3.0.1

Table Of Contents
View Manager Administration Guide
76 VMware, Inc.
Bydefault,inViewConnectionServerwhenaclientvisitsasecurepagesuchasView
Administratortheyarepresentedwiththeselfsignedcertificateprovidedwiththe
application.Byreadingtheservercertificatetheusercandecideiftheserverisatrusted
source,andthenaccept(orreject)theco
nnection.
ThecertificatecanbesignedbyaCertificateAuthority(CA)—atrustedthird partywho
guaranteestheidentityofthecertificateanditscreator.
TocreateyourowncertificateforViewConnectionServerdooneofthefollowing:
Createaselfsignedcertificateforyoursystemusingthekeytoolutilityprovided
withtheJavaRuntimeEnvironment(JRE)instancethataccompaniesView
ConnectionServer.Selfsignedcertificatesareusergeneratedcertificatesthathave
notbeenofficiallyregisteredwithanytrustedCA,andarethereforenot
guaranteedtobeauthentic.
Createacertificateandthensendacertificatesigningrequest(CSR)thatcontains
yourcertificatedetailstoaCA.Afterconductingsomechecksonthecompanyor
individualmakingtheapplication,theCAsignstherequestandencryptsitwith
theirprivatekey.Thevalidcertificateisreturnedandistheninse
rtedintoa
keystoreonViewConnectionServer.
ClientsconnectingtoViewConnectionServerarepresentedwithyourcertificate.Ifthe
certificateisselfsignedbutacceptedbytheuser,orsignedbyaCAthatistrustedby
theclientbrowser,theclientusesthepublickeycontainedwithinthecertificat
eto
encryptthedataitsendstoViewConnectionServer.Typically ,thecertificatefortheCA
itselfisembeddedinthebrowserorislocatedinatrusteddatabasethatisaccessibleby
theclient.
Onceacertificatehasbeenaccepted,theclientrespondsbysendingitsownpublickey
soth
atViewConnectionServercanencryptthedataittransmitstotheclient.Inthis
way,asecureconnectionbetweentheclientandserverisestablished.
Bydefault,ViewConnectionServerincludesaselfsignedSSLcertificatethatclients
canusetocreatesecuresessionswhentheyconnect.Thiscertificateisnottrustedby
c
lientsanddoesnot havethecorrectnamefortheservice,butitdoesallowconnectivity.
YoucanreplacethedefaultcertificateprovidedwithViewManagerwithaproperly
definedcertificatefortheservice.IfthecertificateissignedbyatrustedCA,userswill
notbepresen
tedwithmessagesaskingthemtoverifythecertificate,andthinclient
deviceswillbeabletoconnectwithoutrequiringadditionalconfiguration.
N
OTECertificatesareonlyrequiredforstandard,replica,orsecurityserversthat
receivedirectconnectionsfromtheirclients.Ifyouareusingasecurityserverasyour
clientfacingsystem,onlythisserverwillrequireacertificate.