VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION User's Guide

Browse online or download User's Guide for Software VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION. VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION User`s guide User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 258
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1

VMware vCenter Configuration Manager Installationand Getting Started GuidevCenter Configuration Manager 5.4This document supports the version of each

Page 2 - Copyright

vCenter Configuration Manager Installation and Getting Started Guide10 VMware, Inc.

Page 3 - Contents

Use the following steps to install the Agent.1. Verify that the machine on which you intend to install the agent has enough free disk space. For morei

Page 4 - Getting Started with VCM 69

inflating: CSIInstall/scripts/AltSource_ftp.shinflating: CSIInstall/scripts/AltSource_rcp.shinflating: CSIInstall/scripts/AltSource_sftp.shinflating:

Page 5 - VMware, Inc. 5

Installation Options with DefaultValuesDescriptionCSI_CREATE_USER=YRecommend keeping default value.The user is being created. This value indicates whe

Page 6 - 6 VMware, Inc

Installation Options with DefaultValuesDescriptionCSI_CREATE_LOCAL_SERVICE=YRecommend keeping default value.Setting CSI_CREATE_LOCAL_SERVICE to Y allo

Page 7 - Index 253

values specified in csi.config without prompting for input. To run the installation in silentmode, enter:# ./CSIInstall/InstallCMAgent -sYou might use

Page 8 - 8 VMware, Inc

drwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 Agentdrwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 CFC-rw-rw---- 1 root cfgsoft 49993 Jul 2 17:34 CSIRegistry-

Page 9 - Updated Information

1. (Optional) Copy csi.config, the file that contains all of the custom configuration settings, to a safelocation. (This file can be found in <path

Page 10 - 10 VMware, Inc

instead of the default collection options, and then select the UNIX Patch Assessment filter set. For moreinformation, see the "UNIX Patch Assessm

Page 11 - About This Book

Note that several other UNIX Dashboards are also available. Take time to familiarize yourself with theremainder of the UNIX Dashboards. UNIX Collectio

Page 12 - 12 VMware, Inc

When you select the node, you see a Summary Report as displayed above of the data type that youselected. Click View data grid to go directly to the da

Page 13 - Preparing for Installation

About This BookAbout This BookThe VMware vCenter Configuration Manager Installation and Getting Started Guide describes the stepsnecessary for a succe

Page 14 - Use Installation Manager

Like Dashboards, Reports are run real time against the current data available in the CMDB for themachines in the active machine group, and therefore t

Page 15 - Understand Tools Installation

Adding Mac OS X MachinesBefore you can collect data from your Mac OS X machines, they must be displayed in the Available UNIXMachines list located in

Page 16 - VCM Remote Virtual Directory

4. Enter the Machine and the Domain, and then select DNS for Type. For Machine Type, select theappropriate operating system. Modify the port number if

Page 17 - Server Authentication

5. Click Next. The Product License Details page appears.6. The licensed machine count has increased by the number of machines that you have selected t

Page 18 - 18 VMware, Inc

4. Use chmod u+x <filename> to change the permissions on the agent binary file.5. In the directory where you copied the file, execute the agent

Page 19 - Windows Machines

Installation Options with DefaultValuesDescription• +H means only for HP-UX• +L means only for Linux• +D means only for Darwin (Mac OS X)• + means for

Page 20 - 20 VMware, Inc

Installation Options with DefaultValuesDescriptionCSI_REFRESH_INETD=YKeep default value only if you arerunning your agent as inetd. If youare running

Page 21 - Using Installation Manager

mode, enter:# ./CSIInstall/InstallCMAgent -sYou might use this method if you have manually edited the csi.config file, if you havemodified the csi.con

Page 22 - 22 VMware, Inc

drwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 Agentdrwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 CFC-rw-rw---- 1 root cfgsoft 49993 Jul 2 17:34 CSIRegistry-

Page 23 - Best Practices

NOTE Consider these points when uninstalling an Agent:• The uninstall reverses all changes made by installation, however the installation log files ar

Page 24 - 24 VMware, Inc

Technical Support and Education ResourcesThe following technical support resources are available to you. To access the current version of this bookand

Page 25 - Configure DHCP

The data classes and filters for Mac OS X include the following:nMachines > GeneralnFile System > File StructurenSystem Logs > syslog eventsn

Page 26

4. The Data Types dialog box appears. Select the Select All check box, then confirm that the Use defaultfilters option button is also selected. Click

Page 27 - Configure TFTP

When you select the node, you see a Summary Report as displayed above of the data type that youselected. Click View data grid to go directly to the da

Page 28 - Create Windows Boot Image

ReportsAn alternate way to view your collected Mac OS X data is by running VCM Reports or creating your owncustom reports using VCM ’s reporting wizar

Page 29

To get started with VCM for Oracle, follow these steps:1. Add UNIX machines hosting Oracle and install the Agent.2. Discover Oracle Instances.3. Creat

Page 30 - Import Windows Distributions

1. In Administration > Machines Manager > Additional Components > VCM for Oracle, click Add.The Add Oracle Instances wizard opens.2. Select t

Page 31 - VMware, Inc. 31

nMachine NamenOracle Home (Collected)nOracle Home (Override)nOracle SIDnOracle Software Owner (Override)nOracle Software Owner (Override)nOracle User3

Page 32 - Collector

3. On the Files Wizard page, select the InstallOracleCollectionUserAccount.sh file.4. Run the job as root. If desired, select the option of storing re

