6.0

Table Of Contents
Prerequisites
n
Verify that the key length is at least 1024 bits.
n
Verify that the SSL certificate is valid. The current time on the server computer must be within the
certificate start and end dates.
n
Verify that the certificate subject name or a subject alternate name matches the SSLCertPsgSni setting in
the Windows registry. See “Verify That the Server Name Matches the PSG Certificate Subject Name,”
on page 76.
n
Verify that the Certificate snap-in was added to MMC. See “Add the Certificate Snap-In to MMC,” on
page 68.
n
Familiarize yourself with importing a certificate into the Windows certificate store. See “Import a
Signed Server Certificate into a Windows Certificate Store,” on page 68.
n
Familiarize yourself with modifying the certificate Friendly name. See “Modify the Certificate Friendly
Name,” on page 69.
Procedure
1 In the MMC window on the Windows Server host, open the Certificates (Local Computer) > Personal
folder.
2 Import the SSL certificate that is issued to the PSG by selecting More Actions > All Tasks > Import.
Select the following settings in the Certificate Import wizard:
a Mark this key as exportable
b Include all extendable properties
Complete the wizard to finish importing the certificate into the Personal folder
3 Verify that the new certificate contains a private key by taking one of these steps:
n
Verify that a yellow key appears on the certificate icon.
n
Double-click the certificate and verify that the following statement appears in the Certificate
Information dialog box: You have a private key that corresponds to this certificate..
4 Right-click the new certificate and click Properties.
5 On the General tab, delete the Friendly name text and type the Friendly name that you have chosen.
Make sure that you enter exactly the same name in the SSLCertWinCertFriendlyName setting in the
Windows registry, as described in the next procedure.
6 Click Apply and click OK.
The PSG presents the CA-signed certificate to client devices that connect to the server over PCoIP.
NOTE This procedure does not affect legacy client devices. The PSG continues to present the default legacy
certificate to legacy client devices that connect the this server over PCoIP.
What to do next
Configure the certificate Friendly name in the Windows registry.
Chapter 6 Configuring SSL Certificates for View Servers
VMware, Inc. 77