VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION Betriebsanweisung

Stöbern Sie online oder laden Sie Betriebsanweisung nach Software VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION herunter. VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION User`s guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 258
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1

VMware vCenter Configuration Manager Installationand Getting Started GuidevCenter Configuration Manager 5.4This document supports the version of each

Seite 2 - Copyright

vCenter Configuration Manager Installation and Getting Started Guide10 VMware, Inc.

Seite 3 - Contents

Use the following steps to install the Agent.1. Verify that the machine on which you intend to install the agent has enough free disk space. For morei

Seite 4 - Getting Started with VCM 69

inflating: CSIInstall/scripts/AltSource_ftp.shinflating: CSIInstall/scripts/AltSource_rcp.shinflating: CSIInstall/scripts/AltSource_sftp.shinflating:

Seite 5 - VMware, Inc. 5

Installation Options with DefaultValuesDescriptionCSI_CREATE_USER=YRecommend keeping default value.The user is being created. This value indicates whe

Seite 6 - 6 VMware, Inc

Installation Options with DefaultValuesDescriptionCSI_CREATE_LOCAL_SERVICE=YRecommend keeping default value.Setting CSI_CREATE_LOCAL_SERVICE to Y allo

Seite 7 - Index 253

values specified in csi.config without prompting for input. To run the installation in silentmode, enter:# ./CSIInstall/InstallCMAgent -sYou might use

Seite 8 - 8 VMware, Inc

drwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 Agentdrwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 CFC-rw-rw---- 1 root cfgsoft 49993 Jul 2 17:34 CSIRegistry-

Seite 9 - Updated Information

1. (Optional) Copy csi.config, the file that contains all of the custom configuration settings, to a safelocation. (This file can be found in <path

Seite 10 - 10 VMware, Inc

instead of the default collection options, and then select the UNIX Patch Assessment filter set. For moreinformation, see the "UNIX Patch Assessm

Seite 11 - About This Book

Note that several other UNIX Dashboards are also available. Take time to familiarize yourself with theremainder of the UNIX Dashboards. UNIX Collectio

Seite 12 - 12 VMware, Inc

When you select the node, you see a Summary Report as displayed above of the data type that youselected. Click View data grid to go directly to the da

Seite 13 - Preparing for Installation

About This BookAbout This BookThe VMware vCenter Configuration Manager Installation and Getting Started Guide describes the stepsnecessary for a succe

Seite 14 - Use Installation Manager

Like Dashboards, Reports are run real time against the current data available in the CMDB for themachines in the active machine group, and therefore t

Seite 15 - Understand Tools Installation

Adding Mac OS X MachinesBefore you can collect data from your Mac OS X machines, they must be displayed in the Available UNIXMachines list located in

Seite 16 - VCM Remote Virtual Directory

4. Enter the Machine and the Domain, and then select DNS for Type. For Machine Type, select theappropriate operating system. Modify the port number if

Seite 17 - Server Authentication

5. Click Next. The Product License Details page appears.6. The licensed machine count has increased by the number of machines that you have selected t

Seite 18 - 18 VMware, Inc

4. Use chmod u+x <filename> to change the permissions on the agent binary file.5. In the directory where you copied the file, execute the agent

Seite 19 - Windows Machines

Installation Options with DefaultValuesDescription• +H means only for HP-UX• +L means only for Linux• +D means only for Darwin (Mac OS X)• + means for

Seite 20 - 20 VMware, Inc

Installation Options with DefaultValuesDescriptionCSI_REFRESH_INETD=YKeep default value only if you arerunning your agent as inetd. If youare running

Seite 21 - Using Installation Manager

mode, enter:# ./CSIInstall/InstallCMAgent -sYou might use this method if you have manually edited the csi.config file, if you havemodified the csi.con