Page 33 - VMware, Inc. 33

f. If the option was chosen to store results in a local directory, the job status (success or failure)will be returned here.1 After the Oracle OS-auth

Page 34 - 34 VMware, Inc

chmod o+rx $ORACLE_HOME/nlschmod o+rx $ORACLE_HOME/nls/datachmod o+r $ORACLE_HOME/nls/data/lx1boot.nlbchmod o+r $ORACLE_HOME/nls/data/*chmod o+rx $ORA

Page 35 - VMware, Inc. 35

Preparing for Installation1Preparing for InstallationUse this information to help you prepare to install VCM components and tools in your enterprise.n

Page 36 - Confirm Stunnel Configuration

For Oracle 9i Online Documentation, see:(http://www.oracle.com/pls/db92/db92.docindex?remark=homepage)For Oracle 10g Online Documentation, see:(http:/

Page 37 - VMware, Inc. 37

How to Set Up and Use VCM AuditingThe VCM Auditing capability tracks all changes in the security aspects of VCM. Security-related events arewritten to

Page 38 - 38 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide132 VMware, Inc.

Page 39

Getting Started with VCM for Virtualization7Getting Started with VCM for VirtualizationVCM collects virtualization configuration information for virtu

Page 40 - What to do next

Figure 1. Virtual Environments Configuration DiagramESX/ESXi Server CollectionsWhen collecting from ESX and ESXi servers, you must configure at least

Page 41

vCenter Server CollectionsWhen collecting data from vCenter Server, you must license the Windows machine running the vCenterServer and install a VCM A

Page 42

Procedure1. Select Administration > Machines Manager > Licensed Machines > Licensed Windows Machines.2. Select the vCenter Server machines an

Page 43

Procedure1. Download and install the appropriate version of PowerShell 2.0 included in the Windows ManagementFramework.2. Reboot the vCenter Server ma

Page 44 - 44 VMware, Inc

Troubleshooting vCenter Server Data CollectionsIf you encounter problems with vCenter collections, review the troubleshooting options.vCenter Data Mis

Page 45 - Configuration Manager

Procedure1. Determine if the Collector is licensed by selecting Administration > Machines Manager > AvailableMachines > Available Windows Mac

Page 46

Use Installation ManagerUse Installation Manager to perform new installations as well as upgrades. Installation Manager provides ahighly simplified pr

Page 47 - Back up Your Certificates

PrerequisitesnVerify that at least one Agent Proxy machine is configured. See "Configure the Collector as an AgentProxy" on page 138.nLicens

Page 48 - Migration Process

Option DescriptionnIgnore untrusted SSL Certificate: Connection allowed even whencertificates are not verified as trusted.4. On the Important page, re

Page 49 - Environment

Option DescriptionServers passes the SSH and Web Services user information to the target machines.Configure ESXiServers Passes the Web Services to th

Page 50 - 50 VMware, Inc

You can monitor the collection job in Job Manager. When the collection is completed, the data is availablefor reports and compliance assessments.What

Page 51 - VMware, Inc. 51

PrerequsitesnVerify you are using VMware vCenter 4 Server.nVerify the VMware vSphere Client is installed.nVerify the VMware Tools are installed on the

Page 52 - Upgrade Process

Procedure1. Select Administration > Settings > Integrated Products > VMware > vSphere Client VCM Plug-In.2. Select the setting you want to

Page 53 - After You Upgrade VCM

PrerequisitesUnregister the previous version of the vSphere Client VCM Plug-In. See "Unregister the Previous Versionof the vSphere Client VCM Plu

Page 54 - 54 VMware, Inc

HTTPS/SSL Is Not Configured on the CollectorIf the VCM Summary and VCM Actions tabs are not displayed, the settings are improperly configured.ProblemI

Page 55 - VMware, Inc. 55

vCenter Configuration Manager Installation and Getting Started Guide148 VMware, Inc.

Page 56 - 56 VMware, Inc

Getting Started with VCM Remote8Getting Started with VCM RemoteGetting Started with VCM RemoteMany workstations come and go from the network. This tra

Page 57 - ESX 2.5 5.1.3

Understand Tools InstallationSeveral tools are installed with automatically VCM. These tools include:nFoundation CheckernImport/Export Tool and Conten

Page 58 - 58 VMware, Inc

Before Collecting Remote DataBegin using VCM Remote by following the steps outlined below. For more information, click any step tojump to the related

Page 59 - VMware, Inc. 59

The VCM Remote Client can be installed using any of several methods, including a manual installation(provided below), "Installing the Remote Clie

Page 60

4. Accept the default installation location, or click Change to enter a different location. Click Next.5. Type the name of the Collector machine and t

Page 61 - Understanding User Access

7. Configure or select one of the following certificate options:nIf you copied the VCM-generated Enterprise certificate to the CM Remote Client, to lo

Page 62 - Starting and Logging Onto VCM

msiexec.exe /qn /i "[path]\cm remote client.msi" COLLECTOR="YourCollectorName"PATHTOASP="VCMRemote/ecmremotehttp.asp" IN

Page 63 - VMware, Inc. 63

1. On your VCM Collector, copy ...\VMware\VCM\AgentFiles\CM Remote Client.msito...\VMware\VCM\WebConsole\L1033\Files\Remote_Command_Files.2. On your V

Page 64 - Portal Toolbar

sAddRemove = 1 'Whether or not VCM remote should appear in the Add/Removeprograms List, should be 0 = hide, 1 = showsMSIPackageName = "CM Re

