2.6

Table Of Contents
ACE Management Server Administrator’s Manual
42 VMware, Inc.
Create New SSL Certificates and Keys for Each Server
IfyoudonotwanttousethesameSSLcertificateandkeyforeachACEManagementServ er,youmustcreate
newSSLcertificatesandkeysforeachserver.
IfyouplantoobtainSSLcertificatesfromacertificateauthority,youmustcreatecertificatechains.Figure 52
providesanoverviewof
determiningwhichcertificatesareincludedinachain.
Figure 5-2. Creating the Certificate Chain File
To create new SSL certificates and keys for each server
1 CreateasmanySSLcertificateandkeypairsasyouneed(oneforeachserverinyourserverfarm).
Theprocedurevaries,dependingonthetoolsyouuse.Todeterminehowtocreatethesecertificatesand
keys,seethedocumentationfor
yourplatform.Eachcertificatemusthaveauniquecommonnameanda
uniqueserialnumber.
2Ifyourcertificatesrequireacertificatechaintobeverified,createacertificatechainfileforeachcertificate.
Thecertificatechainfileisatextfilethatcontainseverycertificate(inPEMformat)neededtoverifythe
leafcertificate(includingtherootcertificateofthechain).
a Downloadtheverificationchainfromyourcertificateauthority.
b EachcertificatemustbeinPEMformatbeforeyoucreatethecertificatechainfile.
ToconverttoPEMformat,usetheopenSSLtoolsavailableonline.
c CreatethecertificatechainfilebyconcatenatingeachPEM
encodedcertificateintoonefile.
Ifbothofyourcertificatesareselfsigned,yourcertificatechainfilemustbeafilethatcontains
bothcertificatesconcatenated.
Ifyoureceivedyourcertificatesfromthesamecertificateauthority,thechainfilemustcontain
onlytheverificationchainforthesecertificates,andthechainsmustbethesame.
Ifthecertificatescomefromdifferentcertificateauthorities,thechainfilemustcontainboth
certificateverificationchains.
Forexample,ifyouareusingtwoACEManagementServerinstancesyouhavetwocertificatechainfiles.
[Root SSL Certificate in PEM format]
[Intermediary SSL Certificate in PEM format]
[AMS #1 SSL Certificate in PEM format]
[AMS #1 SSL Certificate in PEM format]
convert to PEM
then append to file
convert to PEM
then append to file
convert to PEM
then append to file
convert to PEM
then append to file
certificate
verification
chain
Server SSL
Certificates
Certificate Chain File
Root SSL Certificate
Intermediary SSL Certificate
ACE Management Server #1
SSL Certificate
ACE Management Server #2
SSL Certificate