6.2

Table Of Contents
Configuring SSL Certificates for View
Servers 8
VMware strongly recommends that you configure SSL certificates for authentication of View Connection
Server instances, security servers, and View Composer service instances.
A default SSL server certificate is generated when you install View Connection Server instances, security
servers, or View Composer instances. You can use the default certificate for testing purposes.
IMPORTANT Replace the default certificate as soon as possible. The default certificate is not signed by a
Certificate Authority (CA). Use of certificates that are not signed by a CA can allow untrusted parties to
intercept traffic by masquerading as your server.
This chapter includes the following topics:
n
“Understanding SSL Certificates for View Servers,” on page 77
n
“Overview of Tasks for Setting Up SSL Certificates,” on page 79
n
“Obtaining a Signed SSL Certificate from a CA,” on page 80
n
“Configure View Connection Server, Security Server, or View Composer to Use a New SSL
Certificate,” on page 81
n
“Configure Client Endpoints to Trust Root and Intermediate Certificates,” on page 86
n
“Configuring Certificate Revocation Checking on Server Certificates,” on page 88
n
“Configure the PCoIP Secure Gateway to Use a New SSL Certificate,” on page 89
n
“Setting View Administrator to Trust a vCenter Server or View Composer Certificate,” on page 93
n
“Benefits of Using SSL Certificates Signed by a CA,” on page 93
n
“Troubleshooting Certificate Issues on View Connection Server and Security Server,” on page 94
Understanding SSL Certificates for View Servers
You must follow certain guidelines for configuring SSL certificates for View servers and related
components.
View Connection Server and Security Server
SSL is required for client connections to a server. Client-facing View Connection Server instances, security
servers, and intermediate servers that terminate SSL connections require SSL server certificates.
By default, when you install View Connection Server or security server, the installation generates a self-
signed certificate for the server. However, the installation uses an existing certificate in the following cases:
n
If a valid certificate with a Friendly name of vdm already exists in the Windows Certificate Store
VMware, Inc.
77