Installation

Table Of Contents
2 Congure a PSG Certicate in the Windows Certicate Store on page 92
To replace the default PSG certicate with a CA-signed certicate, you must congure the certicate
and its private key in the Windows local computer certicate store on the View Connection Server or
security server computer on which the PSG is running.
3 Set the PSG Certicate Friendly Name in the Windows Registry on page 94
The PSG identies the SSL certicate to use by means of the server name and certicate Friendly
name. You must set the Friendly name value in the Windows registry on the View Connection Server
or security server computer on which the PSG is running.
4 (Optional) Force a CA-Signed Certicate to Be Used for Connections to the PSG on page 94
You can ensure that all client connections to the PSG use the CA-signed certicate for the PSG instead
of the default legacy certicate. This procedure is not required to congure a CA-signed certicate for
the PSG. Take these steps only if it makes sense to force the use of a CA-signed certicate in your View
deployment.
Verify That the Server Name Matches the PSG Certificate Subject Name
When a View Connection Server instance or security server is installed, the installer creates a registry seing
with a value that contains the FQDN of the computer. You must verify that this value matches the server
name part of the URL that security scanners use to reach the PSG port. The server name also must match the
subject name or a subject alternate name (SAN) of the SSL certicate that you intend to use for the PSG.
For example, if a scanner connects to the PSG with the URL https://view.customer.com:4172, the registry
seing must have the value view.customer.com. Note that the FQDN of the View Connection Server or
security server computer that is set during installation might not be the same as this external server name.
Procedure
1 Start the Windows Registry Editor on the View Connection Server or security server host where the
PCoIP Secure Gateway is running.
2 Navigate to the HKEY_LOCAL_MACHINE\SOFTWARE\Teradici\SecurityGateway\SSLCertPsgSni registry
seing.
3 Verify that the value of the SSLCertPsgSni seing matches the server name in the URL that scanners will
use to connect to the PSG and matches the subject name or a subject alternate name of the SSL certicate
that you intend to install for the PSG.
If the value does not match, replace it with the correct value.
4 Restart the VMware Horizon View PCoIP Secure Gateway service to make your changes take eect.
What to do next
Import the CA-signed certicate into the Windows local computer certicate store and congure the
certicate Friendly name.
Configure a PSG Certificate in the Windows Certificate Store
To replace the default PSG certicate with a CA-signed certicate, you must congure the certicate and its
private key in the Windows local computer certicate store on the View Connection Server or security server
computer on which the PSG is running.
If you intend the PSG to use a unique certicate, you must import the certicate into the Windows local
computer certicate store with an exportable private key and set the appropriate Friendly name.
If you intend the PSG to use the same certicate as the server, you do not have to follow this procedure.
However, in the Windows registry you must set the server name to match the server certicate subject name
and set the Friendly name to vdm.
View Installation
92 VMware, Inc.