Installation

Table Of Contents
Prerequisites
n
Verify that the key length is at least 1024 bits.
n
Verify that the SSL certicate is valid. The current time on the server computer must be within the
certicate start and end dates.
n
Verify that the certicate subject name or a subject alternate name matches the SSLCertPsgSni seing in
the Windows registry. See “Verify That the Server Name Matches the PSG Certicate Subject Name,” on
page 92.
n
Verify that the Certicate snap-in was added to MMC. See Add the Certicate Snap-In to MMC,” on
page 84.
n
Familiarize yourself with importing a certicate into the Windows certicate store. See “Import a
Signed Server Certicate into a Windows Certicate Store,” on page 84.
n
Familiarize yourself with modifying the certicate Friendly name. See “Modify the Certicate Friendly
Name,” on page 85.
Procedure
1 In the MMC window on the Windows Server host, open the  (Local Computer) > Personal
folder.
2 Import the SSL certicate that is issued to the PSG by selecting More Actions > All Tasks > Import.
Select the following seings in the Certicate Import wizard:
a Mark this key as exportable
b Include all extendable properties
Complete the wizard to nish importing the certicate into the Personal folder
3 Verify that the new certicate contains a private key by taking one of these steps:
n
Verify that a yellow key appears on the certicate icon.
n
Double-click the certicate and verify that the following statement appears in the Certicate
Information dialog box: You have a private key that corresponds to this certificate..
4 Right-click the new certicate and click Properties.
5 On the General tab, delete the Friendly name text and type the Friendly name that you have chosen.
Make sure that you enter exactly the same name in the SSLCertWinCertFriendlyName seing in the
Windows registry, as described in the next procedure.
6 Click Apply and click OK.
The PSG presents the CA-signed certicate to client devices that connect to the server over PCoIP.
N This procedure does not aect legacy client devices. The PSG continues to present the default legacy
certicate to legacy client devices that connect the this server over PCoIP.
What to do next
Congure the certicate Friendly name in the Windows registry.
Chapter 8 Configuring SSL Certificates for View Servers
VMware, Inc. 93