpDeskapplication
mustbeamemberoftheACE
Administratorsgroup.
HelpDeskRoleorGroupDNCreatingaHelpDeskroleallowsyoutopermit
certainuserstoperformHelpDesktasksfromtheHelpDeskapplication.Usersin
thisrolecannotaccessotheradministrativetools.YoucanstilllogintotheHelp
DeskWebapplicationwithyouradministrative
LDAPcredentialsorlocal
Administratorpassword.
IfyoumakechangestotheinformationontheAccessControltab,youmustclick
ApplyorCancelbeforeyoucannavigatetoanothertab.
Uploading Custom SSL Certificates
TohaveACEManagementServerusecustomSSLcertificates,eitheryourown
selfsignedcertificatesorthoseofathirdpartyorinternalCA(certificateauthority),
usetheCustomSSLCertificatestabtouploadthePEMencodedfiles.
BeforeyoucanuploadcustomSSLcertificates,youmustcreateandrenamethe
certificatefiles.See“PrepareCustomSecurityCertificates”onpage 44.
Bydefault,duringACEManagementServerinstallation,thefollowingtwofilesare
created:
server.keyThisRSA1024bitkeyistheprivatekey.
server.crtThisselfsignedcertificateisvalidfor10yearsfromthedateandtime
atwhichtheserverisinstalled.Itssignatureisverifiedbythepublickey,whichis
embeddedinthecertificate.ThecertificatefileisencodedinPEMformat.
WhenyourunanACEinstance,
theVMwarePlayerapplicationusesthecomplete
certificationchainthatisincludedinitspackage,notonthehost,toverifyconnections
madetoACEManagementServer.Therefore,theuseofselfsignedcertificatesis
adequateformostsecurityneeds.FormoreinformationabouthowVMwareACEuses
securitycertificates,see
“UsingSSLCertificatesandProtocol”onpage 21.
WhenyouclickUploadcertificates,asummarypagedisplaysthefilesandlocations
youspecifyonthistab.Notethelocationofanybackupfiles.Youmightneedtousethe
backupifyoufindthatthenewfileisinv alidwhenyou
clickApply.See“Restorea
BackupCopyofanSSLCertificate”onpage 72.