(cas:72) Google Analyticator was unable to authenticate you with Google using the Auth Token you pasted into the input box on the previous step.

This could mean either you pasted the token wrong, or the time/date on your server is wrong, or an SSL issue preventing Google from Authenticating.

Try Deauthorizing & Resetting Google Analyticator.

Tech Info 400:Error fetching OAuth2 access token, message: 'invalid_grant'
Unique
Visitors
Powered By Google Analytics
SSL Certificates – Long White Virtual Cloudsu by http://longwhiteclouds.com all things Nutanix, VMware, cloud and virtualizing business critical applications Thu, 26 Sep 2013 21:41:17 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.6 45024036 The Trouble With SSL Certificates and Upgrading to VMware SSO 5.5 http://longwhiteclouds.com/2013/09/27/the-trouble-with-ssl-certificates-and-upgrading-to-vmware-sso-5-5/ http://longwhiteclouds.com/2013/09/27/the-trouble-with-ssl-certificates-and-upgrading-to-vmware-sso-5-5/#comments Thu, 26 Sep 2013 19:05:48 +0000 http://longwhiteclouds.com/?p=2397


If you’re upgrading from vSphere 5.1 to vSphere 5.5 and you ARE NOT using Custom CA SSL Certificates then you might run into an error. The error will be encountered during the upgrade of SSO, and specifically the Lookup Service, and only occurs in specific conditions, such as when using the default VMware Self-Signed Certificates. […]

]]>


SSL Secure

If you’re upgrading from vSphere 5.1 to vSphere 5.5 and you ARE NOT using Custom CA SSL Certificates then you might run into an error. The error will be encountered during the upgrade of SSO, and specifically the Lookup Service, and only occurs in specific conditions, such as when using the default VMware Self-Signed Certificates. If you run into this problem your upgrade process will roll back, but leave behind some upgrade files that need to be cleaned up. This article will briefly touch on the recommended solution to this problem.

Many of you will recall the many articles that I wrote regarding updating the default self-signed SSL Certificates in vSphere 5.0 and 5.1 to Custom CA Certificates. If you haven’t seen these articles and you’re interested in SSL Security you can check out Updating CA SSL Certificates in vSphere 5.1 and Updating CA SSL Certificates in vSphere 5. To make the process of updating certificates easier VMware created the VMware Certificate Automation Tool and VMware Partner VSS Labs created vCert Manager.  If you’re using CA Signed Certificates for your SSL communications between the various vCenter components then you won’t strike the problem I described above. So now might be a good time to review my previous articles and/or use one of the automation solutions that are available.

This issue during the upgrade from vCenter 5.1 to vCenter 5.5 is described in the VMware KB Article – Upgrade from vSphere 5.1 to vSphere 5.5 rolls back after importing Lookup Service data (2060511). You will likely see an error such as “Warning 25000. Please verify that the SSL certificate for your vCenter Single Sign-On 5.1 SSL is not expired. If it did expire, please replace it with a valid certificate before upgrading to vCenter Single Sign-On 5.5.” or the vCenter Upgrade will simply fail and roll back. In the vim-sso-msi.log you will see an error message like the following:

“Action 10:06:03: PostInstallScripts. Importing Lookupservice data…
CustomAction DoUpdateAndMigrateTasks returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)”

As described in the VMware KB this issue does not affect you if:

  • You are using custom certificates (recommended)
  • You are using the vCenter Server Virtual Appliance (only applies to the Windows version of vCenter Server)
  • You are performing a fresh install of vCenter Server 5.5
  • You are upgrading from:
    • vCenter Server 5.0
    • vCenter Server 4.x
    • a fresh install of vCenter Server 5.1 Update 1a or later

For the recommended fix please refer to the VMware KB – Upgrade from vSphere 5.1 to vSphere 5.5 rolls back after importing Lookup Service data (2060511). The fix will require modifying the Windows Registry. Before any upgrade of vCenter is attempted it is recommended that you take a backup and potentially have a snapshot in place for the vCenter Database and the vCenter Server system itself so you have a point you can roll back to. This should be standard practice in most VMware environments, as should testing the upgrade process, as should upgrading test environments and management environments before upgrading production. Given that this impacts environments that have self-signed certificates it has the potential to impact a large number of customers, however as it only impacts customers upgrading from vCenter 5.1 prior to version Update 1a to vCenter 5.5, the number of impacted customers is reduced.

 

Final Word

The easiest way to get around this problem if you’re using vCenter 5.1 would be to either run through the registry fix described in the KB article. Upgrading to vCenter 5.1 U1b will not correct the issue as it doesn’t correct the certificate. You may also choose to completely rebuild your vCenter with a fresh install of vCenter 5.5 against your existing database. Alternatively you may choose to update your vCenter Server to use CA Signed Certificates, which will also improve the security of your critical management infrastructure. Regardless of the option you choose make sure you have a backup of the vCenter Database and vCenter so you can roll back if needed.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.

 


]]>
http://longwhiteclouds.com/2013/09/27/the-trouble-with-ssl-certificates-and-upgrading-to-vmware-sso-5-5/feed/ 14 2397
VSS Labs To Showcase Latest VMware Automation Solutions At VMworld USA 2013 http://longwhiteclouds.com/2013/08/21/vss-labs-to-showcase-latest-vmware-automation-solutions-at-vmworld-usa-2013/ http://longwhiteclouds.com/2013/08/21/vss-labs-to-showcase-latest-vmware-automation-solutions-at-vmworld-usa-2013/#comments Wed, 21 Aug 2013 08:45:36 +0000 http://longwhiteclouds.com/?p=2229


VSS Labs will be showcasing its latest offerings at the New Innovator Pavilion at Booth 2035 at VMworld USA 2013. The two offerings include it’s globally successful and VMware exclusive Cloud Migration Portal and it’s new SSL Certificate lifecycle management product vCert Manager. Lets have a look at what these two products are all about to give […]

]]>


VSSLabsLogoVSS Labs will be showcasing its latest offerings at the New Innovator Pavilion at Booth 2035 at VMworld USA 2013. The two offerings include it’s globally successful and VMware exclusive Cloud Migration Portal and it’s new SSL Certificate lifecycle management product vCert Manager. Lets have a look at what these two products are all about to give you a glimpse of what you might find out at their booth at VMworld USA.

Cloud Migration Portal Takes The Manual Out of Migrating To The Cloud

Automated migration of workloads from physical to virtual, virtual to virtual and now a new prototype that shows the automated migration from Amazon’s AWS to VMware’s vCHS.  VSS Labs will be showing an early prototype of a solution to fully automate migration of workloads from Amazon’s AWS (Amazon Web Services) to VMware’s new vCHS offering – VMware vCloud Hybrid Services. This prototype is expected to be fully integrated into the VSS Labs Cloud Migration Portal (CMP) by Q4, 2013. CMP is a fully automated solution that manages and automates large scale any to VMware vSphere environment migration projects. It has deep integration with the VMware stack and cuts down migration times by a factor of 5x or more. VMware has exclusively licensed CMP from VSS Labs for use at no charge by its partners, clients and internal professional services organizations and has used this with great success in a number of migration projects now. This latest addition will no doubt create huge value for the burgeoning interest in vCHS.

VSS Labs Brings You The Big Red Easy Button for VMware SSL Certificate Lifecycle Managementthat-was-easy

VSS Labs have just announced the GA release of vCert Manager, their fully automated lifecycle management solution for managing SSL certificates in a VMware environment. This is the culmination of almost a full years development, testing and feedback in a collaborative way with many of the worlds largest organisations and the VMware community.