Seite 22 - 22 VMware, Inc

drwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 Agentdrwxr-x--- 3 root cfgsoft 4096 Jul 2 17:34 CFC-rw-rw---- 1 root cfgsoft 49993 Jul 2 17:34 CSIRegistry-

Seite 23 - Best Practices

NOTE Consider these points when uninstalling an Agent:• The uninstall reverses all changes made by installation, however the installation log files ar

Seite 24 - 24 VMware, Inc

Technical Support and Education ResourcesThe following technical support resources are available to you. To access the current version of this bookand

Seite 25 - Configure DHCP

The data classes and filters for Mac OS X include the following:nMachines > GeneralnFile System > File StructurenSystem Logs > syslog eventsn

Seite 26

4. The Data Types dialog box appears. Select the Select All check box, then confirm that the Use defaultfilters option button is also selected. Click

Seite 27 - Configure TFTP

When you select the node, you see a Summary Report as displayed above of the data type that youselected. Click View data grid to go directly to the da

Seite 28 - Create Windows Boot Image

ReportsAn alternate way to view your collected Mac OS X data is by running VCM Reports or creating your owncustom reports using VCM ’s reporting wizar

Seite 29

To get started with VCM for Oracle, follow these steps:1. Add UNIX machines hosting Oracle and install the Agent.2. Discover Oracle Instances.3. Creat

Seite 30 - Import Windows Distributions

1. In Administration > Machines Manager > Additional Components > VCM for Oracle, click Add.The Add Oracle Instances wizard opens.2. Select t

Seite 31 - VMware, Inc. 31

nMachine NamenOracle Home (Collected)nOracle Home (Override)nOracle SIDnOracle Software Owner (Override)nOracle Software Owner (Override)nOracle User3

Seite 32 - Collector

3. On the Files Wizard page, select the InstallOracleCollectionUserAccount.sh file.4. Run the job as root. If desired, select the option of storing re

Seite 33 - VMware, Inc. 33

f. If the option was chosen to store results in a local directory, the job status (success or failure)will be returned here.1 After the Oracle OS-auth

Seite 34 - 34 VMware, Inc

chmod o+rx $ORACLE_HOME/nlschmod o+rx $ORACLE_HOME/nls/datachmod o+r $ORACLE_HOME/nls/data/lx1boot.nlbchmod o+r $ORACLE_HOME/nls/data/*chmod o+rx $ORA

Seite 35 - VMware, Inc. 35

Preparing for Installation1Preparing for InstallationUse this information to help you prepare to install VCM components and tools in your enterprise.n

Seite 36 - Confirm Stunnel Configuration

For Oracle 9i Online Documentation, see:(http://www.oracle.com/pls/db92/db92.docindex?remark=homepage)For Oracle 10g Online Documentation, see:(http:/

Seite 37 - VMware, Inc. 37

How to Set Up and Use VCM AuditingThe VCM Auditing capability tracks all changes in the security aspects of VCM. Security-related events arewritten to

Seite 38 - 38 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide132 VMware, Inc.

Seite 39

Getting Started with VCM for Virtualization7Getting Started with VCM for VirtualizationVCM collects virtualization configuration information for virtu

Seite 40 - What to do next

Figure 1. Virtual Environments Configuration DiagramESX/ESXi Server CollectionsWhen collecting from ESX and ESXi servers, you must configure at least

Seite 41

vCenter Server CollectionsWhen collecting data from vCenter Server, you must license the Windows machine running the vCenterServer and install a VCM A

Seite 42

Procedure1. Select Administration > Machines Manager > Licensed Machines > Licensed Windows Machines.2. Select the vCenter Server machines an

Seite 43

Procedure1. Download and install the appropriate version of PowerShell 2.0 included in the Windows ManagementFramework.2. Reboot the vCenter Server ma

Seite 44 - 44 VMware, Inc

Troubleshooting vCenter Server Data CollectionsIf you encounter problems with vCenter collections, review the troubleshooting options.vCenter Data Mis

