Installation

Table Of Contents
Configuring SSL Certificates for View
Servers 8
VMware strongly recommends that you congure SSL certicates for authentication of View Connection
Server instances, security servers, and View Composer service instances.
A default SSL server certicate is generated when you install View Connection Server instances, security
servers, or View Composer instances. You can use the default certicate for testing purposes.
I Replace the default certicate as soon as possible. The default certicate is not signed by a
Certicate Authority (CA). Use of certicates that are not signed by a CA can allow untrusted parties to
intercept trac by masquerading as your server.
This chapter includes the following topics:
n
“Understanding SSL Certicates for View Servers,” on page 79
n
“Overview of Tasks for Seing Up SSL Certicates,” on page 81
n
“Obtaining a Signed SSL Certicate from a CA,” on page 82
n
“Congure View Connection Server, Security Server, or View Composer to Use a New SSL
Certicate,” on page 83
n
“Congure Client Endpoints to Trust Root and Intermediate Certicates,” on page 88
n
“Conguring Certicate Revocation Checking on Server Certicates,” on page 90
n
“Congure the PCoIP Secure Gateway to Use a New SSL Certicate,” on page 91
n
“Seing View Administrator to Trust a vCenter Server or View Composer Certicate,” on page 95
n
“Benets of Using SSL Certicates Signed by a CA,” on page 95
n
“Troubleshooting Certicate Issues on View Connection Server and Security Server,” on page 96
Understanding SSL Certificates for View Servers
You must follow certain guidelines for conguring SSL certicates for View servers and related components.
View Connection Server and Security Server
SSL is required for client connections to a server. Client-facing View Connection Server instances, security
servers, and intermediate servers that terminate SSL connections require SSL server certicates.
By default, when you install View Connection Server or security server, the installation generates a self-
signed certicate for the server. However, the installation uses an existing certicate in the following cases:
n
If a valid certicate with a Friendly name of vdm already exists in the Windows Certicate Store
VMware, Inc.
79