Administration

Table Of Contents
n
Logging in with CRL Checking on page 57
When you configure CRL checking, View constructs and reads a CRL to determine the revocation
status of a user certificate.
n
Logging in with OCSP Certificate Revocation Checking on page 57
When you configure OCSP certificate revocation checking, View sends a request to an OCSP
Responder to determine the revocation status of a specific user certificate. View uses an OCSP signing
certificate to verify that the responses it receives from the OCSP Responder are genuine.
n
Configure CRL Checking on page 57
When you configure CRL checking, View reads a CRL to determine the revocation status of a smart
card user certificate.
n
Configure OCSP Certificate Revocation Checking on page 58
When you configure OCSP certificate revocation checking, View sends a verification request to an
OCSP Responder to determine the revocation status of a smart card user certificate.
n
Smart Card Certificate Revocation Checking Properties on page 59
You set values in the locked.properties file to enable and configure smart card certificate revocation
checking.
Logging in with CRL Checking
When you configure CRL checking, View constructs and reads a CRL to determine the revocation status of a
user certificate.
If a certificate is revoked and smart card authentication is optional, the Enter your user name and password
dialog box appears and the user must provide a password to authenticate. If smart card authentication is
required, the user receives an error message and is not allowed to authenticate. The same events occur if
View cannot read the CRL.
Logging in with OCSP Certificate Revocation Checking
When you configure OCSP certificate revocation checking, View sends a request to an OCSP Responder to
determine the revocation status of a specific user certificate. View uses an OCSP signing certificate to verify
that the responses it receives from the OCSP Responder are genuine.
If the user certificate is revoked and smart card authentication is optional, the Enter your user name and
password dialog box appears and the user must provide a password to authenticate. If smart card
authentication is required, the user receives an error message and is not allowed to authenticate.
View falls back to CRL checking if it does not receive a response from the OCSP Responder or if the
response is invalid.
Configure CRL Checking
When you configure CRL checking, View reads a CRL to determine the revocation status of a smart card
user certificate.
Prerequisites
Familiarize yourself with the locked.properties file properties for CRL checking. See “Smart Card
Certificate Revocation Checking Properties,” on page 59.
Procedure
1 Create or edit the locked.properties file in the SSL gateway configuration folder on the View
Connection Server or security server host.
For example: install_directory\VMware\VMware View\Server\sslgateway\conf\locked.properties
Chapter 3 Setting Up Authentication
VMware, Inc. 57