VMware View Manager 4.5 Admin Manual page 121

Hide thumbs Also See for View Manager 4.5:
Table of Contents

Advertisement

Obtain the Root Certificate from the CA
You must obtain the root certificate from the CA that signed the certificates on the smart cards presented by
your users.
If you do not have the root certificate of the CA that signed the certificates on the smart cards presented by
your users, you can export a root certificate from a CA-signed user certificate or a smart card that contains one.
See
"Export a Root Certificate from a User Certificate,"
Procedure
1
Obtain the root certificate from one of the following sources.
A Microsoft IIS server running Microsoft Certificate Services. See the Microsoft TechNet Web site for
n
information on installing Microsoft IIS, issuing certificates, and distributing certificates in your
organization.
The public root certificate of a trusted CA. This is the most common source of a root certificate in
n
environments that already have a smart card infrastructure and a standardized approach to smart
card distribution and authentication.
2
Select a certificate to use for smart card authentication.
The signing chain lists a series a signing authorities. The best certificate to select is usually the intermediate
authority above the user certificate.
3
Verify that the authority does not sign other certificates on the card.
What to do next
Add the root certificate to a server truststore file. See
page 122.
Export a Root Certificate from a User Certificate
If you have a CA-signed user certificate or a smart card that contains one, you can export the root certificate if
it is trusted by your system.
Procedure
1
If the user certificate is on a smart card, insert the smart card into the reader to add the user certificate to
your personal store.
If the user certificate does not appear in your personal store, use the reader software to export the user
certificate to a file.
2
In Internet Explorer, select Tools > Internet Options.
3
On the Content tab, click Certificates.
4
On the Personal tab, select the certificate you want to use and click View.
If the user certificate does not appear on the list, click Import to manually import it from a file. After the
certificate is imported, you can select it from the list.
5
On the Certification Path tab, select the certificate at the top of the tree and click View Certificate.
If the user certificate is signed as part of a trust hierarchy, the signing certificate might be signed by another
higher-level certificate. Select the parent certificate (the one that actually signed the user certificate) as
your root certificate.
6
On the Details tab, click Copy to File.
The Certificate Export Wizard appears.
VMware, Inc.
Chapter 7 Setting Up User Authentication
on page 121.
"Add the Root Certificate to a Server Truststore File,"
on
121

Advertisement

Table of Contents
loading

This manual is also suitable for:

View composer 2.5

Table of Contents