5.5.1

Table Of Contents
9 When prompted for the password for dunes, press Enter to use the same password as the keystore
password (dunesdunes).
10 Log in to the Orchestrator configuration interface as vmware and start the Orchestrator server service.
a In the Orchestrator configuration interface, click the Startup Options tab.
b Click Start service.
What to do next
You can create a signing request and submit the certificate to a Certificate Authority. You can then import
the signed certificate into your local keystore.
You can also replace the Web views SSL certificate, the SSL certificate for the Orchestrator configuration
interface, or the SSL certificate for the Orchestrator client with the certificate you generated.
Install a Certificate from a Certificate Authority
To install a signed certificate from a Certificate Authority you must obtain an SSL certificate from a CA and
import it in your local keystore.
Prerequisites
Generate a new SSL certificate.
Procedure
1 Create a certificate signing request by running the following command in the Java utility.
keytool -certreq -dunes -keypass "dunesdunes" -keystore
"install_directory\app-server\conf\security\jssecacerts" -storepass
"dunesdunes" -file certreq.csr
The utility generates a file called certreq.csr.
2 (Optional) Submit the certreq.csr file to a certificate authority, such as VeriSign or Thawte.
Procedures might vary from one CA to another, but they all require a valid proof of your identity.
The CA returns a certificate that you must import.
3 Import the SSL certificate into your local keystore.
a Download a root certificate from the CA that signed your certificate.
b Import the root certificate in your keystore by running the following command in the Java utility.
keytool -import -alias root -keystore
"install_directory\app-server\conf\security\jssecacerts" \
-trustcacerts -file <filename_of_the_root_certificate>
c Import the SSL certificate signed by the CA (the SSL certificate must be in X509 DER format).
keytool -importcert -alias dunes -keypass "dunedunes" -file
vcoCertificate.crt -keystore
"install_directory\app-server\conf\security\jssecacerts" -storepass "dunesdunes"
The SSL certificate is installed. You can change the Web views SSL certificate, the SSL certificate for the
Orchestrator configuration interface, or the SSL certificate for the Orchestrator client.
Installing and Configuring VMware vCenter Orchestrator
104 VMware, Inc.