
View Manager Administration Guide
100 VMware, Inc.
Bydefault,inViewConnectionServerwhenaclientvisitsasecurepagesuchas
View Administratortheyarepresentedwiththeself‐signedcertificateprovidedwith
theapplication.Byreadingtheservercertificatetheusercandecideiftheserverisa
trustedsource,andthenaccept(orreject)theconnection.
ThecertificatecanbesignedbyaCertificateAuthority(CA)—atrustedthirdpartywho
guaranteestheidentityofthecertificateanditscreator.
TocreateyourowncertificateforViewConnectionServerdooneofthefollowing:
Createaself‐signedcertificateforyoursystemusingthekeytoolutilityprovided
withtheJavaRuntimeEnvironment(JRE)instancethataccompaniesView
ConnectionServer.Self‐signedcertificatesareusergeneratedcertificatesthathave
notbeenofficiallyregisteredwithanytrustedCA,andarethereforenot
guaranteedtobeauthentic.
Createacertificateandthensendacertificatesigningrequest(CSR)thatcontains
yourcertificatedetailstoaCA.Afterconductingsomechecksonthecompanyor
individualmakingtheapplication,theCAsignstherequestandencryptsitwith
theirprivatekey.Thevalidcertificateisreturnedandisthen
insertedintoa
keystoreonViewConnectionServer.
ClientsconnectingtoViewConnectionServerarepresentedwithyourcertificate.Ifthe
certificateisself‐signedbutacceptedbytheuser,orsignedbyaCAthatistrustedby
theclientbrowser,theclientusesthepublickeycontainedwithinthe
certificateto
encryptthedataitsendstoViewConnectionServer.Typically ,thecertificatefortheCA
itselfisembeddedinthebrowserorislocatedinatrusteddatabasethatisaccessibleby
theclient.
Afteracceptingthecertificate,theclientrespondsbysendingasecretkey,whichis
encrypted
withtheserver’spublickey.Thiskeyisusedtoencrypttrafficbetweenthe
clientandtheViewConnectionServerinstanceorsecurityserver.
Bydefault,ViewConnectionServerincludesaself‐signedSSLcertificatethatclients
canusetocreatesecuresessionswhentheyconnect.Thiscertificateisnot
trustedby
clientsanddoesnothavethecorrectnamefortheservice,butitdoesallowconnectivity.
N
OTEItisstronglyrecommendedthatyoucontinuetousethedefaultcertificate
providedwithViewConnectionServeruntilyouarereadytocreateyourown
certificateandgetitsignedbyaCA.
N
OTECertificatesareonlyrequiredforstandard,replica,orsecurityserversthat
receivedirectconnectionsfromtheirclients.Ifyouareusingasecurityserverasyour
client‐facingsystem,onlythisserverwillrequireacertificate.
Commentaires sur ces manuels