6.1

Table Of Contents
n
Verify that you have the appropriate credentials to request a certificate that can be issued to a computer
or service.
Procedure
1 In the MMC window on the Windows Server host, expand the Certificates (local computer) node and
select the Personal folder.
2 From the Action menu, go to All Tasks > Request New Certificate to display the Certificate Enrollment
wizard.
3 Select a Certificate Enrollment Policy.
4 Select the types of certificates that you want to request, select the Make private key exportable option,
and click Enroll.
5 Click Finish.
The new signed certificate is added to the Personal > Certificates folder in the Windows Certificate Store.
What to do next
n
Verify that the server certificate and certificate chain were imported into the Windows Certificate Store.
n
For a View Connection Server instance or security server, modify the certificate friendly name to vdm.
See “Modify the Certificate Friendly Name,” on page 77.
n
For a View Composer server, bind the new certificate to the port that used by View Composer. See
“Bind a New SSL Certificate to the Port Used by View Composer,” on page 79.
Configure View Connection Server, Security Server, or View
Composer to Use a New SSL Certificate
To configure a View Connection Server instance, security server, or View Composer instance to use an SSL
certificate, you must import the server certificate and the entire certificate chain into the Windows local
computer certificate store on the View Connection Server, security server, or View Composer host.
In a pod of replicated View Connection Server instances, you must import the server certificate and
certificate chain on all instances in the pod.
By default, the Blast Secure Gateway (BSG) uses the SSL certificate that is configured for the View
Connection Server instance or security server on which the BSG is running. If you replace the default, self-
signed certificate for a View server with a CA-signed certificate, the BSG also uses the CA-signed certificate.
IMPORTANT To configure View Connection Server or security server to use a certificate, you must change the
certificate Friendly name to vdm. Also, the certificate must have an accompanying private key.
If you intend to replace an existing certificate or the default, self-signed certificate with a new certificate
after you install View Composer, you must run the SviConfig ReplaceCertificate utility to bind the new
certificate to the port used by View Composer.
Procedure
1 Add the Certificate Snap-In to MMC on page 76
Before you can add certificates to the Windows Certificate Store, you must add the Certificate snap-in
to the Microsoft Management Console (MMC) on the Windows Server host on which the View server
is installed.
Chapter 7 Configuring SSL Certificates for View Servers
VMware, Inc. 75