Seite 45 - Configuration Manager

Procedure1. Determine if the Collector is licensed by selecting Administration > Machines Manager > AvailableMachines > Available Windows Mac

Seite 46

Use Installation ManagerUse Installation Manager to perform new installations as well as upgrades. Installation Manager provides ahighly simplified pr

Seite 47 - Back up Your Certificates

PrerequisitesnVerify that at least one Agent Proxy machine is configured. See "Configure the Collector as an AgentProxy" on page 138.nLicens

Seite 48 - Migration Process

Option DescriptionnIgnore untrusted SSL Certificate: Connection allowed even whencertificates are not verified as trusted.4. On the Important page, re

Seite 49 - Environment

Option DescriptionServers passes the SSH and Web Services user information to the target machines.Configure ESXiServers Passes the Web Services to th

Seite 50 - 50 VMware, Inc

You can monitor the collection job in Job Manager. When the collection is completed, the data is availablefor reports and compliance assessments.What

Seite 51 - VMware, Inc. 51

PrerequsitesnVerify you are using VMware vCenter 4 Server.nVerify the VMware vSphere Client is installed.nVerify the VMware Tools are installed on the

Seite 52 - Upgrade Process

Procedure1. Select Administration > Settings > Integrated Products > VMware > vSphere Client VCM Plug-In.2. Select the setting you want to

Seite 53 - After You Upgrade VCM

PrerequisitesUnregister the previous version of the vSphere Client VCM Plug-In. See "Unregister the Previous Versionof the vSphere Client VCM Plu

Seite 54 - 54 VMware, Inc

HTTPS/SSL Is Not Configured on the CollectorIf the VCM Summary and VCM Actions tabs are not displayed, the settings are improperly configured.ProblemI

Seite 55 - VMware, Inc. 55

vCenter Configuration Manager Installation and Getting Started Guide148 VMware, Inc.

Seite 56 - 56 VMware, Inc

Getting Started with VCM Remote8Getting Started with VCM RemoteGetting Started with VCM RemoteMany workstations come and go from the network. This tra

Seite 57 - ESX 2.5 5.1.3

Understand Tools InstallationSeveral tools are installed with automatically VCM. These tools include:nFoundation CheckernImport/Export Tool and Conten

Seite 58 - 58 VMware, Inc

Before Collecting Remote DataBegin using VCM Remote by following the steps outlined below. For more information, click any step tojump to the related

Seite 59 - VMware, Inc. 59

The VCM Remote Client can be installed using any of several methods, including a manual installation(provided below), "Installing the Remote Clie

Seite 60

4. Accept the default installation location, or click Change to enter a different location. Click Next.5. Type the name of the Collector machine and t

Seite 61 - Understanding User Access

7. Configure or select one of the following certificate options:nIf you copied the VCM-generated Enterprise certificate to the CM Remote Client, to lo

Seite 62 - Starting and Logging Onto VCM

msiexec.exe /qn /i "[path]\cm remote client.msi" COLLECTOR="YourCollectorName"PATHTOASP="VCMRemote/ecmremotehttp.asp" IN

Seite 63 - VMware, Inc. 63

1. On your VCM Collector, copy ...\VMware\VCM\AgentFiles\CM Remote Client.msito...\VMware\VCM\WebConsole\L1033\Files\Remote_Command_Files.2. On your V

Seite 64 - Portal Toolbar

sAddRemove = 1 'Whether or not VCM remote should appear in the Add/Removeprograms List, should be 0 = hide, 1 = showsMSIPackageName = "CM Re

Seite 65 - VMware, Inc. 65

sVirDir = Trim(sVirDir)End IfIf sInstallDir = "" ThensInstallDir = "c:\vcm remote client"ElsesInstallDir = Trim(sInstallDir)End If

Seite 66 - Select: If you want to:

nRun Action now: This option immediately installs VCM Remote Client on the target machines.nSchedule the Action to run later: This option allows you t

Seite 67 - Where to Go Next

1. In VCM, click Administration > Settings > General Settings > VCM Remote. The default selection forthe Broadband, Dialup, and LAN collectio

Seite 68 - 68 VMware, Inc

The Local System account named NT AUTHORITY\System has unrestricted access to all local systemresources. This account is a member of the Windows Admin

Seite 69

vCenter Configuration Manager Installation and Getting Started Guide160 VMware, Inc.

