2.7

Table Of Contents
ACE Management Server Administrator’s Manual
32 VMware, Inc.
Prepare Custom Security Certificates
TousecustomSSLcertificates,eitheryourownselfsignedcertificatesorthoseofathirdpartyorinternalCA
(certificateauthority),youmustprovidethecertificate,key,and(inthecaseofCAs)certificatechainfiles.
ThesefilesmustbePEMencoded.
Afteryoucreateorobtainthesefiles,upload
themtoACEManagementServerbyusingtheCustomSSL
CertificatestabintheACEManagementServerSetupapplication.
FormoreinformationabouthowVMwareACEusesSSLcertificates,see“UsingSSLCertificatesandProtocol”
onpage 16.
To prepare custom security certificates
1 Createorprovidetheneededfiles:
Foryourownselfsignedcertificate,usetheopensslutilitytocreateanewselfsignedcertificate.
ForathirdpartyCAorinternalCA,obtainanSSLcertificatesignedbythatCA,anda
certificateverificationchainfile.
ThechainfileisaconcatenationofeverycertificaterequiredtoverifythenewSSLcertificateyou
createdorobtained.DependingontheCAandcertificateissued,anexample
chainfilecouldbea
concatenationoftherootcertificate,oneormoreintermediarycertificates,andtheservercertificate.
EachoftheindividualpiecesmustbeSHA1encodedandinPEMformatbeforeconcatenation.Steps
forobtainingthecertificatechainvary,dependingonwhichhostoperatingsystemyouareusing
and
onthesourcefromwhichtheCAcertificateisobtained.ACAauthoritymayprovidethecomplete
chainoryoumayneedtoassemblethechainyourself.
Aprivatekeyfile.SSLencryptsdatathroughtheuseofapublickeyandprivatekeypair.Thepublic
keyisknowntoeveryoneandtheprivatekeyisknownonlytothemessagerecipient.
ThecertificatesignaturesmustusetheSHA1algorithmdigest.ThefilesmustbePEMencoded.
2 Rename
thefiles,asfollows:
Renametheprivatekeyfiletoserver.key.
Renamethecertificatefiletoserver.crt.
Renamethecertificatechainfiletochain.crt.
YoucannowusetheACEManagementServerSetupapplicationtouploadthecertificatefiles.
View the Properties of the Self-Signed Certificate File
ThisfileisstoredintheSSLdirectoryintheVMwareACEManagementServerprogramdirectory.
To view the properties of the self-signed certificate file
Dooneofthefollowing:
OnaWindowshost,navigatetothelocationoftheserver.crtfileanddoubleclickthefilename.
OnaLinuxhost,usethefollowingcommand:
openssl x509 -in /var/lib/vmware/acesc/ssl/server.crt -text
Toreplaceanexpiredcertificate,see“PrepareCustomSecurityCertificates”onpage 32.Donotmodify
certificatestomakethempermanent.