Installation

Table Of Contents
n
If you upgrade to View 5.1 or later from an earlier release, and a valid keystore le is congured on the
Windows Server computer. The installation extracts the keys and certicates and imports them into the
Windows Certicate Store.
vCenter Server and View Composer
Before you add vCenter Server and View Composer to View in a production environment, make sure that
vCenter Server and View Composer use certicates that are signed by a CA.
For information about replacing the default certicate for vCenter Server, see "Replacing vCenter Server
Certicates" on the VMware Technical Papers site at hp://www.vmware.com/resources/techresources/.
If you install vCenter Server and View Composer on the same Windows Server host, they can use the same
SSL certicate, but you must congure the certicate separately for each component.
PCoIP Secure Gateway
To comply with industry or jurisdiction security regulations, you can replace the default SSL certicate that
is generated by the PCoIP Secure Gateway (PSG) service with a certicate that is signed by a CA.
Conguring the PSG service to use a CA-signed certicate is highly recommended, particularly for
deployments that require you to use security scanners to pass compliance testing. See “Congure the PCoIP
Secure Gateway to Use a New SSL Certicate,” on page 91.
Blast Secure Gateway
By default, the Blast Secure Gateway (BSG) uses the SSL certicate that is congured for the View
Connection Server instance or security server on which the BSG is running. If you replace the default, self-
signed certicate for a server with a CA-signed certicate, the BSG also uses the CA-signed certicate.
SAML 2.0 Authenticator
VMware Identity Manager uses SAML 2.0 authenticators to provide Web-based authentication and
authorization across security domains. If you want View to delegate authentication to
VMware Identity Manager, you can congure View to accept SAML 2.0 authenticated sessions from
VMware Identity Manager. When VMware Identity Manager is congured to support View,
VMware Identity Manager users can connect to remote desktops by selecting desktop icons on the Horizon
User Portal.
In View Administrator, you can congure SAML 2.0 authenticators for use with View Connection Server
instances.
Before you add a SAML 2.0 authenticator in View Administrator, make sure that the SAML 2.0 authenticator
uses a certicate that is signed by a CA.
Additional Guidelines
For general information about requesting and using SSL certicates that are signed by a CA, see “Benets of
Using SSL Certicates Signed by a CA,” on page 95.
When client endpoints connect to a View Connection Server instance or security server, they are presented
with the server's SSL server certicate and any intermediate certicates in the trust chain. To trust the server
certicate, the client systems must have installed the root certicate of the signing CA.
When View Connection Server communicates with vCenter Server and View Composer, View Connection
Server is presented with SSL server certicates and intermediate certicates from these servers. To trust the
vCenter Server and View Composer servers, the View Connection Server computer must have installed the
root certicate of the signing CA.
View Installation
80 VMware, Inc.