Seite 70 - 70 VMware, Inc

Getting Started with VCM Patching9Getting Started with VCM PatchingVCM Patching for Windows and UNIX/LinuxVCM Patching is the VCM patch assessment, de

Seite 71 - VMware, Inc. 71

VCM Patching for UNIX/LinuxVCM Patching for UNIX/Linux provides several features that help you deploy patches to remediateUNIX/Linux machines:nBulleti

Seite 72 - Discovering Windows Machines

Getting Started with VCM PatchingVMware, Inc. 163

Seite 73 - VMware, Inc. 73

vCenter Configuration Manager Installation and Getting Started Guide164 VMware, Inc.

Seite 74 - 74 VMware, Inc

10Getting Started with VCM PatchingYou can use VCM Patching to assess the state of managed Windows and UNIX/Linux machines anddeploy patches to those

Seite 75 - Licensing Windows Machines

VCM displays a dialog box communicating the status of your request. Follow the prompts to updateyour bulletins, force an update to the bulletins, or c

Seite 76 - 76 VMware, Inc

6. Review all of the bulletins to include in the assessment template.7. To create a template that includes all of the bulletins for patches to deploy,

Seite 77 - VMware, Inc. 77

select Enable/Disable Summary to enable the Summary view, and click the template node again.The Summary view displays a graph of the patch status for

Seite 78 - 78 VMware, Inc

12. Click Next to either schedule the deploy job or to instruct VCM Patching to execute the jobimmediately.13. On the Reboot Options page, select to n

Seite 79 - VMware, Inc. 79

To be valid, a Collector certificate must be:nLocated in the local machine personal certificate store.nValid for Server Authentication. If any Enhance

Seite 80 - 80 VMware, Inc

PrerequisitePlace patch bulletin files on the local machine to load the bulletin updates from a local file.Procedure1. Select Patching > UNIX/Linux

Seite 81 - VMware, Inc. 81

nThe VCM Agent must be installed on the machine.nThe machine must be licensed for VCM Patching.nIf you choose Filters in the following procedure, you

Seite 82 - 82 VMware, Inc

Procedure1. Select Patching > UNIX/Linux Platform > Assessment Results > All Bulletins to display the patchstatus of all of the machines that

Seite 83 - VMware, Inc. 83

Machine Group MappingWhen you define an alternate patch location for a particular machine group, you must select that machinegroup in VCM before you d

Seite 84 - 84 VMware, Inc

9. On the Patch Deployment Schedule page, set the timing for the patch deployment job.10. On the Reboot Options page, select the options to reboot the

Seite 85 - VMware, Inc. 85

Customize Your Environment for VCM PatchingPerform routine maintenance on your VCM configuration management database to fine-tune the visibilityof con

Seite 86 - 86 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide176 VMware, Inc.

Seite 87 - VMware, Inc. 87

Getting Started with Operating System Pro-visioning11Getting Started with Operating SystemProvisioningOperating system (OS) provisioning is the proces

Seite 88 - 88 VMware, Inc

Provision Machines WorkflowThe process of provisioning operating systems to target machines includes the following general tasks,underlying actions, a

Seite 89 - VMware, Inc. 89

5. Reboot the target machines. As each machine requests an IP address from the DHCP server and thenrequests a PXE boot, OS Provisioning Server checks

Seite 90 - Job Status Reporting for WCI

nThe Collector Certificate is used to initiate and secure a TLS communication channel with an HTTPAgent. The Agent must be able to establish that the