Security and compliance requirements now force VMware’s large customers including the largest banks to implement trusted SSL Certificates and they can’t use the default self-signed certs that ship with off the shelf products any longer. Moreover, all US government organizations will be required to have certificates of greater than 2048 bit strength by the end of 2013. vCert Manager provides an automated solution to these issues and can scale from handling small environments to those containing dozens of vCenters and thousands of hosts.

The GA release of vCert Manager follows an extensive beta program that VSS Labs ran with a number of large enterprises and incorporates several features and enhancements that resulted from feedback from this program. vCert Manager 1.0 includes the ability to update and manage SSL certificates for vCenter Server (including multi-located SSO and other vCenter components), ESX/ESXi host certificate, with the ability to automatically change revoked certificates, do bulk certificate import, export of certificate signing requests, early warning and replacement of expired certificates and a number of other features. Derek Seaman covered the vCert Manager capabilities well in his article VMware SSL Pain? vCert Manager to the Rescue.

One of the best things about vCert Manager is that VSS Labs will be providing a FREE limited edition for home lab use. If you want to use vCert Manager in a home lab you’ll be able to get a license to use it on up to 1 vCenter and 5 hosts. If you’re a VMware vExpert there is a special edition license for you that will allow you to use vCert Manaer on up to 2 vCenters and 10 hosts. This is a great way for VSS Labs to show its support for the VMware Community that was so instrumental in the development of the vCert Manager solution.

Where can I get it!? 

To learn more about both these offerings or to request for an evaluation version, go to www.vsslabs.com, or contact Luisa Juaton deGuzman using the form at the bottom of this post.

 

Final Word

To make large scale cloud migration and secure management of the environments afterward possible you need great automation tools. VSS Labs and VMware bring you such levels of automation. It’s great to see the two companies working together in partnership to deliver such great value to customers. If you are going to VMworld USA I would strongly encourage you to check out the new Innovator Pavilion at Booth 2035 and stop by the VSS Labs area to get a full demo of both of these products. Remember if you want to request an evaluation or find out more about the products above from VSS Labs you can use the contact form below. Don’t forget to check out Derek Seaman article on vCert Manager – VMware SSL Pain? vCert Manager to the Rescue.

[contact-form]

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.

 


]]>
http://longwhiteclouds.com/2013/08/21/vss-labs-to-showcase-latest-vmware-automation-solutions-at-vmworld-usa-2013/feed/ 4 2229
Automating vSphere SSL Cert Management – vCert Manager Beta Demo http://longwhiteclouds.com/2013/01/31/automating-vsphere-ssl-cert-management-vcert-manager-beta-demo/ http://longwhiteclouds.com/2013/01/31/automating-vsphere-ssl-cert-management-vcert-manager-beta-demo/#comments Thu, 31 Jan 2013 10:32:08 +0000 http://longwhiteclouds.com/?p=1733


Want to be able to change the SSL Certificates on your vCenter Servers and vSphere Hosts to properly signed CA certificates at the click of a button? Want to be able to automatically apply certificates to Auto Deployed Hosts? Need a solution that covers vSphere 4.0 through to 5.1? Can detect and alert you to […]

]]>


Want to be able to change the SSL Certificates on your vCenter Servers and vSphere Hosts to properly signed CA certificates at the click of a button? Want to be able to automatically apply certificates to Auto Deployed Hosts? Need a solution that covers vSphere 4.0 through to 5.1? Can detect and alert you to expiring or revoked certificates and change them for you? Something that provides complete SSL Certificate lifecycle management for your vSphere environment with all the reporting, alerting and audit logs you’d expect? Then vCert Manager might be the tool for you and I’ve got a demo of the beta version to wet your appetite.

I wrote an article regarding a few months ago titled vCert Manager – Changing VMware SSL Certs Made Easy, which included a demo of a very early prototype that I presented at VMworld USA in August 2012. The prototype showed how in concept vCert Manager could automatically replace SSL Certificates in vSphere environments with integration back to a windows CA. A few months on now and VSS Labs, who is the company developing the solution, has released a demo of the beta version. The beta is now being tested by select customers who have signed up to the early adopter program. Check out this demo to see how the product has progressed and get an idea of it’s capabilities.

 

I think you’ll agree that the vCert Manager Beta has come a long way since the very early prototype I presented at VMworld and wrote about previously. The work is not over though. There is still a little way to go to get everything feature complete and enterprise ready and before it is ready to be generally available. The work is progressing well. The demo below is only 16 minutes long, so won’t take up much of your time.

Final Word

I know how much pain changing SSL certificates is and the goal of vCert Manager is to take this pain away and provide a solution that makes it affordable for all vSphere environments to become more secure. I’d greatly appreciate your feedback on the vCert Manager beta demo. Your suggestions and feedback will help VSS Labs make vCert Manager a great product.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2013/01/31/automating-vsphere-ssl-cert-management-vcert-manager-beta-demo/feed/ 7 1733
Installing Corporate CA Certificates on iPhone or iPad for Use with VMware View http://longwhiteclouds.com/2013/01/03/installing-corporate-ca-certificates-on-iphone-or-ipad-for-use-with-vmware-view/ http://longwhiteclouds.com/2013/01/03/installing-corporate-ca-certificates-on-iphone-or-ipad-for-use-with-vmware-view/#comments Wed, 02 Jan 2013 12:18:13 +0000 http://longwhiteclouds.com/?p=1604


I was upgrading my VMware View environment recently from 5.0 to 5.1 and wrote about some initial problems in my article Trouble Recomposing View 5.x Desktops After Upgrade to vSphere 5.0 U2. After I had resolved those initial problems I needed to load my internal Root CA certificate onto all my company’s iPhone’s and iPad’s. This […]

]]>


I was upgrading my VMware View environment recently from 5.0 to 5.1 and wrote about some initial problems in my article Trouble Recomposing View 5.x Desktops After Upgrade to vSphere 5.0 U2. After I had resolved those initial problems I needed to load my internal Root CA certificate onto all my company’s iPhone’s and iPad’s. This is because one of the big changes or improvements in View 5.1 is with security and you now need trusted certificates in order to connect to any of the desktops. Fortunately there is no need to purchase expensive public certificates if you have an internal corporate PKI / CA’s already configured, unless you want to. This article will show you how you can easily get your iPhones or iPad’s to trust your corporate CA certificates for use with VMware View.

I’ve included images here to explain the process as I think it’s easier to follow. I used one of my iPhones to keep the images reasonably small. To be honest you’re much more likely to be doing this on an iPad. But iPhones are perfectly usable in my opinion provided  you have the iPhone to VGA adapters and a Bluetooth Keyboard.

Trying to Connect Without Trusting the Certificate

If you try to connect to a VMware View 5.1 environment using the iOS View Client without first trusting the CA certificate you will receive a message as per the image below:

View Connection Denied

If you click on View Certificate you will see some details about the untrusted certificate:

View Client Untrusted Cert View

There is no way to set your device to trust your CA certificate from this screen. In order for you to get your iPhone or iPad to trust the certificate you will need to follow the process below.

Getting Your iPhone or iPad to Trust Your CA Certificate

1. Obtain a copy of the CA Certs (Root CA and Intermediate CA if used) and email them to your device, such as in the following image:

View Cert Emailed

You’ll notice the attachment in the image above shows a certificate type icon.

2. You now need to tap on the attachment. You will be presented with the following screen:

View Cert Install p1

At this point before continuing  to the next step you should click on More Details. You should verify that it is indeed the certificate that you were expecting, it’s form your corporate CA, and that it is valid and should be trusted. Once you are satisfied this is indeed a legitimate certificate that you should trust you continue.

