User manual

Table Of Contents
Configure HTML Access Agents to Use New SSL Certificates
To comply with industry or security regulations, you can replace the default SSL certicates that are
generated by the HTML Access Agent with certicates that are signed by a Certicate Authority (CA).
When you install the HTML Access Agent on View desktops, the HTML Access Agent service creates
default, self-signed certicates. The service presents the default certicates to browsers that use
HTML Access to connect to View.
N In the guest operating system on the desktop virtual machine, this service is called the VMware Blast
service.
To replace the default certicates with signed certicates that you obtain from a CA, you must import a
certicate into the Windows local computer certicate store on each View desktop. You must also set a
registry value on each desktop that allows the HTML Access Agent to use the new certicate.
If you replace the default HTML Access Agent certicates with CA-signed certicates, VMware
recommends that you congure a unique certicate on each desktop. Do not congure a CA-signed
certicate on a parent virtual machine or template that you use to create a desktop pool. That approach
would result in hundreds or thousands of desktops with identical certicates.
Procedure
1 Add the Certicate Snap-In to MMC on a View Desktop on page 13
Before you can add certicates to the Windows local computer certicate store, you must add the
Certicate snap-in to the Microsoft Management Console (MMC) on the View desktops where the
HTML Access Agent is installed.
2 Import a Certicate for the HTML Access Agent into the Windows Certicate Store on page 14
To replace a default HTML Access Agent certicate with a CA-signed certicate, you must import the
CA-signed certicate into the Windows local computer certicate store. Perform this procedure on
each desktop where the HTML Access Agent is installed.
3 Import Root and Intermediate Certicates for the HTML Access Agent on page 15
If the root certicate and intermediate certicates in the certicate chain are not imported with the SSL
certicate that you imported for the HTML Access Agent, you must import these certicates into the
Windows local computer certicate store.
4 Set the Certicate Thumbprint in the Windows Registry on page 15
To allow the HTML Access Agent to use a CA-signed certicate that was imported into the Windows
certicate store, you must congure the certicate thumbprint in a Windows registry key. You must
take this step on each desktop on which you replace the default certicate with a CA-signed certicate.
Add the Certificate Snap-In to MMC on a View Desktop
Before you can add certicates to the Windows local computer certicate store, you must add the Certicate
snap-in to the Microsoft Management Console (MMC) on the View desktops where the HTML Access Agent
is installed.
Prerequisites
Verify that the MMC and Certicate snap-in are available on the Windows guest operating system where the
HTML Access Agent is installed.
Procedure
1 On the View desktop, click Start and type mmc.exe.
2 In the MMC window, go to File > Add/Remove Snap-in.
Chapter 1 Setup and Installation
VMware, Inc. 13