VMware VCENTER APPLICATION DISCOVERY MANAGER 6.1.1 - RESPOSITORY Bedienungsanleitung Seite 30

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 64
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 29
Application Discovery Manager Administration Guide
30 VMware, Inc.
6Placeyourcursorattheendofthelineandappendthelinebytyping:
single
7PressEntertocommitthechange.
8Pressbtostartthesystem.
Yoursystemstartswithoutrequiringapassword.
9Typethefollowingcommandtoresetthepassword:
passwd
10 Followthepromptsastheyappearonthescreentosetthepassword.
11 Typethefollowingcommandtorestartthesystem:
reboot
Yourpasswordischangedandrestartsthesystem.
OpenSSL Self-Signed Test Certificates
TheVMwarevCenterApplicationDiscoveryManagerdefaultinstalledcertificateiscreatedduringthe
installationandisvalidforoneyeartousetheapplianceuntilyouacquirealocalCertificateAuthority(CA).
PublicfacingsecureWebsitesmustuseathirdpartyCA.Ifyouwanttousetheapplianceintestenvironment
andthendeploythatappliancetoaproductionenvironment,youmustnotchangethehostnameastheADM
doesnotsupportchangingthehostname.Instead,youcansetupanaliasintheDNStoresolvetheappliance
hostname.
CA Signed Test Certificates
TocreateCAsignedcertificates,youmustgenerateacertificaterequestfile(csr).Thecertificaterequestfile
providesdetailsabouttherequesterofthecertificateandthecertificateissignedbytheprivatekeyaboveto
yourtrustedcertificateauthority.
Createthecertificaterequestbytyping:
openssl req -new -key server.key -out server.csr
FillintheX.509attributesasspecifiedpreviously.FormoredetailsconsultyourCA.
ToinstallthecertificateprovidedbyyourCA,performthestepsdescribedin“Copyingthe.keyand.crtFiles”
onpage 31.
FreeCAproviders,ashttp://www.cacert.orgexist.
Self-Signed Certificates
Useselfsignedcertificatesonlyinthetestenvironments,orwhereonlyalimitednumberofconnectionsis
established.Forexample,peertopeerrelationshipscanbeacustomVPNorAS2linkbetweentwocompanies,
orbetweentwodifferentsitesofthesamecompany.Selfsignedcertificatesbecomeimpracticalas
thenumber
ofcertificatesnecessarytomanagegrowslinearlywiththenumberofpeeringrelationships.AlocalCA,while
morecomplextosetup,reducesthenumberofkeysrequiredtobedistributedforverification,andreplicates
arealworldcertificateenvironment.ACAcancostlesstomanagethanhundreds
orthousandsofindividual
certificatesoneachpeersystem.
Certificatecreationrequirestheopensslutility.TheopensslutilityislocatedintheADMappliancefolder.
/usr/bin/openssl
NOTEYoucanalsoresettheADMrootpasswordbyrunningsystem_setupcommand.
NOTEDonotusetheselfsignedcertificatesinproductionenvironments.
Seitenansicht 29
1 2 ... 25 26 27 28 29 30 31 32 33 34 35 ... 63 64

Kommentare zu diesen Handbüchern

Keine Kommentare