3. Tap Install.  You will see the following warning image displayed on the screen:

View Cert Install p2

Because your corporate CA is not a trusted public CA it is not automatically in the trusted list for your devices. This is the reason this warning is being displayed. Provided you are happy with the checks you’ve done in the previous step, after reading this warning you can continue to the next step.

4. Tap Install. You will see the following image displayed on screen:

View Cert Install p3

At this point you need to enter your passcode so that the certificate can be loaded into your devices trust store and be trusted. Once you have entered your passcode successfully you will automatically be at the next step.

5. You have successfully loaded your corporate CA certificate into your devices trust store. You will see the following image displayed on the screen:

View Cert Install P4

Now when you connect using the VMware View Client your Connection Servers certificates, which were signed by your corporate CA, will be trusted and your connections will be successful. If you have  more than one CA that needs to be trusted you need to complete these steps for each of the certificates. You can now Tap Done and go back to the VMware View Client and test the connections.

6. Now when connecting to your VMware View Connection Servers or Security Servers an image similar to the following will be displayed on screen:

View Connection Allowed - Cert VerifiedYou can see by the tick on the padlock and the text https being displayed in green that the certificate and connection are trusted. If the connections weren’t trusted you wouldn’t have been able to connect. Enter your username and password and then tap done or go.

7. You will receive the list of entitled desktops similar to the image below and you can no proceed to use your desktops as per normal. This process is complete!

View Connection Allowed - Displaying Desktops

Removing a Certificate From Your iPhone or iPad Trust Store 

If for some reason you find out that a certificate has become invalid or has been revoked you will need to remove it from the trust store on your iDevice. To do this is very simple.

1. Tap Settings.

2. Tap General. You will see on the screen something similar to the following:

Remove Cert Settings Screen p1

You can see the profile listed and the name of the CA in this example.

3. Tap Profile. You will see on the screen something similar to the following:

Remove Cert Settings Screen p2

4. Tap  Remove. You will see a warning displayed similar to the following:

Remove Cert Settings Screen p3

5. Tap Remove. You will see the passcode dialog box displayed as per the image below.

View Cert Install p3

6. Enter your passcode. You will be returned to the settings screen and you’ll notice as per the image below that the profile has now gone.

Remove Cert Settings Screen p4

You have now completely removed the certificate from your devices trust store. When the new certificates are issued you can go back and follow the process to install them again.

Final Word

As you would expect Apple has made it fairly painless to get this all working. However when it comes to security and trusting certificates great care needs to be taken. You must verify that the certificates that are being sent to you for use are genuine and can be trusted. If for some reason the certificates expire, are revoked or for some other reason invalidated then you need to follow the process to remove the certificates from the trust store and then install the new ones. I hope this has been helpful and that you get hours of productivity out of your VMware View 5.1 vDesktops from your favourite iDevices.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2013 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2013/01/03/installing-corporate-ca-certificates-on-iphone-or-ipad-for-use-with-vmware-view/feed/ 10 1604
VMware SRM SSL Certificate Problems After Applying Microsoft Security Patch http://longwhiteclouds.com/2012/11/18/vmware-srm-ssl-certificate-problems-after-applying-microsoft-security-patch/ http://longwhiteclouds.com/2012/11/18/vmware-srm-ssl-certificate-problems-after-applying-microsoft-security-patch/#comments Sun, 18 Nov 2012 05:02:23 +0000 http://longwhiteclouds.com/?p=1549


Microsoft recently issued a security advisory and a patch that blocks any certificates with a key length less than 1024 bits. This has impacted a wide variety of systems including VMware Site Recovery Manager 5.0 and below. This article will provide you a way to quickly regenerate the self-signed SRM certificates. Background The Microsoft Advisory […]

]]>


Microsoft recently issued a security advisory and a patch that blocks any certificates with a key length less than 1024 bits. This has impacted a wide variety of systems including VMware Site Recovery Manager 5.0 and below. This article will provide you a way to quickly regenerate the self-signed SRM certificates.

Background

The Microsoft Advisory and related information can be found in Microsoft Support KB 2661254. I would encourage you to read this article as the impact is wider than just VMware SRM and other VMware products.

Although I’m going to show you a way of generating self-signed certificates here for the use with SRM I would recommend using trusted CA certificates if possible to reduce the risk of man in the middle attacks. However the effort required to set up a CA and issue the certificates is far more than what I’m about to explain. This is the quick way to work around this problem until you come up with a better solution, which may include getting CA issued certificates.

Note: This process is not officially supported by VMware and says as much in the output of the command. So use this at your own risk and I would encourage you to test it in an isolated environment prior to applying this to any production system. Always take a backup of existing certificates before making any modifications. These instructions should work for any versions of SRM 5.1 and prior.

Generate New Self Signed SSL Certificates for SRM

There is a file called CertGenUtil.exe that is shipped with SRM and used by the installer to create the default self-signed SSL certificates. The version included in 5.0 and prior only generates 512 bit keys, which are not sufficiently strong after you’ve applied the MS patch. The MS patch requires 1024 bit keys or higher. Fortunately the version of CertGenUtil.exe shipped with SRM 5.1 generates 2048 bit keys and can be used to re-generate the certificates for use with versions of SRM include 5.0 and prior. You may need to use this if you are upgrading from SRM 5.0 to 5.1 also as the certificates are not generally replaced during an upgrade process. I have not yet tested the upgrade process of SRM 5.0 to 5.1 to see if it’s any different to previous versions with regards to the update of the certificates.

To use CertGenUtil.exe you will need to create a short config XML file so that it will generate the SSL Certs Correctly. The following is an example:

<config>

<DR_CERT_SERVER>SRMSERVERIP</DR_CERT_SERVER>

<DR_CERT_ORG>YOURCO</DR_CERT_ORG>

<DR_CERT_ORG_UNIT>YOURORG</DR_CERT_ORG_UNIT>

</config>

Replace SRMSERVERIP with the IP Address of your SRM Server, YOURCO with your company and YOURORG with your OU. Save the config file in an easily accessible location on the server where you’ll install SRM 5.1, such as c:\ or c:\temp, in the example below I’ve saved the file as srm-certcfg.xml in c:\temp. Note: you only need to install SRM 5.1 to get the CertGenUtil.exe, you are not required to upgrade your environment to SRM 5.1. So it would pay to do this in a test environment with a SQL Express instance and a test VC.

By default the CertGentUtil.exe file is located in c:\Program Files\VMware\VMware vCenter Site Recovery Manager\bin

On a server installed with SRM 5.1 or that contains the SRM 5.1 CertGenUtil.exe file execute the following command:

c:\Program Files\VMware\VMware vCenter Site Recovery Manager\bin\CertGenUtil.exe -cfg c:\temp\srm-certcfg.xml

You will notice this line appears immediately:

VMware internal use only. This program is intended for use only by the SRM installer.

Follow the on screen messages that are displayed.

Installing The New Self Signed SSL Certificates

After the certs are generated you need to install them in the trusted certs store of both SRM Server and also both of the vCenter Servers (Protected and Recovery Sites). This is as simple as logging into the systems as administrator coping the new Cert file across and double clicking it to install it in the cert store (Follow the wizard). You will need to go through SRM and do a ‘Modify’ install and use your new certs in .p12 format. You may need to restart the SRM Services on both SRM Servers before the new certificates will be loaded into memory.

