6.0.3

Table Of Contents
2 If a host is not provisioned by Auto Deploy, change the default SSL certicate to a self-signed certicate
or to a certicate signed by a commercial certicate authority (CA).
Option Description
VMCA certificate
If you are using the default VMCA-signed certicates, you have to ensure
that the authentication proxy host trusts the VMCA certicate.
a Manually add the VMCA certicate to the Trusted Root Certicate
Authorities certicate store.
b
Add the VMCA-signed certicate (root.cer) to the local trust
certicate store on the system where the authentication proxy service
is installed. You can nd the le in
C:\ProgramData\VMware\CIS\data\vmca.
c Restart the vSphere Authentication Proxy service.
Third-party CA-signed certificate
Add the CA-signed certicate (DER-encoded) to the local trust certicate
store on the system where the authentication proxy service is installed and
restart the vSphere Authentication Proxy service.
n
For Windows 2003, copy the certicate le to C:\Documents and
Settings\All Users\Application Data\VMware\vSphere
Authentication Proxy\trust.
n
For Windows 2008, copy the certicate le to C:\Program
Data\VMware\vSphere Authentication Proxy\trust.
Setting up vSphere Authentication Proxy
Your ESXi hosts can use a vSphere Authentication proxy if they have the Authentication Proxy certicate
information.
You need only authenticate the server once.
N ESXi and the Authentication Proxy server must be able to authenticate. Make sure that this
authentication functionality is enabled at all times. If you must disable authentication, you can use the
Advanced Seings dialog box to set the UserVars.ActiveDirectoryVerifyCAMCertifcate aribute to 0.
Export vSphere Authentication Proxy Certificate
To authenticate the vSphere Authentication Proxy to ESXi, you must provide ESXi with the proxy server
certicate.
Prerequisites
Install the vSphere Authentication Proxy (CAM service) on a host. See “Install or Upgrade vSphere
Authentication Proxy,” on page 189.
Procedure
1 On the authentication proxy server system, use the IIS Manager to export the certicate.
Option Action
For IIS 6
a Right-click Computer Account Management Web Site.
b Select Properties > Directory Security > View .
For IIS 7
a Click Computer Account Management Web Site in the left pane.
b Select Bindings to open the Site Bindings dialog box.
c Select  binding.
d Select Edit > View SSL  .
2 Select Details > Copy to File.
3 Select the options Do Not Export the Private Key and Base-64 encoded X.509 (CER).
vSphere Security
194 VMware, Inc.