Installation

Table Of Contents
2 Configure a PSG Certificate in the Windows Certificate Store on page 84
To replace the default PSG certificate with a CA-signed certificate, you must configure the certificate
and its private key in the Windows local computer certificate store on the View Connection Server or
security server computer on which the PSG is running.
3 Set the PSG Certificate Friendly Name in the Windows Registry on page 86
The PSG identifies the SSL certificate to use by means of the server name and certificate Friendly
name. You must set the Friendly name value in the Windows registry on the View Connection Server
or security server computer on which the PSG is running.
4 (Optional) Force a CA-Signed Certificate to Be Used for Connections to the PSG on page 86
You can ensure that all client connections to the PSG use the CA-signed certificate for the PSG instead
of the default legacy certificate. This procedure is not required to configure a CA-signed certificate for
the PSG. Take these steps only if it makes sense to force the use of a CA-signed certificate in your View
deployment.
Verify That the Server Name Matches the PSG Certificate Subject Name
When a View Connection Server instance or security server is installed, the installer creates a registry setting
with a value that contains the FQDN of the computer. You must verify that this value matches the server
name part of the URL that security scanners use to reach the PSG port. The server name also must match the
subject name or a subject alternate name (SAN) of the SSL certificate that you intend to use for the PSG.
For example, if a scanner connects to the PSG with the URL https://view.customer.com:4172, the registry
setting must have the value view.customer.com. Note that the FQDN of the View Connection Server or
security server computer that is set during installation might not be the same as this external server name.
Procedure
1 Start the Windows Registry Editor on the View Connection Server or security server host where the
PCoIP Secure Gateway is running.
2 Navigate to the HKEY_LOCAL_MACHINE\SOFTWARE\Teradici\SecurityGateway\SSLCertPsgSni registry
setting.
3 Verify that the value of the SSLCertPsgSni setting matches the server name in the URL that scanners
will use to connect to the PSG and matches the subject name or a subject alternate name of the SSL
certificate that you intend to install for the PSG.
If the value does not match, replace it with the correct value.
4 Restart the VMware Horizon View PCoIP Secure Gateway service to make your changes take effect.
What to do next
Import the CA-signed certificate into the Windows local computer certificate store and configure the
certificate Firendly name.
Configure a PSG Certificate in the Windows Certificate Store
To replace the default PSG certificate with a CA-signed certificate, you must configure the certificate and its
private key in the Windows local computer certificate store on the View Connection Server or security
server computer on which the PSG is running.
If you intend the PSG to use a unique certificate, you must import the certificate into the Windows local
computer certificate store with an exportable private key and set the appropriate Friendly name.
If you intend the PSG to use the same certificate as the server, you do not have to follow this procedure.
However, in the Windows registry you must set the server name to match the server certificate subject name
and set the Friendly name to vdm.
View Installation
84 VMware, Inc.