VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION Manual do Utilizador Página 14

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 34
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 13
TECHNICAL WHITE PAPER / 14
After VCM installation, if you decide that you want to use different certificates than the ones that you either generated
or selected during the installation process, you must replace those certificates.
Use the following procedure to replace both the Enterprise and Collector Certificates.
1. Create or obtain a new Enterprise certificate. For information on how to create an Enterprise Certificate using
MakeCert Certificate Creation Tool, see Creating Certificates for TLS Using Makecert on page 20.
2. Create or obtain a new Collector Certificate that is signed by the Enterprise Certificate. For information on how
to create a Collector Certificate using MakeCert Certificate Creation Tool, see Creating Certificates for TLS
Using Makecert on page 20.
3. Import the Enterprise Certificate into the Local Computer Trusted Root store on the VCM Collector. For more
information, see Certificate Transport on page 17.
4. Import the Collector Certificate and the private key into the Personal store on the VCM Collector. For more infor-
mation, see Certificate Transport on page 17.
5. Update the Collector Certificate thumbprint in the VCM Collector database. For more information, see Updating
the Collector Certificate Thumbprint in the VCM Collector Database on page 26
6. Restart the Collector service.
7. Import the Enterprise Certificate into the Trusted Root store on the VCM Windows Agent systems (see Cer-
tificate Transport on page 17), install the VCM Agent with the "Enable HTTP" option selected, or change pro-
tocol to DCOM and back to HTTP (only if the Collector can communicate with Agents using DCOM protocol).
On UNIX Agents, place the certificates into the VCM Agent Certificate store.
Replace Only the Collector Certificates
After VCM installation, you may find that you want to use a different Collector Certificate than you specified during
installation, but your Enterprise Certificate is still valid. In this situation, you can use the following procedure to replace
only the Collector Certificate.
1. Create or obtain a new Collector Certificate (and associated private key) that is signed by the Enterprise Cer-
tificate. For information on how to create a Collector Certificate using MakeCert Certificate Creation Tool, see
Creating Certificates for TLS Using Makecert on page 20.
2. Import the Collector Certificate and the private key into the Personal store on the VCM Collector.
3. Update the Collector Certificate thumbprint in the VCM Collector database. See Updating the Collector Cer-
tificate Thumbprint in the VCM Collector Database on page 26.
4. Restart the Collector services.
TLS Implementation for VCM
Vista de página 13
1 2 ... 9 10 11 12 13 14 15 16 17 18 19 ... 33 34

Comentários a estes Manuais

Sem comentários