Administration

Table Of Contents
5 On the  Path tab, select the certicate at the top of the tree and click View .
If the user certicate is signed as part of a trust hierarchy, the signing certicate might be signed by
another higher-level certicate. Select the parent certicate (the one that actually signed the user
certicate) as your root certicate. In some cases, the issuer might be an intermediate CA.
6 On the Details tab, click Copy to File.
The Certicate Export Wizard appears.
7 Click Next > Next and type a name and location for the le that you want to export.
8 Click Next to save the le as a root certicate in the specied location.
What to do next
Add the CA certicate to a server truststore le.
Add the CA Certificate to a Server Truststore File
You must add root certicates, intermediate certicates, or both to a server truststore le for all users and
administrators that you trust. View Connection Server instances and security servers use this information to
authenticate smart card users and administrators.
Prerequisites
n
Obtain the root or intermediate certicates that were used to sign the certicates on the smart cards
presented by your users or administrators. See “Obtain the Certicate Authority Certicates,” on
page 45 and “Obtain the CA Certicate from Windows,” on page 45.
I These certicates can include intermediate certicates if the user's smart card certicate
was issued by an intermediate certicate authority.
n
Verify that the keytool utility is added to the system path on your View Connection Server or security
server host. See the View Installation document for more information.
Procedure
1 On your View Connection Server or security server host, use the keytool utility to import the root
certicate, intermediate certicate, or both into the server truststore le.
For example: keytool -import -alias alias -file root_certificate -keystore truststorefile.key
In this command, alias is a unique case-sensitive name for a new entry in the truststore le,
root_certicate is the root or intermediate certicate that you obtained or exported, and truststorele.key is
the name of the truststore le that you are adding the root certicate to. If the le does not exist, it is
created in the current directory.
N The keytool utility might prompt you to create a password for the truststore le. You will be
asked to provide this password if you need to add additional certicates to the truststore le at a later
time.
2 Copy the truststore le to the SSL gateway conguration folder on the View Connection Server or
security server host.
For example: install_directory\VMware\VMware View\Server\sslgateway\conf\truststorefile.key
What to do next
Modify View Connection Server conguration properties to enable smart card authentication.
View Administration
46 VMware, Inc.