Page 65 - VMware, Inc. 65

sVirDir = Trim(sVirDir)End IfIf sInstallDir = "" ThensInstallDir = "c:\vcm remote client"ElsesInstallDir = Trim(sInstallDir)End If

Page 66 - Select: If you want to:

nRun Action now: This option immediately installs VCM Remote Client on the target machines.nSchedule the Action to run later: This option allows you t

Page 67 - Where to Go Next

1. In VCM, click Administration > Settings > General Settings > VCM Remote. The default selection forthe Broadband, Dialup, and LAN collectio

Page 68 - 68 VMware, Inc

The Local System account named NT AUTHORITY\System has unrestricted access to all local systemresources. This account is a member of the Windows Admin

Page 69

vCenter Configuration Manager Installation and Getting Started Guide160 VMware, Inc.

Page 70 - 70 VMware, Inc

Getting Started with VCM Patching9Getting Started with VCM PatchingVCM Patching for Windows and UNIX/LinuxVCM Patching is the VCM patch assessment, de

Page 71 - VMware, Inc. 71

VCM Patching for UNIX/LinuxVCM Patching for UNIX/Linux provides several features that help you deploy patches to remediateUNIX/Linux machines:nBulleti

Page 72 - Discovering Windows Machines

Getting Started with VCM PatchingVMware, Inc. 163

Page 73 - VMware, Inc. 73

vCenter Configuration Manager Installation and Getting Started Guide164 VMware, Inc.

Page 74 - 74 VMware, Inc

10Getting Started with VCM PatchingYou can use VCM Patching to assess the state of managed Windows and UNIX/Linux machines anddeploy patches to those

Page 75 - Licensing Windows Machines

VCM displays a dialog box communicating the status of your request. Follow the prompts to updateyour bulletins, force an update to the bulletins, or c

Page 76 - 76 VMware, Inc

6. Review all of the bulletins to include in the assessment template.7. To create a template that includes all of the bulletins for patches to deploy,

Page 77 - VMware, Inc. 77

select Enable/Disable Summary to enable the Summary view, and click the template node again.The Summary view displays a graph of the patch status for

Page 78 - 78 VMware, Inc

12. Click Next to either schedule the deploy job or to instruct VCM Patching to execute the jobimmediately.13. On the Reboot Options page, select to n

Page 79 - VMware, Inc. 79

To be valid, a Collector certificate must be:nLocated in the local machine personal certificate store.nValid for Server Authentication. If any Enhance

Page 80 - 80 VMware, Inc

PrerequisitePlace patch bulletin files on the local machine to load the bulletin updates from a local file.Procedure1. Select Patching > UNIX/Linux

Page 81 - VMware, Inc. 81

nThe VCM Agent must be installed on the machine.nThe machine must be licensed for VCM Patching.nIf you choose Filters in the following procedure, you

Page 82 - 82 VMware, Inc

Procedure1. Select Patching > UNIX/Linux Platform > Assessment Results > All Bulletins to display the patchstatus of all of the machines that

Page 83 - VMware, Inc. 83

Machine Group MappingWhen you define an alternate patch location for a particular machine group, you must select that machinegroup in VCM before you d

Page 84 - 84 VMware, Inc

9. On the Patch Deployment Schedule page, set the timing for the patch deployment job.10. On the Reboot Options page, select the options to reboot the

Page 85 - VMware, Inc. 85

Customize Your Environment for VCM PatchingPerform routine maintenance on your VCM configuration management database to fine-tune the visibilityof con

Page 86 - 86 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide176 VMware, Inc.

Page 87 - VMware, Inc. 87

Getting Started with Operating System Pro-visioning11Getting Started with Operating SystemProvisioningOperating system (OS) provisioning is the proces

Page 88 - 88 VMware, Inc

Provision Machines WorkflowThe process of provisioning operating systems to target machines includes the following general tasks,underlying actions, a

Page 89 - VMware, Inc. 89

5. Reboot the target machines. As each machine requests an IP address from the DHCP server and thenrequests a PXE boot, OS Provisioning Server checks

Page 90 - Job Status Reporting for WCI

nThe Collector Certificate is used to initiate and secure a TLS communication channel with an HTTPAgent. The Agent must be able to establish that the

Page 91 - Running Reports

Alternately, you can manually add machines to the list rather than use the OS Provisioning Serverdiscovery process. To manually add machines, select A

Page 92 - 92 VMware, Inc

8. (Optional) (Available only for Windows, Red Hat, and SUSE Linux Enterprise Server) On the Post-install Script page, type a Script Name and the scri

Page 93 - VMware, Inc. 93

Change Agent CommunicationThe VCM Agent is installed by the OS Provisioning Server with default settings. After the machine isprovisioned, you can cha

Page 94 - 94 VMware, Inc

NOTE Static IP addressing is recommended when deploying ESX or ESXi hosts. If DHCP is used, theESX or ESXi machine’s host name will be set to localhos

Page 95 - VMware, Inc. 95

vCenter Configuration Manager Installation and Getting Started Guide184 VMware, Inc.

Page 96

Getting Started with Software Provisioning12Getting Started with Software ProvisioningIntroduction to VCM Software ProvisioningSoftware provisioning i

Page 97 - Adding UNIX/Linux Machines

Software Provisioning Component RelationshipsThe following diagram displays the general relationship between Package Studio, repositories, andPackage

Page 98 - Licensing UNIX/Linux Machines

nSoftware Repository for Windows: Installed on at least one Windows machine in your environment,and installed on the same machine with Package Studio.

