2.5

Table Of Contents
ACE Management Server Administrator’s Manual
56 VMware, Inc.
2Ifyourcertificatesrequireacertificatechaintobeverified,createacertificatechain
fileforeachcertificate.
Thecertificatechainfileisatextfilethatcontainseverycertificate(inPEMformat)
neededtoverifytheleafcertificate(includingtherootcertificateofthechain).
a Downloadtheverificationchainfromyour
certificateauthority.
b EachcertificatemustbeinPEMformatbeforeyoucreatethecertificatechain
file.
ToconverttoPEMformat,usetheopenSSLtoolsavailableonline.
c CreatethecertificatechainfilebyconcatenatingeachPEMencodedcertificate
intoonefile.
Ifbothofyourcertificatesareselfsigned,yourcertificatechainfilemust
beafilethatcontainsbothcertificatesconcatenated.
Ifyoureceivedyourcertificatesfromthesamecertificateauthority,the
chainfilemustcontainonlytheverificationchainforthesecertificates,
andthechainsmustbethesame.
Ifthecertificatescomefromdifferentcertificateauthorities,thechainfile
mustcontainbothcertificateverificationchains.
Forexample,ifyouareusingtwoACEManagementServerinstancesyouhave
twocertificatechainfiles.
3Joinallofthecertificatechainfilesintoonefile.
Ifyoucan,eliminatetheduplicateentries.
4Convert
theserversSSLcertificatestoPEMformat.
5AddtheserversSSLcertificatesinPEMformattothecertificatechainfile.
6OntheCustomSSLCertificatestab,uploadtheSSLcertificatefile,theSSLkeyfile,
andthecertificatechainfile:
aSpecifythekeyfileintheServerPrivateKeyfield.
bSpecifythecertificate
fileintheServerPublicCertificatefield.
cClickUploadcertificates.
dClickApplyandclickRestart.
CompletethisstepforeveryACEManagementServ erinyourfarmtouploadfiles
toeachACEManagementServer.