7.0

Table Of Contents
Configuring SSL Certificates for View
Servers 8
VMware strongly recommends that you configure SSL certificates for authentication of View Connection
Server instances, security servers, and View Composer service instances.
A default SSL server certificate is generated when you install View Connection Server instances, security
servers, or View Composer instances. You can use the default certificate for testing purposes.
IMPORTANT Replace the default certificate as soon as possible. The default certificate is not signed by a
Certificate Authority (CA). Use of certificates that are not signed by a CA can allow untrusted parties to
intercept traffic by masquerading as your server.
This chapter includes the following topics:
n
“Understanding SSL Certificates for View Servers,” on page 79
n
“Overview of Tasks for Setting Up SSL Certificates,” on page 81
n
“Obtaining a Signed SSL Certificate from a CA,” on page 82
n
“Configure View Connection Server, Security Server, or View Composer to Use a New SSL
Certificate,” on page 83
n
“Configure Client Endpoints to Trust Root and Intermediate Certificates,” on page 88
n
“Configuring Certificate Revocation Checking on Server Certificates,” on page 90
n
“Configure the PCoIP Secure Gateway to Use a New SSL Certificate,” on page 91
n
“Setting View Administrator to Trust a vCenter Server or View Composer Certificate,” on page 95
n
“Benefits of Using SSL Certificates Signed by a CA,” on page 95
n
“Troubleshooting Certificate Issues on View Connection Server and Security Server,” on page 96
Understanding SSL Certificates for View Servers
You must follow certain guidelines for configuring SSL certificates for View servers and related
components.
View Connection Server and Security Server
SSL is required for client connections to a server. Client-facing View Connection Server instances, security
servers, and intermediate servers that terminate SSL connections require SSL server certificates.
By default, when you install View Connection Server or security server, the installation generates a self-
signed certificate for the server. However, the installation uses an existing certificate in the following cases:
n
If a valid certificate with a Friendly name of vdm already exists in the Windows Certificate Store
VMware, Inc.
79