7.1

Table Of Contents
Certificate Trust Requirements in a Distributed Deployment
For secure communication, vRealize Automation relies on certicates to create trusted relationships among
components.
The specic implementation of the certicates required to achieve this trust depends on your environment.
To provide high availability and failover support, you might deploy load-balanced clusters of components.
In this case, you obtain a multi-use certicate that includes the IaaS Web component in the cluster, and then
copy that multi-use certicate to each component in the cluster. You can use Subject Alternative Name
(SAN) certicates, wildcard certicates, or any other method of multi-use certication appropriate for your
environment as long as you satisfy the trust requirements. If you use load balancers in your deployment,
you must include the load balancer FQDN in the trusted address of the cluster mult-use certicate.
For example, if you have a load balancer conguration that requires a certicate on the load balancer as well
as its components, you might obtain a SAN certicate to certify web-load-balancer.eng.mycompany.com,
web-component-1.eng.mycompany.com, and web-component-2.eng.mycompany.com. You would copy that
single multi-use certicate to the load balancer and each of the appliances and then register the certicate on
the Web component machines.
The Certicate Trust Requirements table summarizes the trust registration requirements for various
imported certicates.
Table 45. Certificate Trust Requirements
Import Register
vRealize Automation appliance cluster Web components cluster
Web component cluster
n
vRealize Automation appliance cluster
n
Manager Service components cluster
n
DEM Orchestrators and DEM Worker components
Manager Service component cluster
n
DEM Orchestrators and DEM Worker components
n
Agents and Proxy Agents
Configure Web Component, Manager Service and DEM Host Certificate Trust
Customers who use a thumb print with pre installed PFX les to support user authentication must congure
thumb print trust on the web host, manager service, and DEM Orchestrator and Worker host machines.
Customers who import PEM les or use self-signed certicates can ignore this procedure.
Prerequisites
Valid web.pfx and ms.pfx available for thumb print authentication.
Procedure
1 Import the web.pfx and ms.pfx les to the following locations on the web component and manager
service host machines:
n
Host Computer/Certificates/Personal certificate store
n
Host Computer/Certificates/Trusted People certificate store
2 Import the web.pfx and ms.pfx les to the following locations on the DEM Orchestrator and Worker
host machines:
Host Computer/Certificates/Trusted People certificate store
Chapter 4 The Standard vRealize Automation Installation Interfaces
VMware, Inc. 63