Final Word

I hope this helps if you quickly need to regenerate the default self-signed SRM Certificates for 4.x and 5.x to be compliant with the new MS patch. I would recommend that you use CA signed certificates to improve security and reduce the risk of man in the middle attacks, so this should be viewed as a temporary measure. This should allow you to continue to run your existing systems till you are able to upgrade to SRM 5.1.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2012/11/18/vmware-srm-ssl-certificate-problems-after-applying-microsoft-security-patch/feed/ 4 1549
Updating CA SSL Certificates in vSphere 5.1 vCenter Virtual Appliance http://longwhiteclouds.com/2012/10/29/updating-ca-ssl-certificates-in-vsphere-5-1-vcenter-virtual-appliance/ http://longwhiteclouds.com/2012/10/29/updating-ca-ssl-certificates-in-vsphere-5-1-vcenter-virtual-appliance/#comments Mon, 29 Oct 2012 10:34:33 +0000 http://longwhiteclouds.com/?p=1521


Recently I wrote about Updating CA SSL Certificates in vSphere 5.1 which applied to the Windows installable version of the vCenter 5.1 and it’s supporting components including SSO. VMware has now also released the instructions to update the CA SSL certificates in the vSphere 5.1 vCenter Virtual Appliance. While there are a total of 136 steps in the […]

]]>


Recently I wrote about Updating CA SSL Certificates in vSphere 5.1 which applied to the Windows installable version of the vCenter 5.1 and it’s supporting components including SSO. VMware has now also released the instructions to update the CA SSL certificates in the vSphere 5.1 vCenter Virtual Appliance.

While there are a total of 136 steps in the process to update the CA SSL Certificates in the Windows vCenter 5.1 there are only 81 steps to update it in the vSphere 5.1 vCenter Virtual Appliance. But note that these steps do not include update manager. I will include the link below to the KB regarding update manager also.

Here are the KB articles required to update the vSphere 5.1 vCenter Virtual Appliance and Update Manager.

Configuring certificates signed by a Certificate Authority (CA) for vCenter Server Appliance 5.1 – http://kb.vmware.com/kb/2036744

Configuring CA signed SSL certificates for vSphere Update Manager in vCenter 5.1 – http://kb.vmware.com/kb/2037581

It was another great team effort across the globe within VMware to put these instructions together and test them. Hopefully you find this information useful.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2012/10/29/updating-ca-ssl-certificates-in-vsphere-5-1-vcenter-virtual-appliance/feed/ 2 1521
Updating CA SSL Certificates in vSphere 5.1 http://longwhiteclouds.com/2012/10/27/updating-ca-ssl-certificates-in-vsphere-5-1/ http://longwhiteclouds.com/2012/10/27/updating-ca-ssl-certificates-in-vsphere-5-1/#comments Fri, 26 Oct 2012 13:16:23 +0000 http://longwhiteclouds.com/?p=1509


Over the past few weeks I have been working behind the scenes with a team of people at VMware spread around the globe on the process to successfully change out the self-signed certificates in vSphere 5.1. With the introduction of Single Sign-On in vSphere 5.1 the process is somewhat more complicated than vSphere 5 (ok […]

]]>


Over the past few weeks I have been working behind the scenes with a team of people at VMware spread around the globe on the process to successfully change out the self-signed certificates in vSphere 5.1. With the introduction of Single Sign-On in vSphere 5.1 the process is somewhat more complicated than vSphere 5 (ok quite a lot more complicated). But now I’m able to bring you some of the solutions you’ve all been waiting for.

This work covers vCenter, and all the related core components such as SSO, Inventory Service, Update Manager etc. The great news is that this work has resulted in KB’s that I and a number of others have tested and verified to work with vSphere 5.1 GA for the Windows installable version of vCenter. There are also updates to some previously released KB’s for vSphere 5.0. These processes will also work with the recently released patches to vCenter. The KB articles for the vCenter Virtual Appliance edition will also be published shortly and I will update this article when they are available.

Below are the links to all of the articles and a note with regard to Update Manager. I want to say a massive thank you to all of the people at VMware that made this happen. It was a big team effort. I’m glad I could make a contribution to the effort.  I will be making sure the process is automated for you as part of the vCert Manager project that I’m working on. My goal would be to automate both the Windows Installable and Virtual Appliance editions for vSphere 5.1.

Note you should start with KB 2034833 – Implementing CA signed SSL certificates with vSphere 5.1.

Configuring CA signed certificates for VMware vCenter Server 5.0.x – http://kb.vmware.com/kb/2015421
Configuring CA signed SSL certificates for vSphere Update Manager in vCenter 5.1 – http://kb.vmware.com/kb/2037581
Creating certificate requests and certificates for the vCenter 5.1 components – http://kb.vmware.com/kb/2037432
Configuring CA signed SSL certificates for vCenter SSO in vCenter 5.1 – http://kb.vmware.com/kb/2035011
Configuring CA signed SSL certificates for the Web Client and Log Browser in vCenter 5.1 – http://kb.vmware.com/kb/2035010
Configuring CA signed SSL certificates for the Inventory service in vCenter 5.1 – http://kb.vmware.com/kb/2035009
Configuring OpenSSL for installation and configuration of CA signed certificates in the vSphere environment – http://kb.vmware.com/kb/2015387
Configuring CA signed certificates for ESXi 5.x hosts – http://kb.vmware.com/kb/2015499
Configuring CA signed certificates for vCenter 5.1 – http://kb.vmware.com/kb/2035005
Implementing CA signed SSL certificates with vSphere 5.0 – http://kb.vmware.com/kb/2015383
Implementing CA signed SSL certificates with vSphere 5.1 – http://kb.vmware.com/kb/2034833

VMware has also put out a blog article on these KB’s titled Implementing CA Signed SSL Certificates with vSphere 5.1.

Note: I have found a problem with Update Manager when vCenter system is an all in one configuration with everything on the same VM and using a local MS SQL Server database. Update Manager will not be able to log into or register with vCenter when the SSL certificates have been changed. This prevents you from updating the SSL certs for Update Manager and Update Manager may no longer work. This does not appear to occur when the MS SQL Server database is remote. I have not tested this with a local Oracle or other supported local database. I am continuing to work with VMware on this issue and will update this article when it is resolved. In the meantime I would recommend placing the databases for vCenter and it’s other core components on a separate VM, even in small environments.

Final Word

Although changing out the self-signed SSL Certificates is not simple, and is very time consuming to do manually, the above articles make it possible and give you a tested and verified process. I will be automating the processes to take this pain away as part of the vCert Manager project. In the meantime I would recommend you start with KB 2034833 – Implementing CA signed SSL certificates with vSphere 5.1 and work your way through the rest. I hope you get a lot of value out of these articles and the effort that the team has put in. As always your feedback is appreciated.

Derek Seaman has put together a great series of articles on VMware vCenter 5.1 Installation that includes coverage of SSL certificates. I would highly recommend you check it out. Derek has made a great contribution to the process for SSL Certificate Replacement in vSphere 5.1.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2012/10/27/updating-ca-ssl-certificates-in-vsphere-5-1/feed/ 16 1509
VMworld US 2012 and vSphere 5.1 Launch Roundup – My First VMworld http://longwhiteclouds.com/2012/09/23/vmworld-us-2012-roundup/ http://longwhiteclouds.com/2012/09/23/vmworld-us-2012-roundup/#comments Sun, 23 Sep 2012 10:02:34 +0000 http://longwhiteclouds.com/?p=1230


The twitter wires and blogosphere were ablaze with news out of VMworld US 2012 (August 27 – 30th). This was my first ever VMworld (with hopefully many more to come), and I greatly enjoyed it and I also enjoyed meeting many of you. My direct flight home to Auckland from San Francisco on Air New […]

