VMware Horizon Community
KyleCompassion
Enthusiast
Enthusiast

Replace expiring SSL certificate on View 5.1 security server

Are there steps to replace an expiring SSL certificate on a view 5.1 security server? i found documentation for 5.0, but don't see anything for replacing the existing cert on 5.1. Is it as simple as placing the new cert on the server, changing the VDM value on the existing cert, and putting VDM on the new cert and then restarting the view services?

0 Kudos
3 Replies
mittim12
Immortal
Immortal

Yes, in most cases it is that simple.  I used the certreq.exe to generte my certificate request and apply the ceritifcate to the server.   I then added VDM to the friendly name and rebooted the server, though I think a restart of the service would suffice.     As in all instances you would want to have a backup plan such as snapshot the server prior to making any changes.

Here is a KB that describes another method.   http://kb.vmware.com/kb/2020913

0 Kudos
bjm534
Enthusiast
Enthusiast

Basically that is all you need to do. You'll need to generate your new cert and import it into the certificate manager within windows, make sure you do it for the computer and not for just the user. this needs to be done on all brokers, load balnacers and security servers. Restart the services when you are done and it should all work. Also you need to ensure that the "external URL" that is defined on the SS and CS are the same as what you've requested the cert for.

More info here

VMware KB: Using Microsoft Certreq to generate and import a signed certificate into Horizon View 5.1...

Also if you have zero clients you need them to trust the cert you are installing as well

VMwareAmI: Teradici Firmware version 4 and Certificates

-Brad

-Brad
0 Kudos
VirtualMattCT
Enthusiast
Enthusiast

The last few times I've done it, I just renewed the cert with my CA (without having to go through the cert req process), deleted the old cert with the certificates MMC, imported the new cert, gave it the vdm friendly name, and recycled the SS or CS service(s).  Whole process should take about 5-10 minutes.

0 Kudos