2.7

Table Of Contents
VMware, Inc. 35
Chapter 4 Configuration Options for ACE Management Server
Bydefault,duringACEManagementServerinstallation,thefollowingtwofilesarecreated:
server.keyThisRSA1024bitkeyistheprivatekey.
server.crtThisselfsignedcertificateisvalidfor10yearsfromthedateandtimeatwhichtheserveris
installed.Itssignatureisverifiedbythepublickey,whichisembeddedinthecertificate.Thecertificate
fileisencodedinPEMformat.
WhenyourunanACEinstance,
theVMwarePlayerapplicationusesthecompletecertificationchainthatis
includedinitspackage,notonthehost,toverifyconnectionsmadetoACEManagementServer.Therefore,
theuseofselfsignedcertificatesisadequateformostsecurityneeds.Formoreinformationabouthow
VMwareACEusessecuritycertificates,see
“UsingSSLCertificatesandProtocol”onpage 16.
WhenyouclickUploadcertificates,asummarypagedisplaysthefilesandlocationsyouspecifyonthistab.
Notethelocationofanybackupfiles.Youmightneedtousethebackupifyoufindthatthenewfileisinvalid
whenyou
clickApply.See“RestoreaBackupCopyofanSSLCertificate”onpage 50.
AfteryouuploadcustomSSLcertificates,youmustupdateanyexistingACEenabledvirtualmachinestouse
anewcertificateandkeyfile.Todoso,useWorkstationtocreateanupdatepackage.Whenyoudeploythe
newpackage,ACEinstancesreceivethenewcertificatefileandcertificatechain.
Logging Events
Theservercollectslogentriesforeventsthatchangethedatabase.OntheLoggingtab,youcansetthelogging
levelsandsetanoptionforpurginglogentries.
ACEManagementServerusesthefollowingloggingcategories:
ACEAdministrationLogseventsforinstancecreation,update,anddestruction.
PackageAdministrationLogseventsforpackagecreation,update,instancecustomization,andpackage
removal.
PolicyAdministrationLogseventsforpolicysetupdateandpublish,useraccesscontrolchanges,and
instancepasswordssetbyanACEadministrator.
InstanceAdministrationLogsACEinstancelifecycleevents,suchascreation,copying,revocation,
reenablement,anddeletion.Alsologsinstancepasswordchangebyauseroranadministrator,changes
inexpirationforeachinstance,changesofinstanceguestorhostoperatingsysteminformation,and
settinginstancecustomfields.Thedebuglevel
canbeusedtologthemostubiquitoustrafficsuchas
policyupdaterequestsfromactiveinstances.Failedinstanceverificationsareloggedonlyatthedebug
level.
AuthenticationLogseventsforeveryauthenticationrequest,suchasadministrationorhelpdesk
authenticationattempts(atthenormallevel),instanceauthentication(attheinformationallevel),and
remoteLDAPpasswordchange.Setloggingforthiscategorytothelowestlevelthatispracticalforyou.
Thiscategorycangeneratealarge
volumeofentries.
Foreachcategory,youcanchooseoneofthefollowinglogginglevels:
NoneNologentryismadeforthisevent.
CriticalAnexampleofacriticallogeventisonethatremovesallpackages,instances,andpolicies
associatedwithanACEenabledvirtualmachine.
NormalThislevelofdetailissufficienttoanswermostqueries.
InformativeEntriesfornondestructiveeventsthathavelimitedeffect.
DebugEntriesforeveryclientaccessoftheserver.Itprovidesmorerecordsofcertaineventtypes,
creatingalargenumberloggingentriescomparedtootherloglevels.Itlogsallinformationaltransactions,
suchasinstancestatusandsoon.