Administration

Table Of Contents
Cause
View supports certificate revocation checking with certificate revocation lists (CRLs) and with the Online
Certificate Status Protocol (OCSP). A CRL is a list of revoked certificates published by the CA (Certificate
Authority) that issued the certificates. OCSP is a certificate validation protocol that is used to get the
revocation status of an X.509 certificate. The CA must be accessible from the View Connection Server or
security server host. This issue can only occur if you configured revocation checking of smart card
certificates. See Using Smart Card Certificate Revocation Checking.
Solution
1 Create your own (manual) procedure for downloading an up-to-date CRL from the CA website you
use to a path on your View server.
2 Create or edit the locked.properties file in the SSL gateway configuration folder on the View
Connection Server or security server host.
For example: install_directory\VMware\VMware
View\Server\sslgateway\conf\locked.properties
3 Add the enableRevocationChecking and crlLocation properties in the locked.properties file
to the local path to where the CRL is stored.
4 Restart the View Connection Server service or security server service to make your changes take
effect.
Further Troubleshooting Information
You can find further troubleshooting information in VMware Knowledge Base articles.
The VMware Knowledge Base (KB) is continually updated with new troubleshooting information for
VMware products.
For more information about troubleshooting View, see the KB articles that are available on the VMware
KB Web site:
http://kb.vmware.com/selfservice/microsites/microsite.do
View Administration
VMware, Inc. 224