Monday, August 27, 2012

Integrating XenDesktop 5.6 with VMWare VCenter 5 Certificate Error


I ran into this issue earlier today while configuring my first XenDesktop setup using VMWare.  To resolve this issue, you can do one of three things.

Option 1: Purchase an SSL certificate for your vCenter from a third party.

Option 2: Self-sign a certificate from your enterprise certificate authority.

Option 3: Trust the existing SSL certificate  This option is by far the quickest and easiest. To do that, you can follow these steps:
  1. If you are logged in as a local administrator, open Internet Explorer and navigate to https://YOURVCENTERSERVERNAME/
  2. If you are not logged in as local administrator, or a user with sufficient permissions, it is very important that you SHIFT & Right-Click Internet Explorer, and run it as an Administrator, then navigate to https://YOURVCENTERSERVERNAME/
  3. You will get a warning screen that the SSL Certificate is not trusted, select Continue to this web site (not recommended).
  4. Click the Certificate error in the Security Status bar and select View Certificate.
  5. Click Install Certificate.
  6. When the Certificate Import Wizard launches, select Place All Certificates in the following store and click Browse.
  7. When the Select Certificate Store window comes up, make sure you select the check box for Show physical stores.
  8. Find and expand Trusted People, select Local Computer and click OK.
  9. It is important to note that if you don't see the Local Computer option under trusted People, you are not logged in with a user that has sufficient rights, therefore, you must run Internet Explorer as an Administrator.
  10. Click Finish to complete the certificate import process
  11. Click OK when you receive the import successful window
  12. Close your browser, re-open it again, and browse to your vCenter server using the FQDN. The browser should now trust your vCenter server and therefore you should not receive a certificate error. That is how you can verify if the process was successful.  Make sure you test using the FQDN or it will not work.
  13. Repeat the above steps on the XenDesktop server as well.  That way both machines trust the self-signed certificate.
  14. Configure the hosting infrastructure settings on the XenDesktop 5 controller to point to https://vCenterServer.domain.com/sdk
That's it.  From there you can continue with your configuration.

No comments: