6.2

Table Of Contents
9 (Optional) Click SSL.
You can import a certificate or generate a self-signed certificate for the Identity Appliance. A self-
signed certificate is also created for you when you deploy the Identity Appliance.
10 Select the certificate type from the Choose Action menu.
If you are using a PEM-encoded certificate, for example for a distributed environment, select Import
PEM Encoded Certificate.
Certificates that you import must be trusted and must also be applicable to all instances of vRealize
Appliance and any load balancer by using Subject Alternative Name (SAN) certificates.
Note If you use certificate chains, specify the certificates in the following order:
n
The client/server certificate signed by the intermediate CA certificate
n
One or more intermediate certificates
n
A root CA certificate
Option Action
Import PEM Encoded Certificate a Copy the certificate values from BEGIN PRIVATE KEY to END PRIVATE KEY,
including the header and footer, and paste them in the RSA Private Key text
box.
b Copy the certificate values from BEGIN CERTIFICATE to END
CERTIFICATE, including the header and footer, and paste them in the
Certificate Chain text box.
c (Optional) If your certificate uses a pass phrase to encrypt the certificate key,
copy the pass phrase and paste it in the Pass Phrase text box.
Generate Self-Signed Certificate a Type a common name for the self-signed certificate in the Common Name
text box. You can use the fully qualified domain name of the virtual appliance
(hostname.domain.name) or a wild card, such as *.mycompany.com.
b Type your organization name, such as your company name, in the
Organization text box.
c Type your organizational unit, such as your department name or location, in
the Organizational Unit text box.
d Type a two-letter ISO 3166 country code, such as US, in the Country text
box.
Keep Existing Leave the current SSL configuration. Select this option to cancel your changes.
11 Click Apply Settings.
After a few minutes the certificate details appear on the page.
12 Join the Identity Appliance to your Native Active Directory domain.
For migration, you must configure Native Active Directory. If you are not using the migration tool, this
step is optional.
a Click the Active Directory tab.
b Type the domain name of the Active Directory in Domain Name.
Installation and Configuration
VMware, Inc. 67