Page 99 - VMware, Inc. 99

PrerequisitesnTo uninstall the application, you must use the same version of the Repository.msi that was used toinstall the application.Procedure1. Co

Page 100 - 100 VMware, Inc

PrerequisitesnTarget machine meets the supported hardware requirements, operating system, and softwarerequirements. See VCM Hardware and Software Requ

Page 101 - VMware, Inc. 101

For more information about Installing the Agent on UNIX/Linux Machines and UNIX/Linux packages andplatforms, refer to section Installing the VCM Agent

Page 102 - 102 VMware, Inc

Install Package Manager on Managed MachinesThe Package Manager is automatically installed on target machines when the 5.3 VCM Agent or later isinstall

Page 103 - VMware, Inc. 103

Creating PackagesA software package provides the files and metadata necessary to install and remove programs. One of themost useful features of a pack

Page 104 - 104 VMware, Inc

a. Click Add Platforms to add a platform.b. Select a platform, and then click Add Sections.c. Select a section, and then click Publish Package.d. Sele

Page 105 - VMware, Inc. 105

nYou have created software provisioning packages using VMware vCenter Configuration ManagerPackage Studio and published the packages to the repositori

Page 106 - 106 VMware, Inc

8. Review the information, resolve any conflicts, and then click Finish. You can monitor the process inthe Jobs Manager. See "Viewing Provisionin

Page 107 - VMware, Inc. 107

Install PackagesThe process of installing packages includes identifying and processing dependencies and conflicts, runningany specified prescripts, ru

Page 108 - 108 VMware, Inc

Related Software Provisioning ActionsYou can use the following management options in VCM when working with software provisioning:nJob Manager: Display

Page 109 - VMware, Inc. 109

In this example the Compliance rule checks whether the source, where platform=Any and section=Release,was added to selected Package Managers as a sour

Page 110 - 110 VMware, Inc

In this example, you want to determine if a software application named XSoftware is correctly installed. Ifthe software is installed correctly, a serv

Page 111 - Adding Mac OS X Machines

21. Select one of the following Security Options:This option determines if a package is installed or removed based on the state of the signature. Sele

Page 112 - Licensing Mac OS X Machines

CopyrightYou can find the most up-to-date technical documentation on the VMware Web site at:http://www.vmware.com/support/The VMware Web site also pro

Page 113 - VMware, Inc. 113

Cryptography used in VCM Software ComponentsVCM uses various software components that also use cryptography. Microsoft IIS, Internet Explorer, andSCha

Page 114 - 114 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide200 VMware, Inc.

Page 115 - VMware, Inc. 115

Getting Started with VCM ManagementExtensions for Assets13Getting Started with VCM ManagementExtensions for AssetsGetting Started with VCM Management

Page 116 - 116 VMware, Inc

3. Consider whether the fields are listed in the order in which you want them to appear in the Console. Ifnot, click Column Order in the data grid vie

Page 117 - VMware, Inc. 117

2. Click VCM Devices or Other Devices, depending on the type of field you want to delete.3. If you are editing an existing field, select the field, an

Page 118 - 118 VMware, Inc

1. Click Administration > Settings > Asset Extension Settings > Hardware Configuration Items.2. Click VCM Devices or Other Devices, depending

Page 119 - VMware, Inc. 119

5. If you have defined this field as a lookup, the wizard prompts you to define or edit the lookup values.Enter the required information, and then cli

Page 120 - 120 VMware, Inc

4. Select the fields to edit, and then click Next.5. Enter a value for each of the fields displayed, and then click Next.6. Confirm your change, and t

Page 121 - VMware, Inc. 121

NOTE If you want to change only the values for that device, and not the device name or descriptionitself, click Edit Values, instead of Edit. The Edit

Page 122 - 122 VMware, Inc

1. Select the record, and then click Delete.2. Click OK to confirm your deletion. VCMMXA deletes the requested record from the SoftwareConfiguration I

Page 123 - VMware, Inc. 123

Getting Started with VCM Service DeskIntegration14Getting Started with VCM Service DeskIntegrationGetting Started with Service Desk IntegrationVCM Ser

Page 124 - Discovering Oracle Instances

Installing VCM2Installing VCMUse Installation Manager to install VCM and all of its components and tools.To install only the VCM tools, follow the ins

Page 125 - VMware, Inc. 125

Service Desk Integration in Job ManagerWhen VCM Service Desk Integration is licensed and activated, it suspends any requested change to aVCM-managed m

Page 126 - 126 VMware, Inc

NOTE Jobs for VCM Patching-managed machines appear in the Patching Job Manager, not the VCM JobManager. Locate these jobs at: Patching > Administra

Page 127 - VMware, Inc. 127

vCenter Configuration Manager Installation and Getting Started Guide212 VMware, Inc.

