Administration

Table Of Contents
2 Add the enableRevocationChecking and crlLocation properties to the locked.properties le.
a Set enableRevocationChecking to true to enable smart card certicate revocation checking.
b Set crlLocation to the location of the CRL. The value can be a URL or a le path.
3 Restart the View Connection Server service or security server service to make your changes take eect.
Example: locked.properties File
The le shown enables smart card authentication and smart card certicate revocation checking, congures
CRL checking, and species a URL for the CRL location.
trustKeyfile=lonqa.key
trustStoretype=jks
useCertAuth=true
enableRevocationChecking=true
crlLocation=http://root.ocsp.net/certEnroll/ocsp-ROOT_CA.crl
Configure OCSP Certificate Revocation Checking
When you congure OCSP certicate revocation checking, View sends a verication request to an OCSP
Responder to determine the revocation status of a smart card user certicate.
Prerequisites
Familiarize yourself with the locked.properties le properties for OCSP certicate revocation checking. See
“Smart Card Certicate Revocation Checking Properties,” on page 56.
Procedure
1 Create or edit the locked.properties le in the SSL gateway conguration folder on the View
Connection Server or security server host.
For example: install_directory\VMware\VMware View\Server\sslgateway\conf\locked.properties
2 Add the enableRevocationChecking, enableOCSP, ocspURL, and ocspSigningCert properties to the
locked.properties le.
a Set enableRevocationChecking to true to enable smart card certicate revocation checking.
b Set enableOCSP to true to enable OCSP certicate revocation checking.
c Set ocspURL to the URL of the OCSP Responder.
d Set ocspSigningCert to the location of the le that contains the OCSP Responder's signing
certicate.
3 Restart the View Connection Server service or security server service to make your changes take eect.
Example: locked.properties File
The le shown enables smart card authentication and smart card certicate revocation checking, congures
both CRL and OCSP certicate revocation checking, species the OCSP Responder location, and identies
the le that contains the OCSP signing certicate.
trustKeyfile=lonqa.key
trustStoretype=jks
useCertAuth=true
enableRevocationChecking=true
enableOCSP=true
allowCertCRLs=true
ocspSigningCert=te-ca.signing.cer
ocspURL=http://te-ca.lonqa.int/ocsp
Chapter 3 Setting Up Smart Card Authentication
VMware, Inc. 55