
VMware, Inc. 101
Chapter 5 Client Management
YoucanreplacethedefaultcertificateprovidedwithViewwithaproperlydefined
certificatefortheservice.IfthecertificateissignedbyatrustedCA,userswillnotbe
presentedwithmessagesaskingthemtoverifythecertificate,andthinclientdevices
willbeabletoconnectwithoutrequiringadditional
configuration.
TocreateandinstallyourowncertificateyoumustfirstaddtheJavakeytoolutilityto
yourcommandpathsothatyoucanexecuteitfromanylocationusingthecommand
prompt.Oncethisisdone youcancreateaself‐signedSSLcertificateusingthekeytool
utility.
Toobtain
avalidatedcertificatethathasbeensignedbyatrustedthird‐partyyoumust
firstsubmitacertificatesigningrequest(CSR)totheCA.Onceyouhavereceiveda
trustedcertificatefromtheCAyoucanimportitintothekeystorefortheView
ConnectionServer,andthenconfigureViewConnection
Servertouseit.
Creating an SSL Certificate
Decidingwhatnametobindtoacertificateisanimportantconsideration.Acertificate
bindsthenameoftheservicetoacryptographickeypairand,indoingso,assumes
ownershipoftheserviceandkeys.
Oncethecertificateissignedtheclientcantrusttheserver(anditscryptographickey)
becausetheCAindependentlydeterminedthattheorganizationthatisclaiming
ownershiprequestedthekey.
Themostimportantpartofthecertificateisthecommonname(CN)attribute.Usethe
FQDNthattheclientcomputerusestoconnecttotheViewConnectionServer.Ina
single‐serverenvironment,thename
istypicallythenameoftheserver.Ifload
balancingisbeingused,usetheload‐balancername.
To add the Java keytool to the system path
1PresstheWindowskey+BreaktodisplaytheWindowsSystemPropertiesdialog
box.
2UndertheAdvancedtab,clickEnvironmentVariables.
3IntheSystemvariablesgroup,selectPATHandthenclickEdit.
N
OTEYoumayalreadyhaveanSSLcertificatethatyouwanttousewithView
ConnectionServer.Referto“UsingExistingSSLCertificates”onpage 105formore
informationonhowtodothis.
Comentários a estes Manuais