Page 128 - 128 VMware, Inc

Getting Started with VCM for Active Direc-tory15Getting Started with VCM for ActiveDirectoryVCM for Active Directory (AD) collects AD objects across D

Page 129 - VMware, Inc. 129

Confirming the Presence of DomainsPrior to setting up VCM for Active Directory, you must confirm that all fully-qualified DNS Domains thatyou want to

Page 130 - 130 VMware, Inc

Adding and Assigning Network Authority AccountsBefore you can perform any type of action (Discovery, Collection, and so forth), the Collector must gai

Page 131 - VMware, Inc. 131

4. Select By Browse List, then click Next. The Discovery Filters page appears.5. Select Only discover machines in the Browse List that match these cri

Page 132 - 132 VMware, Inc

Verifying Domain Controller Machines in Available MachinesOnce your Domain Controller discovery is completed, verify that your Domain Controllers are

Page 133 - VMware, Inc. 133

9. Verify the method used for communication. The default communication method is DCOM. For mostVCM for Active Directory configurations, the default va

Page 134 - ESX/ESXi Server Collections

4. Click the Tools tab.5. In the Tool Name list, select Disable UAC.6. Click Launch. A Command window displays the running action. When the command is

Page 135 - Prerequisites

1. Select one of these options:nRun Installation Manager. Starts Installation Manager and begins the installation.nView Help. Displays the Installatio

Page 136 - Procedure

7. On the Domains/OUs tab, select the domain/OU to which the target machines belong, and then clickOK.8. On the Select Group Policy Object dialog box,

Page 137 - Collect vCenter Server Data

IMPORTANT Click Administration > Job Manager > History > Instant Collections > Past 24 Hours toverify that all jobs have completed before

Page 138 - Solution

NOTE VCM for AD will operate with only a single domain controller configured with VCM for AD asboth the FDS/RDS (Forest Data Source/Replication Data S

Page 139 - VMware, Inc. 139

6. Upon completing the Setup DCs action, a collection will be submitted to the selected DCs. Forestinformation will be displayed in the Administration

Page 140 - Option Description

3. Select a Forest Data Source (FDS) for each Forest to be managed in VCM for Active Directory, andthen click Next. The Select the Replication Data So

Page 141

Performing an Active Directory Data CollectionYou are now ready to perform your first collection of Active Directory objects using the same collection

Page 142

NOTE The delta collection feature makes subsequent collections run faster and more efficiently thanthe initial collection. For the initial collection,

Page 143 - VMware, Inc. 143

11. Expand the Enterprise tree, and then select an AD Location.12. Click OK, to close the page.13. On the Location page, click Next.14. Click Finish.I

Page 144

Note that several other Active Directory Dashboards are available. Take time to familiarize yourself withthe remainder of the VCM for AD Dashboards.Ac

Page 145

NOTE The default view is the Summary Report. At any time, however, you may switch the default viewto go directly to the data grid by using the Enable/

Page 146

Installing and Configuring the OS Pro-visioning Server and Components3Installing and Configuring the OSProvisioning Server and ComponentsThe Operating

Page 147 - VMware, Inc. 147

Active Directory ReportsAn alternative way to view your collected AD data is by running VCM Reports or creating your owncustom reports using VCM’s rep

Page 148 - 148 VMware, Inc

Accessing Additional Compliance Content16Accessing Additional Compliance ContentVMware provides several additional VCM Compliance Content Packages rel

Page 149 - Workflow Diagram

If the particular Content Package(s) you have imported contains filter sets, they will appear underAdministration > Collection Filters > Filter

Page 150 - Before Collecting Remote Data

Installing and Getting Started with VCMTools17Installing and Getting Started with VCMToolsSeveral VCM components and tools were automatically installe

Page 151 - VMware, Inc. 151

The VCM tool or tools are now installed on this machine. Proceed to the following sections in this chapterto get started using the tools.NOTE The VCM

Page 152 - 152 VMware, Inc

IMPORTANT Use of the CLI should be restricted to advanced users who exercise caution when testing outtheir scripts.Import/Export and CW were automatic

Page 153 - VMware, Inc. 153

NOTE VMware recommends that you refer to Import/Export Help to gain a thorough understanding ofthe logging of Content that is not imported by Import/E

Page 154 - 154 VMware, Inc

Maintaining VCM After Installation18Maintaining VCM After InstallationAfter you have performed the initial setup and familiarized yourself with VCM an

Page 155 - VMware, Inc. 155

In addition to several general global settings, these components have specific settings that should beconsidered if you licensed the component.nAsset

Page 156 - 156 VMware, Inc

Configure Database File GrowthAfter VCM is installed, the installer creates a single 2GB data file and a 1GB log file. As data is added toVCM through

Page 157 - VMware, Inc. 157

Procedure1. Mount the VCM-OS-Provisioning-Server-<version number>.iso by either attaching to the media imageor mounting the image.When mounting

Page 158 - 158 VMware, Inc

Configure Database Recovery SettingsSQL Server supports these recovery models, which you can set differently for each database:nSimple. In Simple reco

Page 159 - VMware, Inc. 159

2. Open the Management folder, right-click Maintenance Plans and select Maintenance Plan Wizard.3. Click Next. The Select Plan Properties page appears

Page 160 - 160 VMware, Inc

4. Enter a maintenance plan name, select Single schedule for the entire plan or no schedule, and clickChange.5. In the Job Schedule Properties - Maint

Page 161 - VCM Patching for Windows

7. On the Select Maintenance Tasks page, select the maintenance tasks to be performed, including CheckDatabase Integrity, Rebuild Index, Update Statis

Page 162 - Minimum System Requirements

9. On the Define Database Check Integrity Task page, click the Databases drop down menu and select theCSI_Domain, VCM, VCM_Coll, VCM_Raw, and VCM_UNIX

Page 163 - VMware, Inc. 163

10. On the Define Rebuild Index Task page, specify how the Maintenance Plan should rebuild the Index.Click the Databases drop down menu, select the CS