]]>


The twitter wires and blogosphere were ablaze with news out of VMworld US 2012 (August 27 – 30th). This was my first ever VMworld (with hopefully many more to come), and I greatly enjoyed it and I also enjoyed meeting many of you. My direct flight home to Auckland from San Francisco on Air New Zealand was the best flight I’ve ever had, and I got a full 8 hours sleep so I didn’t have any jetlag (Thanks Air New Zealand). But this article is all about my take on the event, what I learned, and vSphere 5.1. I’ve decided to do something slightly different to others, to take it all in, and then write this roundup post VMworld. I’m also going to target this towards the relevance to production and business critical applications environments. I’ll also give you some insight into the sessions I presented, the results and my lessons learned.

vRAM and Cloud Suites: Ding Dong! The Witch is dead. Which old Witch? The vRAM Witch! (The movie this is from is well before my time – Can you guess which movie?) Yes the vRAM Witch is now definitively dead. VMware Announced in the first Keynote on Monday 27th August that vRAM licensing is no more and they will instead be introducing vCloud Suites containing a bundle of products based on per CPU Socket, unlimited cores, unlimited RAM, and unlimited VM entitlement per licensed socket. Although the suite is a collection of products right now over time will become ever more integrated, and the licenses can’t be broken apart into their individual components. This is all very good news for VMware customers. The vRAM announcement was made in the context of vSphere 5.1, but it also applies to vSphere 5. So even if you’re running a vSphere 5 environment vRAM is no longer relevant. Personally I didn’t have a problem with the concept of vRAM as everything is moving towards a consumption based model, but it did cause a lot of extra things to consider during design, especially when every customer I ever engaged with had no impact as a result of vRAM. The free VMware vSphere Hypervisor will still be limited to running on hosts with 32GB physical RAM, but there are no longer any vRAM limitations (think configured memory / overcommitment is unlimited). Everyone with vSphere Enterprise Plus will get entitlement to vCloud Suite Standard, and VMware will be running promotions to get customers to upgrade to the other editions, so watch out for those. Information and comparisons between the vCloud Suites. This is great news for all environments, especially those with Monster VM’s. So now you don’t have to worry about VMware vRAM licensing for your business critical applications you can go back to only worrying about your ISV licensing and the best solution to meet all your other requirements.

vSphere 5.1 and the Mega Monster VM: 64 vCPU, 1TB RAM, 1M IOPs per VM, less network jitter, lower latency, Zero-downtime upgrade for VMware Tools (from 5.1 onwards), Dump Collector works with vDS. These are just some of the highlights of vSphere 5.1. VMware has taken the Monster VM and turned it into a more Mega Monster VM. Best of all the efficiency is still what you come to expect form VMware. So if you can configure 64 vCPU’s you know you can get within a few percentage points of native. IMHO it’s not good saying your architecture supports a huge number of vCPU’s if you can’t utilize them efficiently. VMware does a lot of work to ensure they optimize their architecture to get best efficiency as well as scalability. 1 Million IOPS per VM is great if you have a single VM that you can run off an entire fully FLASH array. But realistically this is just to eliminate any possible thoughts that the hypervisor is the bottleneck when it comes to storage. The test was conducted with 4k IO size and produced very low latency. The IO Size and Latency being important factors as I outlined in Storage Sizing Considerations when Virtualizing Business Critical Applications.  See What’s New in VMware vSphere 5.1 – Platform and What’s New in VMware vSphere 5.1 – Performance.

VMware vSphere Distributed Switch: Config Backup/Restore, Rollback and Recovery, Network Healthcheck, BPDU Filter. There is now no reason to run a mixed vSS / vDS environment. With the config backup / restore and automatic rollback and recovery you can be confident that the vSphere Distributed Switch (note name change) will be reliable and available, and easy to recover when things go wrong. The Rollback and Recovery will revert any change that has the consequence of disconnecting the hosts from vCenter or vice versa. Network Healthcheck will periodically check the network for configuration errors such as incorrect VLAN trunking, incorrect MTU, uplink erros etc and alert you to these issues before they become a major problem. This should greatly reduce the effort required in quality assurance when provisioning new hosts and operating hosts as the environment changes. The new vDS also supports Netflow v10 (IPFIX), LACP (IP Hash Only), and also RSPAN/ERSPAN. BPDU Filter is important as it stops the accidental or malicious configuration of a bridged VM from causing a physical host port down event and cascading failure across the cluster. BPDU filter will filter out any BPDU packets. As mentioned above the Network Dump Collector, which collects Purple Screen of Death (PSOD) Core dumps from ESXi hosts now works with vDS. In vSphere 5 this only worked with the standard vSwitch. See What’s New in VMware vSphere 5.1 – Networking.

VMware vSphere Storage Enhancements: All Paths Down (APD), Permanent Device Loss (PDL), Storage IO Control Enhancements, Parallel Storage vMotion, Combined vMotion / Storage vMotion without Shared Disks. The APD and PDL behaviour has been again enhanced in vSphere 5.1, which will see far more predictable behaviour under what should be very rare storage failures. Storage IO Control has been enhanced to be more self tuning. Storage vMotion now supports up to 4 parallel disk copies per VM. See What’s New in VMware vSphere 5.1 – Storage. With the combined vMotion / Storage vMotion and no need to have shared storage we can say goodbye to the concept of a swing datastore or jump datastore. Duncan Epping does a great job of covering this in his article “Say Goodbye to the Transfer LUN aka Swing LUN aka Stepping Stone“.

vCloud Networking and Security: HA, SSL VPN, Load Balancer, 10 NIC’s per Edge, VXLAN Gateway, Endpoint included with vSphere 5.1. All of the new features of vCloud Networking and Security are a major leap forward from the previous version of vShield, which this supersedes. The HA functionality for vShield Edge combined with support for 10 NIC’s, which are user configurable between internal / external means that you can realistically replace a large number of enterprise firewalls very cost effectively. This also means you can very cheaply set up realistic testing and validation environments to test multi-tier applications and their firewall rules before you apply the firewall rules to production physical firewalls. With HA if one host with the primary Edge device fails the firewall state will failover to stand by Edge, this is a real active / passive firewall cluster. Load balancing has been greatly improved to include health checks and can now support HTTPS pass through and any custom TCP ports. SSL VPN is a very convenient way of allowing end user access to the vApps and infrastructure protected by the Edge or for management of the infrastructure. The admin user interface has been greatly enhanced and so has it’s capability, including the logging functionality. Many will be pleased that rules now have a rule ID and this flows through into syslogs. The interface is much more intuitive when it comes to App Firewall also and is simplified removing the rule precedence that existed in the previous version. Flow monitoring is improved and you can now get statistics per rule to determine which rules are being used in addition to the top rules that are used. With Endpoint now included with the Hypervisor I predict that most organizations will start moving to VMware’s Endpoint protection and partner integrated solutions. Service Insertion now allows parters to integrate virtual editions and physical editions of their components with vCloud Networking and Security and also vCloud Director. This will allow many organizations to further differenciate their services and offerings.  The automation capabilities that are possible through vCloud Director, vCloud Connector and the REST API’s mean that vCloud Networking and Security is a major step forward with capabilities that really deliver on the software defined datacenter and software defined networking and security. See VMware vCloud Networking and Security Overview.

vCloud Director: SDRS Integration, Storage Profiles / Storage Tiering, Elastic VDC, Linked clones on VMFS across 32 hosts, vApp Snapshots, HA Edge Devices. See What’s New in VMware vCloud Director 5.1. There are so many improvements in vCloud Director 5.1 that I’m only going to cover a few very briefly. Storage DRS and Storage Profile integration is a big one. You will no longer require a separate Provider VDC just to support a different tier of storage. For smaller environments this made the design very tricky as you might in a single 2 or 3 node cluster have to support 2 tiers of storage. This forced you to break with some best practices and use resource pools instead of clusters as the demarcation for the Provider VDC compute resources. This will help greatly improve resource utilisation efficiency in vCloud Director environments. It will be interesting to see the new designs incorporating this and how they are now differentiating their service offerings. With vCloud Director 1.5 you could configure an Elastic VDC across multiple clusters only with the PAYG resource model, but all the vShield Edge devices stayed in the original cluster. With 5.1 you can now do this also with the Allocation Pool resource model and vShield Edge and system resource pools will be split across clusters. With the addition of VXLAN it is now also easier to stretch VDC’s across clusters and this adds improved performance to the isolation networks.

