6.0

Table Of Contents
Configuring SSL Certificates for View
Servers 6
VMware strongly recommends that you configure SSL certificates for authentication of View Connection
Server instances, security servers, and View Composer service instances.
A default SSL server certificate is generated when you install View Connection Server instances, security
servers, or View Composer instances. You can use the default certificate for testing purposes.
IMPORTANT Replace the default certificate as soon as possible. The default certificate is not signed by a
Certificate Authority (CA). Use of certificates that are not signed by a CA can allow untrusted parties to
intercept traffic by masquerading as your server.
This chapter includes the following topics:
n
“Understanding SSL Certificates for View Servers,” on page 63
n
“Overview of Tasks for Setting Up SSL Certificates,” on page 65
n
“Obtaining a Signed SSL Certificate from a CA,” on page 66
n
“Configure View Connection Server, Security Server, or View Composer to Use a New SSL
Certificate,” on page 67
n
“Configure Client Endpoints to Trust Root and Intermediate Certificates,” on page 72
n
“Configuring Certificate Revocation Checking on Server Certificates,” on page 74
n
“Configure the PCoIP Secure Gateway to Use a New SSL Certificate,” on page 75
n
“Setting View Administrator to Trust a vCenter Server or View Composer Certificate,” on page 79
n
“Benefits of Using SSL Certificates Signed by a CA,” on page 79
n
“Troubleshooting Certificate Issues on View Connection Server and Security Server,” on page 80
Understanding SSL Certificates for View Servers
You must follow certain guidelines for configuring SSL certificates for View servers and related
components.
View Connection Server and Security Server
SSL is required for client connections to a server. Client-facing View Connection Server instances, security
servers, and intermediate servers that terminate SSL connections require SSL server certificates.
By default, when you install View Connection Server or security server, the installation generates a self-
signed certificate for the server. However, the installation uses an existing certificate in the following cases:
n
If a valid certificate with a Friendly name of vdm already exists in the Windows Certificate Store
VMware, Inc.
63