Page 164 - 164 VMware, Inc

11. On the Define Update Statistics Task page, specify how the Maintenance Plan should update thedatabase statistics. Click the Databases drop down me

Page 165

13. On the Select Report Options page, select Write a report to a text file, specify the folder location tosave a record of the maintenance plan actio

Page 166

15. When the Maintenance Plan Wizard completes, verify that the actions were successful.16. To view, save, copy, or send the report, click Report and

Page 167 - Prerequisite

Troubleshooting Problems with VCMATroubleshooting Problems with VCMThis chapter provides important information that will help you troubleshoot issues

Page 168

# su - fsrepo[fsrepo@<machine name>~]$ create-repository11. When the action completes, run the [fsrepo@<machine name>~]$ exit command.If n

Page 169

oSupport for additional UNIX platforms was added in 5.1, along with the automateddistribution of bulletin information to Agent machines.nThe process o

Page 170

1. Open a command prompt.2. Navigate to the C:\Program Files (x86)\VMware\VCM\AgentData\protected directory, anddelete these files: ECMv.csi.pds and E

Page 171

1. Log into VCM and select Administration > Settings > General Settings > Database.2. In the Database settings, click to highlight the settin

Page 172 - Store the UNIX Patches

Index%%Systemroot% environment variable 79AAbout Patching 161about this book 11access by user 61accessingcompliance content 231accountapplication serv

Page 173

collection resultsAD 227Oracle 129Remote 159UNIX/Linux 107virtualization 143collection scriptscustom for WCI 93collection user accountcreating, Config

Page 174 - Running VCM Patching Reports

collection resultsOracle 129UNIX/Linux 107virtualization 143Windows 84imported content 231Remote collection results 159Ffilter setsimported content 23

Page 175 - VMware, Inc. 175

collection 119collection results 121licensing 112maintenanceafter installation 237backup/disaster recovery plan 248configure database file growth 239c

Page 176 - 176 VMware, Inc

assets 208Oracle 129Service Desk 211registeringvSphere Client Plug-in 59, 143, 145remediationcompliance rulesoftware provisioning 197Remotecollection

Page 177 - Provisioning

check for Windows 165updatingIIS settings 251virtual directory 251upgrading 45agent 53agent proxy 57agent proxy manually 58automatic 54failed, trouble

Page 178 - Provision Machines Workflow

Whether you use a private provisioning network or a shared network you can use either the OSProvisioning Server DHCP server or a separate DHCP server;

Page 179 - Collect OS Distributions

3. On the corporate DHCP server, update the dhcpd.conf file with the following options:allow bootp;allow booting;next-server <IP address of the OS

Page 180 - Provision Machines

[Thu Jul 22 08:57:08 IST 2010] UNINSTALL-ME: Command : /sbin/service FastScalestopShutting down FSnetfs: [ OK ]Shutting down FSsyslog: [ OK ]Shutting

Page 181 - Post-Provisioning Action

Option DescriptionProvisioningServerPublic IP><OSProvisioningServerPrivate IP>OS Provisioning Server's Private Interface IP Address. The

Page 182 - Re-Provision Machines

ContentsUpdated Information 9About This Book 11Preparing for Installation 13Use Installation Manager 14Understand Installation Configurations 14Unders

Page 183

For example, # cp -R /media/cdrom/Win2003-R2-SP2-Standard /tmp/Win2003-R2-SP2-Standard3. Replace the first CD with the second CD and type:# cp -R /med

Page 184 - 184 VMware, Inc

8. The script runs as follows with a specific example:Importing data into repository...Importing source data...No recipes are accessible.Adding new re

Page 185 - Package Manager for Windows

7. The script runs as follows:Importing data into repository...Importing source data...No recipes are accessible.Adding new recipe ESX4.0ulBasicRecipe

Page 186 - 186 VMware, Inc

nAll private keys are RSA keys.nCertificates are created or obtained, and copied to the required locations using industry best practices.nOn the VCM C

Page 187

; The hash can be obtained with the command: openssl x509 -noout -incert.pem -hashCApath = /opt/FastScale/var/certsclient = noforeground = nooutput =

Page 188 - Install Package Studio

Procedure1. Place the VCM Stunnel certificate in[C:]\Program Files (x86)\VMware\VCM\Tools\sTunnel\certs\vcm_stunnel_cert.pem.2. Place the VCM Stunnel

Page 189

;; verify = level;; level 1 - verify peer certificate if present;; level 2 - verify peer certificate;; level 3 - verify peer with locally installed ce

Page 190

Procedure1. From the VCM Collector, start Internet Explorer and go to http://localhost:21307/.If the connection is properly configured, the following

Page 191 - Creating Packages

Procedure1. Log in as the fsrepo user.# su - fsrepo2. Run the backup command to backup the repository files to /temp/fs-backup.[fsrepo@localhost~]$ mk

Page 192

[fsrepo@localhost~]$ db2 CONNECT RESET;[fsrepo@localhost~]$ db2 RESTORE DATABASE FSREPO FROM /tmp/fs-backup TAKEN AT<timestamp> WITH 2 BUFFERS B

Page 193 - VMware, Inc. 193

vCenter Configuration Manager Installation and Getting Started GuideUpgrade and Migration Scenarios 45Prerequisites 46Back up Your Databases 47Back up

Page 194 - 194 VMware, Inc

key = /opt/FastScale/var/certs/private/service.key; Either CAfile or CAPath, but not both, should be defined; CAfile = /opt/FastScale/var/certs/ca-cer

Page 195 - Install Packages

PrerequisitesnBefore placing the VCM Stunnel certificate and the VCM Stunnel private key, you must ensure thefiles are secured according to your corpo

Page 196 - 196 VMware, Inc

;; cert (the first 4 bytes of the MD5 hash in least significant byte order).;; The hash can be obtained with the command: openssl x509 -noout -in cert

Page 197 - VMware, Inc. 197

PrerequisitesnConfigure Stunnel on the OS Provisioning Server as described in "Configure Stunnel on the OSProvisioning Server " on page 39.n

Page 198 - 198 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide44 VMware, Inc.