New Certifications: VMware launched a number of new certifications for the Desktop and Cloud tracks. We now see certification paths right up to VCDX-Cloud and VCDX-Desktop. The existing VCP and VCDX have been renamed slightly to VCP-DV and VCDX-DV to designate Datacenter Virtualization. The actual path to VCDX-Cloud and VCDX-Desktop is not quite clear yet and neither is the migration path for existing VCDX qualified individuals. But it is great to see these two new certification paths that will allow everyone to demonstrate their mastery of these technology areas in addition to Datacenter Virtualization. See VMware Certification Roadmap. If you think this looks similar to how Cisco’s certification works you’re right. This is intentional and it just happens the man who designed Cisco’s certification tracks is now in charge of doing that at VMware.

Oracle Virtualization Architecture and Performance Deep Dive: I presented two sessions at VMworld US regarding Oracle Virtualization. The first one APP-BCA1432 – Virtualizing Oracle Across the World — Success Stories from University of Auckland and Indiana University covered the process of how to go about virtualizing Oracle when migrating from traditional Unix platforms and how to engage the DBA’s and keep them happy. My content was based on a large project that I had delivered on behalf of VMware Professional Services. I had Don Sullivan (Oracle Certified Master) from VMware and Dan Young from Indiana University as co-presenters. In my second session APP-BCA1624 Virtualizing Oracle: An Architectural and Performance Deep Dive we really drilled into how to architect Oracle databases for maximum performance and how the hypervisor helped. In this session I had Mark Achtemichuk from VMware (Performance Technical Marketing) and Don Sullivan again. I took the same project as my previous session but this time really drilled down in the technical details of how we delivered 5x performance improvement from the source systems and as such a high ROI. Both would give you a very good understanding of how you really can virtualize Oracle Databases in large organizations successfully and ensure you meet the business requirements and performance requirements.

I received some pretty good ratings (4.39 and 4.3 respectively) for these sessions so a big thank you to all of the people that attended these sessions. You all thought we hit the mark with the content. This is very encouraging and I’ll try and do even better next year if I get a session selected. Based on the feedback a lot of people thought the sessions weren’t long enough. We could have talked for a lot longer and gone a lot deeper. This is the challenge when the sessions are only 60 minutes.

Automating Security and Compliance with DR: I presented this session INF-SEC1282 Automating Security and Compliance with Disaster Recovery Using VCM, vCOps, vShield, VIN and SRM along side Gargi Keeling who is the Product Manager for Security at VMware. This presentation was loosely based on a customer project I had been involved with where we had designed automated security and compliance processes along with DR. In addition to the learning from the actual customer project we enhanced the presentation with a partner solution (Catbird) that allows for automated syncing of vShield polices across multiple datacenters. The presentation covers all of the process and technology steps you need to take and gave an example of a technical architecture that would allow you to implement this, all using out of the box functionality from vShield, vCenter Configuration Manager, vCenter Operations, Virtual Infrastructure Navigator, and vCenter Site Recovery Manager, and supplemented if required with the Catbird solution. This presentation was also the worldwide premier of the SSL Management Solution mentioned below vCert Manager, which was very well received.

I received pretty good rating for this session of 4.15. Not quite as good as my Oracle sessions, so I will try and do better next time. This one was pitched as just a technical session not advanced technical. I also received a lot of feedback that the session wasn’t long enough and it would have been good to have the time to go deeper. What I’ve learned from the presentations I gave is that I probably need to narrow the scope and go a lot deeper. This will allow a lot more to get into a 60 minute presentation. Feel free to comment on this article and let me know your thoughts on this.

SSL Management – vCert Manager: My demo of the vCert Manager prototype was very well received and everyone in the audience of the Automating Security and Compliance with DR session agreed it would greatly simplify the process of managing SSL Certificates in VMware environments. I have published the Demo online and written about it in article vCert Manager – Changing VMware SSL Certs Made Easy.

Top Sessions I Attended:

The below sessions I highly recommend you review. I attended these sessions and thought they were a real highlight. Note I only had very limited time so I wasn’t able to attend many great sessions. I would have liked to have gone to the vCenter Technical Deep Dive and also Jason Nash’s vSphere Distributed Switch Deep Dive also. Jason got the top session of VMworld this year. I think it might be the first year a non-VMware employee has had the top spot.

Virtualizing SQL 2012: APP-BCA1516 Virtualizing SQL 2012 : Doing It Right. Jeff Szastak of VMware and Michael Corey of Ntirety managed to get through 160 slides of a very entertaining and deep technical presentation in just 60 minutes. I think they finished on time to the minute even with questions. I was very flattered that Jeff and Michael borrowed a quote from my Oracle Virtualization Architecture and Performance Deep Dive – “Your database is just an extension of your storage”. It is definitely relevant to SQL just as it is to Oracle or any other database. Optimizing storage performance is critically important and Jeff and Michael covered it well in the context of SQL Server 2012 and the relevant best practices.

SMP FT a.k.a. Multi-vCPU Fault Tolerance: INF-BCO2655 VMware vSphere Fault Tolerance for Multiprocessor Virtual Machines—Technical Preview and Best Practices. Presented by Jim Chow, Shrinand Javadekar, Srinivas Kotamraju, all from VMware. There was no timeframe or commitment given on when or if this might actually make it into the product given given how good it was I really hope it’s sooner rather than later. One of the attendees said this technology would literally save peoples lives as he worked in the 911 system as a systems admin and they could not leverage VMware FT currently due to it’s limitations. I can see many and varied applications for this. I can’t wait to get it into my lab environment when if it gets released.

Stretched Metro Clusters: INF-BCO1159 Architecting and Operating a VMware vSphere Metro Storage Cluster. Duncan Epping and Lee Dilworth did a great job of covering all the key points of architecting and operating a vSphere Metro Cluster environment. This is becoming a very popular solution for many environments these days, but it is not without its challenges.

Storage DRS Datastore Clusters: INF-STO1545 Architecting Storage DRS Datastore Clusters. Frank Denneman and Valentin Hamburger highlighted a number of key considerations when architecting Storage DRS datastore clusters, including some important limitations and considerations around storage IO control and array auto tiering. I wouldn’t operate a Storage DRS Datastore Cluster environment without reviewing this session first.

Oracle RAC Cluster Build Automation: APP-BCA1333 Virtualizing Oracle RAC. Rick Lindberg, Don Sullivan and Bryan Wood of VMware took the audience through the ins and outs of successfully virtualizing Oracle RAC on vSphere. Including the fully automated deployment of a new Oracle RAC Cluster in under 30 minutes (cut down demo recording was 7 minutes). The automation, which is available via a VMware Professional Services engagement allows not only new Oracle RAC Cluster creation but also node addition and node removal from existing clusters that have been created through this process. This will be especially valuable in Test and Development environments. The session also covered what VMware IT is doing in the process of virtualizing all their Oracle RAC systems and the necessary best practices to ensure the process is successful.

