2.7

Table Of Contents
VMware, Inc. 51
Chapter 7 Troubleshooting and Maintenance
To restore a backup copy of an SSL certificate
1 NavigatetotheACEManagementServerdirectorywherethebackupisstored.
Thefilenamesusethefollowingformat:
<certificate_filename>.<date>-<time>
The<certificate_filename>valueisoneofthefollowing:
server.crtTheserverpubliccertificate
server.keyTheserverprivatekey
chain.crtThecertificatechain
The <date>portionofthefilenameisintheformatYYYYMMDD(year,month,day).
The <time>portionofthefilenameisintheformatHHMMSS(hours,minutes,seconds).
Forexample,afilenamemightbeserver.crt.20070216-095344.
2 Savethefileinthecorrectlocationasssl/<filename>.crt and restarttheApacheservermanually.
See“VerifyThattheApacheServiceIsStartedorRestarted”onpage 23.
3StarttheACEManagementServerSetupapplicationandusetheCustomSSLCertificatestabtoupload
thebackupcopy.
“StartandConfigureACEManagementServeronpage 24.
Configuring Multiple ACE Management Server Instances to Use SSL
YoumightconfiguremultipleACEManagementServerinstancestouseSSLinthefollowingscenarios:
Multipleserversbehindoneormoreproxyservers:
EachservercanhaveitsownSSLkeyandcertificate(ACEManagementServerandproxyserver).
Thecert_chainfilemustcontainthecertificatefileandverificationchainfortheSSLcertificatesthat
theproxyserversareusing.Placethiscert_chainfileineachACEManagementServer.
Whenselfsignedcertificatesarebeingused,theactualcertificateistheverificationchain.Thechain
filecontainseachselfsignedcertificatebeingthattheproxiesareusing.
Youcanalsousethesamekeyandcertificateforeveryserverandproxy.Inthiscase,youdonotneed
tocreateacert_chainfile.
Eachcertificatemusthaveauniquecommonname.
MultipleserversusingDNSroundrobin:
EachservercanhaveitsownSSLkeyandcertificate(ACEManagementServerandproxyserver).
Thecert_chainfilemustcontainthecertificateandverificationchainforeverycertificatethatthe
serversuse.PlacethiscertificatechainfileineachACEManagementServer.
Whenselfsignedcertificatesarebeingused,theactualcertificateistheverificationchain.Thechain
filecontainseachselfsignedcertificatethateachoftheserversisusing.
Youcanusethesamekeyandcertificateforeveryserver.Inthiscase,youdonotneedtocreatea
cert_chainfile.
SeealsoChapter 5,“LoadBalancingMultipleACEManagementServerInstances,”onpage 37.