Page 199 - Further Reading

Upgrading or Migrating vCenter Con-figuration Manager4Upgrading or Migrating vCenterConfiguration ManagerWhen you migrate vCenter Configuration Manage

Page 200 - 200 VMware, Inc

PrerequisitesVCM 5.4 now supports 64-bit environments only, which include 64-bit hardware, a 64-bit operatingsystem, and SQL Server 2008 R2. If you mi

Page 201 - Extensions for Assets

Back up Your DatabasesBack up all of the databases used in your configuration. Depending on which version you migrate, thedatabase names differ slight

Page 202 - View Available Fields

Migration ProcessYou can migrate these environments to support VCM 5.4:n"Migrate a 32-bit environment running VCM 5.3 or earlier to VCM 5.4"

Page 203 - VMware, Inc. 203

Replace your existing 32-Bit Environment with the Supported 64-bitEnvironmentA 32-bit environment must be functional before you migrate to VCM 5.4. Be

Page 204 - 204 VMware, Inc

ContentsGetting Started with VCM for Mac OS X 110Adding Mac OS X Machines 111Licensing Mac OS X Machines 112Installing the Agent on Mac OS X Machines

Page 205 - Editing Values for Devices

Migrate a 32-bit environment running VCM 5.3 or earlier to VCM 5.4Your 32-bit environment must be functional before you migrate to VCM 5.4.CAUTION Bef

Page 206 - Modifying Other Devices

For information about the sp_changedbowner stored procedure, see SQL Server 2008 R2 Books Online.Migrate a 64-bit environment running VCM 5.3 or earli

Page 207 - VMware, Inc. 207

11. During the installation, do not select SSL unless your machine is already configured for SSL.12. After the upgrade completes, copy the contents of

Page 208

To upgrade to VCM 5.4:1. Upgrade the operating system to Windows Server 2008 R2.2. Uninstall the 32-bit version of SQLServer Reporting Services (SSRS

Page 209 - Integration

nWill fail for any machine on which an Agent does not already exist.nWill use an Agent's current settings. For example, if the Agent uses DCOM, t

Page 210 - 210 VMware, Inc

Platforms Not Supported for Upgrade to 5.4 AgentInstalling or upgrading on the following platforms is supported only to the 5.1.3 UNIX Agent. You cani

Page 211

To Upgrade the UNIX Agent(s) with a Remote PackageThis method sends the upgrade package with the remote command to execute on the UNIX machine. Thefol

Page 212 - 212 VMware, Inc

CAUTION When upgrading VCM for Virtualization, take the following precautions:Do not change the password for the CSI Communication Proxy service. Doin

Page 213 - Directory

7. Click Next. The Important page appears. Review the contents, click Back to make any necessaryalterations.8. Click Finish. The Agent Proxy is upgrad

Page 214 - 214 VMware, Inc

6. The installer proceeds with the installation. When the VCM Windows Agent has been successfullyinstalled, click Finish.7. Copy the following executa

Page 215 - VMware, Inc. 215

vCenter Configuration Manager Installation and Getting Started GuideRunning VCM Patching Reports 174Customize Your Environment for VCM Patching 175Get

Page 216 - 216 VMware, Inc

Procedure1. Go to https://vCenter machine name/mob/?moid=ExtensionManager.vCenter machine name represents the name of your vCenter Server 4.0 instance

Page 217 - VMware, Inc. 217

Getting Started with VCM Componentsand Tools5Getting Started with VCM Components andToolsThis chapter covers global getting started procedures for VCM

Page 218 - 218 VMware, Inc

All VCM user accounts must have the following rights on the VCM Collector machine:nAbility to log on locally to access IIS.nRead access to the System3

Page 219 - VMware, Inc. 219

2. Depending on your browser security settings, you may have to supply your user network credentials.3. (Optional) Select Automatically log on using t

Page 220 - 220 VMware, Inc

General Information BarThe general information bar displays the VCM Collector’s (active SQL Server) name, your VCM username and active Role, and these

Page 221 - VMware, Inc. 221

The Copy button is used to copy information from the selected rows in the data gridto the clipboard.The Copy link to clipboard button is used to copy

Page 222 - 222 VMware, Inc

Select: If you want to:nView Active Directory Group Policy Container Settings.nView information about Active Directory Domains, DCs, and Trusts.nTrack

Page 223 - Running the Setup DCs Action

Where to Go NextYou are now ready to proceed to Getting Started with VCM to start using VCM and all of its componentsand tools.After you have complete

Page 224 - 224 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide68 VMware, Inc.