Final Word

It was great to see Oracle actually had an official presence at VMworld this year. They had a booth in the Solutions Exchange, which I stopped by for a chat and they gave me a nice T-shirt, and also had taxis and branded cars taking customers from their hotels to VMworld. This is another great show of support for VMware, which is a great place to run Oracle databases and applications. Oracle also confirmed at VMworld that running their applications and databases in a large cluster and using DRS Must Affinity Rules is a perfectly acceptable solution, provided the rules are not violated and the Oracle software is not installed and/or run on an unlicensed host. They also completely clarified the support situation with VMware vSphere. I think all of this is absolutely great news for Oracle and VMware customers. Now if you don’t believe that this actually happend why not just review the video, which is in an article on the License Consulting blog – VMworld TV – Richard Garsthagen Oracle Licensing and Support in VMware Virtualized Environments.

This was my first ever VMworld and it will definitely not be my last. I had a great time presenting to over 650 people and got great feedback. I met so many great people and was able to hang out with some of the VMware virtualization royalty. The only problem I had with VMworld was that it went way too fast. Mind you it was really hard work getting up at 6am every day and not getting to bed until after midnight most days. I would like to once again thank everyone that attended my sessions and gave feedback through the surveys, it was greatly appreciated. I’m looking forward to seeing some of the great people again in a couple of weeks at VMworld Barcelona, which I will be presenting a session titled APP-BCA1751 – Oracle Virtualization: Caging the Licensing Dragon with a great lineup of co-presenters. I hope to see some of you there. I also hope to meet a lot more new people.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2012/09/23/vmworld-us-2012-roundup/feed/ 2 1230
vCert Manager – Changing VMware SSL Certs Made Easy http://longwhiteclouds.com/2012/09/15/vcert-manager-changing-vmware-ssl-certs-made-easy/ http://longwhiteclouds.com/2012/09/15/vcert-manager-changing-vmware-ssl-certs-made-easy/#comments Sat, 15 Sep 2012 11:04:40 +0000 http://longwhiteclouds.com/?p=1240


During my VMworld session presentation INF-SEC1282 Automating Security and Compliance with DR (VMworld account required to access recording) I gave a world premier glimpse of a prototype solution that will allow completely automated management of SSL Certificates in a vSphere environment. The solution is still under development. But if you’d like to peak into the future of an […]

]]>


During my VMworld session presentation INF-SEC1282 Automating Security and Compliance with DR (VMworld account required to access recording) I gave a world premier glimpse of a prototype solution that will allow completely automated management of SSL Certificates in a vSphere environment. The solution is still under development. But if you’d like to peak into the future of an easy and completely automated SSL management world for vSphere then this article is for you.

[Updated 14/09/2013] vCert Manager is now Generally Available! This was announced at VMworld USA 2013 in San Francisco. If you’d like to see how the prototype changed into the full product please check out my article VMworld USA 2013 By The Numbers. You can obtain an evaluation version of vCert Manager by visiting VSS Labs

 

The session was an outstanding success, we received a massive response from the audience and subsequent to the session. As a result of this positive feedback we’ve decided to make the demo video available to the public on YouTube here and displayed below. I’m the lead architect of the solution and I’m working with VSS Labs based in Singapore and Philippines. If after reviewing the demo you’d like to become part of the early adopter / beta program please visit the VSS Labs web site and register your expression of interest by filling in the Early Adopter Form.

Some things you should know about the demo before you watch it:

  1. This is a very early prototype and is a stand alone .net application in this demo. The full version will be web based and we will likely have .net or Java / Virtual Appliance options. We’d appreciate feedback on which varient would be the highest priority.
  2. In the demo we are only showing the replacement of ESXi certs, but the intention is to support ESX/ESXi 4.x and 5.x out of the gate, in addition to vCenter, vSphere Web Client and selected integrated components and management tools, such as VMware View, vCloud Director, SRM, vShield, vCOps. Your feedback on the most critical components to support upon GA would be valuable.
  3. We will be supporting multiple Certificate Authorities, both private and public. We will support stand alone and enterprise / AD integrated Windows CA’s (2003 and 2008 version). Public CA support if API’s are not available may still require some manual steps, but the creation of CSR and the applying of the certs and managing the lifecycle of the cert will be automated.
  4. The minimum key length supported will be 1024 bits, with maximum of 4096bits and default of 2048bits.
  5. In the demo we use a stand alone Windows CA, this is the reason for the message in IE being displayed towards the end of the demo. The CA’s cert was not pre-trusted in the system where the browser is being run. This message would not be displayed had an AD Integrated Enterprise CA been used.

Once you have watched the demo please complete the brief survey below.

Please let us know what your thoughts are on the most critical components we should support when we release vCert Manager 1.0.

Final Word

Managing SSL Certs in a VMware environment is a very complicated, time consuming, error prone, and costly task. My hope is that vCert Manager will revolutionize SSL Management in VMware environments, make it simple, easy, and cost effective to change and maintain SSL certificates throughout their lifecycle, for all customers. Providing a more secure platform to many customers that wouldn’t or couldn’t currently change their SSL certificates. If after reading this article and seeing the demo you still want to do your certificates manually then please feel free to check out my article on Updating SSL Certificates in vSphere 5. I look forward to receiving some good feedback and comments.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.comby Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2012/09/15/vcert-manager-changing-vmware-ssl-certs-made-easy/feed/ 47 1240
Updating SSL Certificate in vShield Manager Made Easy http://longwhiteclouds.com/2012/03/31/updating-ssl-certificate-in-vshield-manager-made-easy/ http://longwhiteclouds.com/2012/03/31/updating-ssl-certificate-in-vshield-manager-made-easy/#comments Fri, 30 Mar 2012 12:17:08 +0000 http://longwhiteclouds.com/?p=902


I was contacted recently by Maish Saidel-Keesing (@maishsk), who is a vExpert, fellow tweeter and top 50 virtualization blogger at technodrone.blogspot.com asking if I had updated the SSL Certs in vShield Manager at all. At this point I have updated quite a lot of certs for customers and in my lab but vShield wasn’t one […]

]]>


I was contacted recently by Maish Saidel-Keesing (@maishsk), who is a vExpert, fellow tweeter and top 50 virtualization blogger at technodrone.blogspot.com asking if I had updated the SSL Certs in vShield Manager at all. At this point I have updated quite a lot of certs for customers and in my lab but vShield wasn’t one of them and it was still firmly on my To Do list. He challenged me to see if I could get it working, so I set about updating my vShield Manager SSL Certs and helped Maish do the same in his environment. It wasn’t quite as hard as some of the other tools when it comes to changing SSL Certs, but it wasn’t entirely straight forward either. If you want to know how to do it the easy way, read on.

The first place you should go when trying to update SSL Certificates in any of the VMware products is the product documentation. At least for an overview of how the process might work. As you are probably aware by now (If you’ve read my previous posts on the SSL Cert Topic – Updating CA SSL Certs in vSphere 5)  there have been a number of examples where the documentation isn’t quite complete or easy to follow. This is also the case with the vShield 5.0 Admin Guide. This article will outline the steps necessary to update the SSL Certs on vShield Manager 5.0 and give you an insight into some of the differences with 5.0.1 that we discovered along the way.

If you want a way to fully manage the certificate lifecycle and replace certs automatically then you’ll want to check out vCert Manager – Changing VMware SSL Certs Made Easy. This will completely automate the SSL certificate process in vSphere environments. 