Seite 91 - Running Reports

Alternately, you can manually add machines to the list rather than use the OS Provisioning Serverdiscovery process. To manually add machines, select A

Seite 92 - 92 VMware, Inc

8. (Optional) (Available only for Windows, Red Hat, and SUSE Linux Enterprise Server) On the Post-install Script page, type a Script Name and the scri

Seite 93 - VMware, Inc. 93

Change Agent CommunicationThe VCM Agent is installed by the OS Provisioning Server with default settings. After the machine isprovisioned, you can cha

Seite 94 - 94 VMware, Inc

NOTE Static IP addressing is recommended when deploying ESX or ESXi hosts. If DHCP is used, theESX or ESXi machine’s host name will be set to localhos

Seite 95 - VMware, Inc. 95

vCenter Configuration Manager Installation and Getting Started Guide184 VMware, Inc.

Seite 96

Getting Started with Software Provisioning12Getting Started with Software ProvisioningIntroduction to VCM Software ProvisioningSoftware provisioning i

Seite 97 - Adding UNIX/Linux Machines

Software Provisioning Component RelationshipsThe following diagram displays the general relationship between Package Studio, repositories, andPackage

Seite 98 - Licensing UNIX/Linux Machines

nSoftware Repository for Windows: Installed on at least one Windows machine in your environment,and installed on the same machine with Package Studio.

Seite 99 - VMware, Inc. 99

PrerequisitesnTo uninstall the application, you must use the same version of the Repository.msi that was used toinstall the application.Procedure1. Co

Seite 100 - 100 VMware, Inc

PrerequisitesnTarget machine meets the supported hardware requirements, operating system, and softwarerequirements. See VCM Hardware and Software Requ

Seite 101 - VMware, Inc. 101

For more information about Installing the Agent on UNIX/Linux Machines and UNIX/Linux packages andplatforms, refer to section Installing the VCM Agent

Seite 102 - 102 VMware, Inc

Install Package Manager on Managed MachinesThe Package Manager is automatically installed on target machines when the 5.3 VCM Agent or later isinstall

Seite 103 - VMware, Inc. 103

Creating PackagesA software package provides the files and metadata necessary to install and remove programs. One of themost useful features of a pack

Seite 104 - 104 VMware, Inc

a. Click Add Platforms to add a platform.b. Select a platform, and then click Add Sections.c. Select a section, and then click Publish Package.d. Sele

Seite 105 - VMware, Inc. 105

nYou have created software provisioning packages using VMware vCenter Configuration ManagerPackage Studio and published the packages to the repositori

Seite 106 - 106 VMware, Inc

8. Review the information, resolve any conflicts, and then click Finish. You can monitor the process inthe Jobs Manager. See "Viewing Provisionin

Seite 107 - VMware, Inc. 107

Install PackagesThe process of installing packages includes identifying and processing dependencies and conflicts, runningany specified prescripts, ru

Seite 108 - 108 VMware, Inc

Related Software Provisioning ActionsYou can use the following management options in VCM when working with software provisioning:nJob Manager: Display

Seite 109 - VMware, Inc. 109

In this example the Compliance rule checks whether the source, where platform=Any and section=Release,was added to selected Package Managers as a sour

Seite 110 - 110 VMware, Inc

In this example, you want to determine if a software application named XSoftware is correctly installed. Ifthe software is installed correctly, a serv

Seite 111 - Adding Mac OS X Machines

21. Select one of the following Security Options:This option determines if a package is installed or removed based on the state of the signature. Sele

Seite 112 - Licensing Mac OS X Machines

CopyrightYou can find the most up-to-date technical documentation on the VMware Web site at:http://www.vmware.com/support/The VMware Web site also pro

Seite 113 - VMware, Inc. 113

Cryptography used in VCM Software ComponentsVCM uses various software components that also use cryptography. Microsoft IIS, Internet Explorer, andSCha

Seite 114 - 114 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide200 VMware, Inc.

