Administration

Table Of Contents
n
Logging in with OCSP Certicate Revocation Checking on page 54
When you congure OCSP certicate revocation checking, View sends a request to an OCSP
Responder to determine the revocation status of a specic user certicate. View uses an OCSP signing
certicate to verify that the responses it receives from the OCSP Responder are genuine.
n
Congure CRL Checking on page 54
When you congure CRL checking, View reads a CRL to determine the revocation status of a smart
card user certicate.
n
Congure OCSP Certicate Revocation Checking on page 55
When you congure OCSP certicate revocation checking, View sends a verication request to an
OCSP Responder to determine the revocation status of a smart card user certicate.
n
Smart Card Certicate Revocation Checking Properties on page 56
You set values in the locked.properties le to enable and congure smart card certicate revocation
checking.
Logging in with CRL Checking
When you congure CRL checking, View constructs and reads a CRL to determine the revocation status of a
user certicate.
If a certicate is revoked and smart card authentication is optional, the Enter your user name and password
dialog box appears and the user must provide a password to authenticate. If smart card authentication is
required, the user receives an error message and is not allowed to authenticate. The same events occur if
View cannot read the CRL.
Logging in with OCSP Certificate Revocation Checking
When you congure OCSP certicate revocation checking, View sends a request to an OCSP Responder to
determine the revocation status of a specic user certicate. View uses an OCSP signing certicate to verify
that the responses it receives from the OCSP Responder are genuine.
If the user certicate is revoked and smart card authentication is optional, the Enter your user name and
password dialog box appears and the user must provide a password to authenticate. If smart card
authentication is required, the user receives an error message and is not allowed to authenticate.
View falls back to CRL checking if it does not receive a response from the OCSP Responder or if the
response is invalid.
Configure CRL Checking
When you congure CRL checking, View reads a CRL to determine the revocation status of a smart card
user certicate.
Prerequisites
Familiarize yourself with the locked.properties le properties for CRL checking. See “Smart Card
Certicate Revocation Checking Properties,” on page 56.
Procedure
1 Create or edit the locked.properties le in the SSL gateway conguration folder on the View
Connection Server or security server host.
For example: install_directory\VMware\VMware View\Server\sslgateway\conf\locked.properties
View Administration
54 VMware, Inc.