Page 225 - VMware, Inc. 225

Getting Started with VCM6Getting Started with VCMBefore you can begin using VCM to manage the machines in your enterprise, you must complete thefollow

Page 226 - 226 VMware, Inc

ContentsMaking VCM Aware of Domain Controllers 213Confirming the Presence of Domains 214Adding and Assigning Network Authority Accounts 215Discovering

Page 227 - Active Directory Dashboards

If the Windows machines that you want to manage belongs to a domain that is not shown in this list, thenyou must add that domain manually. Click Add,

Page 228 - 228 VMware, Inc

1. Click Administration > Settings > Network Authority > Available Accounts.2. If you need to add a new account, click Add and follow the pro

Page 229 - VMware, Inc. 229

The following procedure illustrates how to assign Network Authority to accounts by NetBios domain.However, you can also assign Network Authority by Ac

Page 230

Your initial discovery can take anywhere from one afternoon to a couple of days, depending on the size ofyour network. You may not have a 100% success

Page 231 - VMware, Inc. 231

3. Type a Name and Description for this new Discovery Rule, then click Next. The Discovery Methodpage appears.4. If you have Active Directory in your

Page 232 - 232 VMware, Inc

8. Create the filter. For more specific filtering of machines for discovery and other advanced features,refer to the online Help. Click Next. The Impo

Page 233 - Installing the VCM Tools Only

VCM requires that you specify the machines you want to manage. Remember, the number of licenses youhave purchased may not match the number of machines

Page 234 - Foundation Checker

4. Leave the Install VCM Agents for the selected machines box unchecked during your first pass atlicensing machines. Once you have more experience lic

Page 235 - VCM Import/Export

3. Click Install and follow the prompts.NOTE To use advanced options such as HTTP communication for your agent, or to deploy the agentfrom an alternat

Page 236 - Content Wizard

1. On your Collector, navigate to the Agent files directory at:C:\Program Files (x86)\VMware\VCM\AgentFiles2. Locate the CMAgentInstall.exe file, and

Page 237 - VMware, Inc. 237

vCenter Configuration Manager Installation and Getting Started Guide8 VMware, Inc.

Page 238 - 238 VMware, Inc

NOTE For Vista, Windows7, and Windows 2008 only: If you set compatibility mode on any Agentexecutables to a prior version of Windows, the operating sy

Page 239 - VMware, Inc. 239

nPORTNUMBER: Installs the Windows Agent on the port number specified, using HTTP instead ofDCOM. For HTTP installs, where PORTNUMBER is set, you must

Page 240 - 240 VMware, Inc

8. Restart the machine to apply the changes.9. Install the Agent as specified in Licensing and Deploying the VCM Agent.10. After installing the Agent

Page 241 - VMware, Inc. 241

Performing an Initial CollectionYou are now ready to collect data. VMware recommends using the default filter set, which collects ageneral view of the

Page 242 - 242 VMware, Inc

5. For initial collections, there should be no conflicts with previously scheduled or running jobscontaining the same data types. Click Finish.6. Veri

Page 243 - VMware, Inc. 243

1. Begin by looking at the Windows Operating Systems Dashboard under Console > Dashboards >Windows > Operating Systems.2. Note that several o

Page 244 - 244 VMware, Inc

4. When you select the node, you will see a Summary Report as displayed above of the data class thatyou selected. Click View Data Grid to go directly

Page 245 - VMware, Inc. 245

TIP The default view is the Summary Report; however, at any time you may switch the defaultview to go directly to the data grid by using the ’Enable/D

Page 246 - 246 VMware, Inc

Getting Started Collecting Windows Custom InformationAs a System Administrator, you can extend the data that VCM can collect by using a script, which

Page 247 - VMware, Inc. 247

nYou must obtain or write a PowerShell script that will return data in a VCM-compatible element-normal XML format.nThe VCM agent (for VCM 5.3 or later

Page 248 - 248 VMware, Inc

Updated InformationUpdated InformationVCM Installation and Getting Started Guide is updated with each release of the product or when necessary.This ta

Page 249 - VMware, Inc. 249

11. Click Next and then Finish.12. Run a collection using your new collection filter.13. Ensure the job completes.14. View data in the Custom Informat

Page 250 - To Resolve the Problem

The Job History Machine Detail view displays a single row for each WCI filter included in the collectionjob. These rows provide information about the

Page 251 - VMware, Inc. 251

Executing PowerShell ScriptsPowerShell contains built-in policies, which limit its use as an attack vector. The primary policy is for scriptexecution.

Page 252 - 252 VMware, Inc

For additional information about Windows PowerShell and signing scripts, see:nScripting with Windows PowerShell: http://technet.microsoft.com/en-us/sc

Page 253 - VMware, Inc. 253

nThe default WCI filter returns PowerShell version information from VCM-managed machines.nDo not include any formatting white space. For example, do n

Page 254 - 254 VMware, Inc

The <schtasks> top-level name is an arbitrary name picked to distinguish the results of this script fromothers. A couple of additional challenge

Page 255 - VMware, Inc. 255

the task name is used as the element name for task rows, but the “increment” option is selected forduplicate handling when creating a collection filte

Page 256 - 256 VMware, Inc

Discover, License, and Install UNIX/Linux MachinesThe following steps must be performed before collecting data from UNIX/Linux machines:1. Add UNIX/Li

Page 257 - VMware, Inc. 257

3. Select Basic, and then click Next. The Manually Add Machines - Basic page appears.NOTE When you expand your UNIX/Linux collections to a broader set

Page 258 - 258 VMware, Inc

NOTE Remember, discovered machines with an indeterminate Machine Type will not be licensed ifthey are included in your selection.2. Select the machine

Comments to this Manuals

No comments