3.0.1
Table Of Contents
- Administration Guide
- Contents
- About This Book
- Introduction
- Installation
- View Administrator
- Virtual Desktop Deployment
- Client Management
- View Client and View Portal
- Client Connections from the Internet
- Creating SSL Server Certificates
- Using Existing SSL Certificates
- Smart Card Authentication
- RSA SecurID Authentication
- View Client Command Line Options
- Virtual Printing
- View Composer
- Offline Desktop
- Component Policies
- Unified Access
- Troubleshooting
- Glossary
- Index
View Manager Administration Guide
76 VMware, Inc.
Bydefault,inViewConnectionServerwhenaclientvisitsasecurepagesuchasView
Administratortheyarepresentedwiththeself‐signedcertificateprovidedwiththe
application.Byreadingtheservercertificatetheusercandecideiftheserverisatrusted
source,andthenaccept(orreject)theco
nnection.
ThecertificatecanbesignedbyaCertificateAuthority(CA)—atrustedthird partywho
guaranteestheidentityofthecertificateanditscreator.
TocreateyourowncertificateforViewConnectionServerdooneofthefollowing:
Createaself‐signedcertificateforyoursystemusingthekeytoolutilityprovided
withtheJavaRuntimeEnvironment(JRE)instancethataccompaniesView
ConnectionServer.Self‐signedcertificatesareusergeneratedcertificatesthathave
notbeenofficiallyregisteredwithanytrustedCA,andarethereforenot
guaranteedtobeauthentic.
Createacertificateandthensendacertificatesigningrequest(CSR)thatcontains
yourcertificatedetailstoaCA.Afterconductingsomechecksonthecompanyor
individualmakingtheapplication,theCAsignstherequestandencryptsitwith
theirprivatekey.Thevalidcertificateisreturnedandistheninse
rtedintoa
keystoreonViewConnectionServer.
ClientsconnectingtoViewConnectionServerarepresentedwithyourcertificate.Ifthe
certificateisself‐signedbutacceptedbytheuser,orsignedbyaCAthatistrustedby
theclientbrowser,theclientusesthepublickeycontainedwithinthecertificat
eto
encryptthedataitsendstoViewConnectionServer.Typically ,thecertificatefortheCA
itselfisembeddedinthebrowserorislocatedinatrusteddatabasethatisaccessibleby
theclient.
Onceacertificatehasbeenaccepted,theclientrespondsbysendingitsownpublickey
soth
atViewConnectionServercanencryptthedataittransmitstotheclient.Inthis
way,asecureconnectionbetweentheclientandserverisestablished.
Bydefault,ViewConnectionServerincludesaself‐signedSSLcertificatethatclients
canusetocreatesecuresessionswhentheyconnect.Thiscertificateisnottrustedby
c
lientsanddoesnot havethecorrectnamefortheservice,butitdoesallowconnectivity.
YoucanreplacethedefaultcertificateprovidedwithViewManagerwithaproperly
definedcertificatefortheservice.IfthecertificateissignedbyatrustedCA,userswill
notbepresen
tedwithmessagesaskingthemtoverifythecertificate,andthinclient
deviceswillbeabletoconnectwithoutrequiringadditionalconfiguration.
N
OTECertificatesareonlyrequiredforstandard,replica,orsecurityserversthat
receivedirectconnectionsfromtheirclients.Ifyouareusingasecurityserverasyour
client‐facingsystem,onlythisserverwillrequireacertificate.