2.5

Table Of Contents
VMware, Inc. 73
Chapter 7 Troubleshooting and Maintenance
Configuring Multiple ACE Management Server Instances
to Use SSL
YoumightconfiguremultipleACEManagementServerinstancestouseSSLinthe
followingscenarios:
Multipleserversbehindoneormoreproxyservers:
EachservercanhaveitsownSSLkeyandcertificate(ACEManagement
Serverandproxyserver).
Thecert_chainfilemustcontainthecertificatefileandverificationchainfor
theSSLcertificatesthattheproxyserversareusing.Placethiscert_chainfile
ineachACEManagementServer.
Whenselfsignedcertificatesarebeingused,theactualcertificateisthe
verificationchain.Thechainfilecontainseachselfsignedcertificatebeingthat
theproxiesareusing.
Youcanalsousethesamekeyandcertificateforeveryserverandproxy.Inthis
case,youdonotneedtocreateacert_chainfile.
Eachcertificatemusthaveauniquecommonname.
MultipleserversusingDNSroundrobin:
EachservercanhaveitsownSSLkeyandcertificate(ACEManagement
Serverandproxyserver).
Thecert_chainfilemustcontainthecertificateandverificationchainfor
everycertificatethattheserversuse.Placethiscertificatechainfileineach
ACEManagementServer.
Whenselfsignedcertificatesarebeingused,theactualcertificateisthe
verificationchain.Thechainfilecontainseachselfsignedcertificatethateach
oftheserversisusing.
Youcanusethesamekeyandcertificateforeveryserver.Inthiscase,youdo
notneedtocreateacert_chainfile.
Seealso“LoadBalancingMultipleACEManagementServerInstances”on
page 51.