2.7

Table Of Contents
ACE Management Server Administrator’s Manual
34 VMware, Inc.
Ifyouareupgradingtheserverfromthepreviousrelease,thedatabaseschemaisupgradedautomaticallyand
youdonotloseyourpreviousdata.Theupgradeisperformedonthefirststartoftheupgradedserver,even
ifyoudonotrerunthesetupapplication.
Ifyoumakechangestothe
informationontheDatabasetab,youmustclickApplyorCancelbeforeyoucan
navigatetoanothertab.
Creating Access Control
OntheAccessControltab,youcancreatealocalAdministratorroleandHelpDeskroleoruseActive
Directoryforauthenticatinguserswiththeseroles.
BeforeyoucanconfiguretheACEManagementServertouseadomainaccountforauthentication,youmust
createusersandgroupssothatACEManagement
ServercanconnecttotheLDAPserver.See“CreateUsers
andGroupsforIntegrationwithActiveDirectory”onpage 27.
Usethefollowinginformationtohelpyoucompletethefieldsforauthentication:
LocalaccountIfyouspecifyapasswordfortheAdministratorroleandforgetorloseit,youmustdelete
theserverconfigurationfile.Deletingthisfilesetstheserverbacktoitsinitialstate.Youmustreconfigure
theserverandsettheadministratorpasswordagain.
See“DeletetheServerConfiguration
FileandSetaNewAdministratorPasswordonpage 50.
Domainaccount(LDAP)TouseActiveDirectoryforauthentication,specifythehostandcredentials
thattheACEManagementServerusestoconnecttoandquerythedomaincontroller:
HostNameEnterafullyqualifieddomainname(forexample,ldap.vmware.com)insteadofanIP
addressorhostnamewithnoparentdomainname(forexample,ldap).
QueryUsersAMAcountNameandQueryUserPasswordUsethepasswordandshortnamefor
theuseraccountyoucreatedforthispurposeinActiveDirectory.
QueryUserDomainThedomainmustbethedomainforwhichtheLDAPhostisadomain
controller.
AdminGroupDNandHelpDeskGroupDN(Optional)Enterthedistinguishednameforthese
groups,whichyoucreatedforthispurposeinActiveDirectory(forexample,
cn=Users,dc=simplecorp,dc=com).
Ifthisoptionisnotenabled,anyonewhologsintotheHelpDeskapplicationmustbeamemberof
theACE
Administratorsgroup.
HelpDeskRoleorGroupDNCreatingaHelpDeskroleallowsyoutopermitcertainuserstoperform
HelpDesktasksfromtheHelpDeskapplication.Usersinthisrolecannotaccessotheradministrative
tools.YoucanstilllogintotheHelpDeskWebapplicationwithyouradministrative
LDAPcredentialsor
localAdministratorpassword.
IfyoumakechangestotheinformationontheAccessControltab,youmustclickApplyorCancelbeforeyou
cannavigatetoanothertab.
Uploading Custom SSL Certificates
TohaveACEManagementServerusecustomSSLcertificates,eitheryourownselfsignedcertificatesorthose
ofathirdpartyorinternalCA(certificateauthority),usetheCustomSSLCertificatestabtouploadthe
PEMencodedfiles.
BeforeyoucanuploadcustomSSLcertificates,youmustcreateandrenamethe
certificatefiles.See“Prepare
CustomSecurityCertificates”onpage 32.