5.1

Table Of Contents
e Select the encryption algorithm for communication between the hosts.
Note that SSL VPN-Plus only supports RSA certificates. VMware recommends RSA for backward
compatibility.
f Edit the default key size if required.
g Type a description for the certificate.
h Click OK.
The CSR is generated and displayed in the Certificates list.
9 Verify that the certificate you generated is selected.
10
Click the Self Sign Certificate (
) icon.
11 Type the number of days the self sign certificate is valid for.
12 Click OK.
Using Client Certificates
You can create a client certificate through a CAI command or REST call. You can then distribute this certificate
to your remote users, who can install the certificate on their web browser
The main benefit of implementing client certificates is that a reference client certificate for each remote user
can be stored and checked against the client certificate presented by the remote user. To prevent future
connections from a certain user, you can delete the reference certificate from the security server's list of client
certificates. Deleting the certificate denies connections from that user.
Add a Certificate Revocation List
A Certificate Revocation List (CRL) is a list of subscribers and their status, which is provided and signed by
Microsoft.
The list contains the following items:
n
The revoked certificates and the reasons for revocation
n
The dates that the certificates are issued
n
The entities that issued the certificates
n
A proposed date for the next release
When a potential user attempts to access a server, the server allows or denies access based on the CRL entry
for that particular user.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click a vShield Edge.
6 Click the Configure tab.
7 Click the Certificates link.
8
Click the Add ( ) icon and select Certificate.
Chapter 9 vShield Edge Management
VMware, Inc. 69