2.6

Table Of Contents
ACE Management Server Administrator’s Manual
36 VMware, Inc.
Creating Access Control
OntheAccessControltab,youcancreatealocalAdministratorroleandHelpDeskroleoruseActive
Directoryforauthenticatinguserswiththeseroles.
BeforeyoucanconfiguretheACEManagementServertouseadomainaccountforauthentication,youmust
createusersandgroupssothatACEManagement
ServercanconnecttotheLDAPserver.See“CreateUsers
andGroupsforIntegrationwithActiveDirectory”onpage 29.
Usethefollowinginformationtohelpyoucompletethefieldsforauthentication:
LocalaccountIfyouspecifyapasswordfortheAdministratorroleandforgetorloseit,youmustdelete
theserverconfigurationfile.Deletingthisfilesetstheserverbacktoitsinitialstate.Youmustreconfigure
theserverandsettheadministratorpasswordagain.
See“DeletetheServerConfiguration
FileandSetaNewAdministratorPasswordonpage 52.
Domainaccount(LDAP)TouseActiveDirectoryforauthentication,specifythehostandcredentials
thattheACEManagementServerusestoconnecttoandquerythedomaincontroller:
HostNameEnterafullyqualifieddomainname(forexample,ldap.vmware.com)insteadofanIP
addressorhostnamewithnoparentdomainname(forexample,ldap).
QueryUsersAMAcountNameandQueryUserPasswordUsethepasswordandshortnamefor
theuseraccountyoucreatedforthispurposeinActiveDirectory.
QueryUserDomainThedomainmustbethedomainforwhichtheLDAPhostisadomain
controller.
AdminGroupDNandHelpDeskGroupDN(Optional)Enterthedistinguishednameforthese
groups,whichyoucreatedforthispurposeinActiveDirectory(forexample,
cn=Users,dc=simplecorp,dc=com).
Ifthisoptionisnotenabled,anyonewhologsintotheHelpDeskapplicationmustbeamemberof
theACE
Administratorsgroup.
HelpDeskRoleorGroupDNCreatingaHelpDeskroleallowsyoutopermitcertainuserstoperform
HelpDesktasksfromtheHelpDeskapplication.Usersinthisrolecannotaccessotheradministrative
tools.YoucanstilllogintotheHelpDeskWebapplicationwithyouradministrative
LDAPcredentialsor
localAdministratorpassword.
IfyoumakechangestotheinformationontheAccessControltab,youmustclickApplyorCancelbeforeyou
cannavigatetoanothertab.
Uploading Custom SSL Certificates
TohaveACEManagementServerusecustomSSLcertificates,eitheryourownselfsignedcertificatesorthose
ofathirdpartyorinternalCA(certificateauthority),usetheCustomSSLCertificatestabtouploadthe
PEMencodedfiles.
BeforeyoucanuploadcustomSSLcertificates,youmustcreateandrenamethe
certificatefiles.See“Prepare
CustomSecurityCertificates”onpage 34.
Bydefault,duringACEManagementServerinstallation,thefollowingtwofilesarecreated:
server.keyThisRSA1024bitkeyistheprivatekey.
server.crtThisselfsignedcertificateisvalidfor10yearsfromthedateandtimeatwhichtheserveris
installed.Itssignatureisverifiedbythepublickey,whichisembeddedinthecertificate.Thecertificate
fileisencodedinPEMformat.
WhenyourunanACEinstance,
theVMwarePlayerapplicationusesthecompletecertificationchainthatis
includedinitspackage,notonthehost,toverifyconnectionsmadetoACEManagementServer.Therefore,
theuseofselfsignedcertificatesisadequateformostsecurityneeds.Formoreinformationabouthow
VMwareACEusessecuritycertificates,see
“UsingSSLCertificatesandProtocol”onpage 18.