Installation

Table Of Contents
Additional Guidelines
For general information about requesting and using SSL certificates that are signed by a CA, see Benefits
of Using SSL Certificates Signed by a CA.
When client endpoints connect to a Connection Server instance or security server, they are presented
with the server's SSL server certificate and any intermediate certificates in the trust chain. To trust the
server certificate, the client systems must have installed the root certificate of the signing CA.
When Connection Server communicates with vCenter Server and View Composer, Connection Server is
presented with SSL server certificates and intermediate certificates from these servers. To trust the
vCenter Server and View Composer servers, the Connection Server computer must have installed the
root certificate of the signing CA.
Similarly, if a SAML 2.0 authenticator is configured for Connection Server, the Connection Server
computer must have installed the root certificate of the signing CA for the SAML 2.0 server certificate.
Overview of Tasks for Setting Up SSL Certificates
To set up SSL server certificates for Horizon 7 servers, you must perform several high-level tasks.
In a pod of replicated Connection Server instances, you must perform these tasks on all instances in the
pod.
The procedures for carrying out these tasks are described in the topics that follow this overview.
1 Determine if you need to obtain a new signed SSL certificate from a CA.
If your organization already has a valid SSL server certificate, you can use that certificate to replace
the default SSL server certificate provided with Connection Server, security server, or View
Composer. To use an existing certificate, you also need the accompanying private key.
Starting Place Action
Your organization provided you with a valid SSL server certificate. Go directly to step 2.
You do not have an SSL server certificate. Obtain a signed SSL server certificate from a CA.
2 Import the SSL certificate into the Windows local computer certificate store on the Horizon 7 server
host.
3 For Connection Server instances and security servers, modify the certificate Friendly name to vdm.
Assign the Friendly name vdm to only one certificate on each Horizon 7 server host.
4 On Connection Server computers, if the root certificate is not trusted by the Windows Server host,
import the root certificate into the Windows local computer certificate store.
In addition, if the Connection Server instances do not trust the root certificates of the SSL server
certificates configured for security server, View Composer, and vCenter Server hosts, you also must
import those root certificates. Take these steps for Connection Server instances only. You do not have
to import the root certificate to View Composer, vCenter Server, or security server hosts.
View Installation
VMware, Inc. 90