5.1

Table Of Contents
Add an SSL Certificate to Identify the vShield Manager Web Service
You can generate a certificate signing request, get it signed by a CA, and import the signed SSL certificate into
vShield Manager to authenticate the identity of the vShield Manager web service and encrypt information sent
to the vShield Manager web server. As a security best practice, you should use the generate certificate option
to generate a private key and public key, where the private key is saved to the vShield Manager.
Procedure
1 Click Settings & Reports from the vShield Manager inventory panel.
2 Click the Configuration tab.
3 Click SSL Certificate.
4 Under Generate Certificate Signing Request, complete the form by filling in the following fields:
Option Action
Common Name
Type the IP address or fully qualified domain name (FQDN) of the vShield
Manager. VMware recommends that you enter the FQDN.
Organization Unit
Enter the department in your company that is ordering the certificate.
Organization Name
Enter the full legal name of your company.
City Name
Enter the full name of the city in which your company resides.
State Name
Enter the full name of the state in which your company resides.
Country Code
Enter the two-digit code that represents your country. For example, the
United States is US.
Key Algorithm
Select the cryptographic algorithm to use from either DSA or RSA. VMware
recommends RSA for backward compatibility.
Key Size
Select the number of bits used in the selected algorithm.
5 Click Generate.
Import an SSL certificate
You can import a pre-existing or CA signed SSL certificate for use by the vShield Manager.
Procedure
1 Click Settings & Reports from the vShield Manager inventory panel.
2 Click the Configuration tab.
3 Click SSL Certificate.
4 Under Import Signed Certificate, click Browse at Certificate File to find the file.
5 Select the type of certificate file from the Certificate Type drop-down list.
If applicable, import root and intermediate certificates before importing the CA signed certificate. If there
are multiple intermediate certificates, combine them into a single file and then import the file.
6 Click Apply.
A yellow bar containing the message Successfully imported certificate is displayed at the top of the screen.
7 Click Apply Certificate.
vShield Manager is restarted to apply the certificate.
The certificate is stored in the vShield Manager.
vShield Administration Guide
20 VMware, Inc.