Prerequisites and Assumptions

This article assumes you the following:

  • You already have an Organisational CA and PKI Infrastructure.
  • vShield Manager is already deployed in the environment with configured with a valid IP address on the management network.
  • You have validated connectivity to your vShield Manager prior to executing this process.
  • Your vShield Manager must have a fully qualified domain name in your DNS.
  • If you are using a Windows 2003 CA you have applied Microsoft KB 931351 to allow the SAN attribute to be specified as part of the certificate request. This will require a restart of the CA services.
  • Your CA certificate template supports the Subject Alternative Name (SAN) attribute in certificate requests. Your chosen CA Certificate Template should be verified before you start this process.
  • You have a copy of your Root CA and Intermediate CA (if applicable) Certificates available for use during this process.
  • You are using Internet Explorer as your browser. Note: Other browsers will work for some parts of this process, however they may not work with the CA certsrv web site and root certificates may need to be pre-trusted in the non-IE browsers.

You will be required to log in as admin to perform all the tasks outlined and will require access to the CA to request and download the certificate.

Updating SSL Certificate in vShield Manager 5.0 High Level Steps

Here I will give you an overview of the high level process steps and then dig into the detail including screenshots in the next section. I hope this makes your process of updating the vShield Manager SSL Certs as painless as possible. This process was tested using vShield 5.0 and 5.0.1 and a Windows 2003 CA, but will also work with Windows 2008 and above.

  1. Generate the Certificate Signing Request (CSR) from the vShield Manager SSL Certificates GUI with the correct details for your organization and CA.
  2. Download the generated CSR from vShield Manager and Submit it to your CA.
  3. Download the CA signed SSL Certificate generated in Step 2.
  4. Download or export the Root CA Certificate and Intermediate CA Certificate if applicable.
  5. Import the Root CA Certificate to vShield Manager.
  6. Import the Intermedia CA Certificate to vShield Manager (if applicable).
  7. Import the CA signed x.509 SSL Certificate for vShield Manager.
  8. When the new CA signed SSL Certificate in Step 7 is applied the vShield Manager will reboot, when this is complete log back into vShield Manager.

So only 8 steps, seems easy right? Well it is fairly easy, but there are some catches, which I’ll explain in detail below.

Updating SSL Certificate in vShield Manager 5.0 Detailed Steps

Now we will dive into the detailed steps required to update the SSL Certificates for vShield Manager. As I take you through this I will point out the gotcha’s and inconsistencies with the existing product documentation you need to be aware of as we come to the relevant steps. Screenshots are included to make the process easier to follow. Bare in mind as you are going through this process that vShield Manager is registered with vCenter using it’s IP address and accessed from within vCenter Server using your browser. This is an important aspect when it comes to certificates and validity checks.

  1. Log into vShield Manager as admin.
  2. Click Settings and Reports in the left hand navigation window.
  3. Click SSL Certificate.
  4. You will find yourself presented with a form allowing you to enter the information required to generate a Certificate Signing Request (CSR). I suggest using RSA 2048bit key. At this point you need to use the fully qualified domain name (FQDN) of the vShield Manager as the Common Name. Failure to use the FQDN will result in an error in vShield Manager 5.0 and you will not be able to generate the CSR. This is the first inconsistency with the product documentation as it advises you to use the IP address of the vShield Manager, which doesn’t work. Using the IP address as the Common Name is possible in vShield Manager 5.0.1.  Fill in the CSR information similar to the following image with your relevant organization details.
    Generate vShield Manager CSR
  5. Click the Generate Button.
  6. When the CSR is generated you should see a message displayed in a yellow bar at the top of the screen saying “Certificate Signing Request is generated successfully”, Click the Download generated certificate link on the right hand side of the screen. Save the file somewhere easily accessible.
  7. Submit the CSR to your CA using either the certreq command or the certsrv web site on your CA. The step-by-step instructions for using the certsrv web site are as follows:
    • Browse to http:// or https:// <yourca>/certsrv from a supported Guest OS and a supported browser (refer to Microsoft for this information for your specific CA).
    • Click Request a certificate Link.
    • Click advanced certificate request Link.
    • Click Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file. Link.
    • Copy and paste the text from your CSR into the base-64-encoded certificate request box, making sure to remove any erroneous carriage returns, select the correct certificate template, and enter the SAN information in the Additional Attributes Field (similar format to the diagram below).
    • Click Submit button.
    • Click Base 64 encoded radio button and click Download certificate, save the certificate in an easily accessible location.
  8. Be sure that you specify the Subject Alternative Name (SAN) of your vShield Manager using it’s IP address as an additional attribute during your request. If you fail to specify the IP address in the SAN you will be prompted with a warning dialog each time you access vShield Manager via vCenter Server. This is because vShield is registered with vCenter Server and accessed using it’s IP address and the IP address won’t match the Common Name specified in the certificate. To specify the SAN use the additional attribute SAN:dns=xxx.xxx.xxx.xxx, where the x’s are replaced with your vShield Manager IP address, as shown in the example image.
    Generate vShield Manager Certificate using Windows 2003 CA
  9. Open your newly generated certificate and verify the attributes are as you expect and the Subject Alternative Name is correctly showing the IP address of your vShield Manager.
  10. In vShield Manager on the SSL Certificate Tab ensure Import Signed Certificate is expanded and visible. At this point the Product Documentation advises you to import your CA signed certificate, however this will not work. If you attempt this you will see a message displayed saying that importing the certificate failed. This is because you have not yet imported the Root CA certificate or Intermediate CA certificate (if applicable).
  11. Select Certificate Type Root CA. You will see something similar to the following displayed.
    Import Root CA Certificate to vShield Manager
  12. Browse and find your Root CA certificate and use that as the Certificate File, then click Apply button. A yellow bar containing the message “Successfully imported certificate.” should be displayed at the top of the screen.
  13. If you used an Intermediate CA to generate your certificate then repeat steps 9 and 10 for the Intermediate CA certificate as the Certificate File being sure to select Intermediate CA for the Certificate Type as per the image below.
    Import Intermediate CA Certificate to vShield Manager
  14. Repeat steps 9 and 10 and using the CA-signed X.509 Cert as the Certificate Type and using your CA signed vShield Manager certificate for the Certificate File, similar to the image below.
    Import the vShield Manager CA Signed X.509 Certificate
  15. When the certificate is imported successfully you will see an Apply Signed Certificate box at the top of the screen. Click Apply Certificate. If you see an error displayed in the yellow box stating “Error: Importing certificate failed. Please retry the operation” either the root or intermediate CA certificates are missing or not imported correctly, or there is a problem with your CA certificate. You may have to start the process again. You may with to refer to VMware KB 1035387 – Importing SSL certificates in vShield Manager.
  16. vShield Manger will be restarted to apply the certificate, once it has restarted, log in again as admin by accessing vShield Manager using it’s IP address. You should not be prompted or warned that you are accessing an untrusted site and the vShield Manager login screen should be immediately visible. To verify the certificate click the padlock icon in the address bar.
  17. Congratulations you have now completed the update of your vShield Manager SSL Certificate Successfully!

Please Note: I have received reports that the SSL Certificate is lost when an upgrade from vShield Manager 5.0 to 5.0.1 is performed. I have not yet been able to verify this with VMware or tested it myself. I would suggest that a backup of vShield Manager is taken prior to any upgrade process. I will investigate these reports and update this post. I would like to hear from you if you have experienced this yourself, or if you have any feedback on this process.

Big thanks to Maish for being the inspiration for this article and for help with some of the detail included in this article.

This post first appeared on the Long White Virtual Clouds blog at longwhiteclouds.com, by Michael Webster +. Copyright © 2012 – IT Solutions 2000 Ltd and Michael Webster +. All rights reserved. Not to be reproduced for commercial purposes without written permission.


]]>
http://longwhiteclouds.com/2012/03/31/updating-ssl-certificate-in-vshield-manager-made-easy/feed/ 13 902