book
Article ID: CTX238398
calendar_today
Updated On:
Description
The articles provides instruction to obtain and import a VMware-installed self-signed Certificate for vCenter Server to each controller.
Instructions
Obtain and import a certificate
To protect vSphere communications, Citrix recommends that you use HTTPS rather than HTTP. HTTPS requires digital certificates. Citrix recommends you use a digital certificate issued from a certificate authority in accordance with your organization's security policy.
If you are unable to use a digital certificate issued from a certificate authority, and your organization's security policy permits it, you can use the VMware-installed self-signed certificate. Add the VMware vCenter certificate to each Controller. Follow this procedure:
- Add the fully qualified domain name (FQDN) of the computer running vCenter Server to the hosts file on that server, located at %SystemRoot%/WINDOWS/system32/Drivers/etc/. This step is required only if the FQDN of the computer running vCenter Server is not already present in the domain name system.
- Obtain the vCenter certificate using any of the following methods:
- From the vCenter server:
- Copy the file rui.crt from the vCenter server to a location accessible on your Delivery Controllers.
- On the Controller, navigate to the location of the exported certificate and open the rui.crt file.
- Download the certificate using a web browser. If you are using Internet Explorer, depending on your user account, you may need to right-click on Internet Explorer and choose Run as Administrator to download or install the certificate.
- Open your web browser and make a secure web connection to the vCenter server; for example https://server1.domain1.com
- Accept the security warnings.
- Click on the address bar where it shows the certificate error.
- View the certificate and click on the Details tab.
- Select Copy to file and export in .CER format, providing a name when prompted to do so.
- Save the exported certificate.
- Navigate to the location of the exported certificate and open the .CER file.
- Import directly from Internet Explorer running as an administrator:
- Open your web browser and make a secure web connection to the vCenter server; for example https://server1.domain1.com.
- Accept the security warnings.
- Click on the address bar where it shows the certificate error.
- View the certificate.
- Import the certificate into the certificate store on each of your Controllers:
- Click Install certificate, select Local Machine, and then click Next.
- Select Place all certificates in the following store, and then click Browse.
- If you are using Windows Server 2008 R2:
- Select the Show physical stores check box.
- Expand Trusted People.
- Select Local Computer.
- Click Next, then click Finish.
If you are using Windows Server 2012 or Windows Server 2012 R2:
- Select Trusted People, then click OK.
- Click Next, then click Finish.
Important: If you change the name of the vSphere server after installation, you must generate a new self-signed certificate on that server before importing the new certificate.
Issue/Introduction
XenApp/XenDesktop 7.X : How to Obtain and Import A VMware-installed Self-Signed Certificate For vCenter Server To Each Controller