Administration

Table Of Contents
3 Add the CA Certicate to a Server Truststore File on page 46
You must add root certicates, intermediate certicates, or both to a server truststore le for all users
and administrators that you trust. View Connection Server instances and security servers use this
information to authenticate smart card users and administrators.
4 Modify View Connection Server Conguration Properties on page 47
To enable smart card authentication, you must modify View Connection Server conguration
properties on your View Connection Server or security server host.
5 Congure Smart Card Seings in View Administrator on page 47
You can use View Administrator to specify seings to accommodate dierent smart card
authentication scenarios.
Obtain the Certificate Authority Certificates
You must obtain all applicable CA (certicate authority) certicates for all trusted user certicates on the
smart cards presented by your users and administrators. These certicates include root certicates and can
include intermediate certicates if the user's smart card certicate was issued by an intermediate certicate
authority.
If you do not have the root or intermediate certicate of the CA that signed the certicates on the smart
cards presented by your users and administrators, you can export the certicates from a CA-signed user
certicate or a smart card that contains one. See “Obtain the CA Certicate from Windows,” on page 45.
Procedure
u
Obtain the CA certicates from one of the following sources.
n
A Microsoft IIS server running Microsoft Certicate Services. See the Microsoft TechNet Web site
for information on installing Microsoft IIS, issuing certicates, and distributing certicates in your
organization.
n
The public root certicate of a trusted CA. This is the most common source of a root certicate in
environments that already have a smart card infrastructure and a standardized approach to smart
card distribution and authentication.
What to do next
Add the root certicate, intermediate certicate, or both to a server truststore le.
Obtain the CA Certificate from Windows
If you have a CA-signed user certicate or a smart card that contains one, and Windows trusts the root
certicate, you can export the root certicate from Windows. If the issuer of the user certicate is an
intermediate certicate authority, you can export that certicate.
Procedure
1 If the user certicate is on a smart card, insert the smart card into the reader to add the user certicate to
your personal store.
If the user certicate does not appear in your personal store, use the reader software to export the user
certicate to a le. This le is used in Step 4 of this procedure.
2 In Internet Explorer, select Tools > Internet Options.
3 On the Content tab, click .
4 On the Personal tab, select the certicate you want to use and click View.
If the user certicate does not appear on the list, click Import to manually import it from a le. After the
certicate is imported, you can select it from the list.
Chapter 3 Setting Up Smart Card Authentication
VMware, Inc. 45