Seite 115 - VMware, Inc. 115

Getting Started with VCM ManagementExtensions for Assets13Getting Started with VCM ManagementExtensions for AssetsGetting Started with VCM Management

Seite 116 - 116 VMware, Inc

3. Consider whether the fields are listed in the order in which you want them to appear in the Console. Ifnot, click Column Order in the data grid vie

Seite 117 - VMware, Inc. 117

2. Click VCM Devices or Other Devices, depending on the type of field you want to delete.3. If you are editing an existing field, select the field, an

Seite 118 - 118 VMware, Inc

1. Click Administration > Settings > Asset Extension Settings > Hardware Configuration Items.2. Click VCM Devices or Other Devices, depending

Seite 119 - VMware, Inc. 119

5. If you have defined this field as a lookup, the wizard prompts you to define or edit the lookup values.Enter the required information, and then cli

Seite 120 - 120 VMware, Inc

4. Select the fields to edit, and then click Next.5. Enter a value for each of the fields displayed, and then click Next.6. Confirm your change, and t

Seite 121 - VMware, Inc. 121

NOTE If you want to change only the values for that device, and not the device name or descriptionitself, click Edit Values, instead of Edit. The Edit

Seite 122 - 122 VMware, Inc

1. Select the record, and then click Delete.2. Click OK to confirm your deletion. VCMMXA deletes the requested record from the SoftwareConfiguration I

Seite 123 - VMware, Inc. 123

Getting Started with VCM Service DeskIntegration14Getting Started with VCM Service DeskIntegrationGetting Started with Service Desk IntegrationVCM Ser

Seite 124 - Discovering Oracle Instances

Installing VCM2Installing VCMUse Installation Manager to install VCM and all of its components and tools.To install only the VCM tools, follow the ins

Seite 125 - VMware, Inc. 125

Service Desk Integration in Job ManagerWhen VCM Service Desk Integration is licensed and activated, it suspends any requested change to aVCM-managed m

Seite 126 - 126 VMware, Inc

NOTE Jobs for VCM Patching-managed machines appear in the Patching Job Manager, not the VCM JobManager. Locate these jobs at: Patching > Administra

Seite 127 - VMware, Inc. 127

vCenter Configuration Manager Installation and Getting Started Guide212 VMware, Inc.

Seite 128 - 128 VMware, Inc

Getting Started with VCM for Active Direc-tory15Getting Started with VCM for ActiveDirectoryVCM for Active Directory (AD) collects AD objects across D

Seite 129 - VMware, Inc. 129

Confirming the Presence of DomainsPrior to setting up VCM for Active Directory, you must confirm that all fully-qualified DNS Domains thatyou want to

Seite 130 - 130 VMware, Inc

Adding and Assigning Network Authority AccountsBefore you can perform any type of action (Discovery, Collection, and so forth), the Collector must gai

Seite 131 - VMware, Inc. 131

4. Select By Browse List, then click Next. The Discovery Filters page appears.5. Select Only discover machines in the Browse List that match these cri

Seite 132 - 132 VMware, Inc

Verifying Domain Controller Machines in Available MachinesOnce your Domain Controller discovery is completed, verify that your Domain Controllers are

Seite 133 - VMware, Inc. 133

9. Verify the method used for communication. The default communication method is DCOM. For mostVCM for Active Directory configurations, the default va

Seite 134 - ESX/ESXi Server Collections

4. Click the Tools tab.5. In the Tool Name list, select Disable UAC.6. Click Launch. A Command window displays the running action. When the command is

Seite 135 - Prerequisites

1. Select one of these options:nRun Installation Manager. Starts Installation Manager and begins the installation.nView Help. Displays the Installatio

Seite 136 - Procedure

7. On the Domains/OUs tab, select the domain/OU to which the target machines belong, and then clickOK.8. On the Select Group Policy Object dialog box,

Seite 137 - Collect vCenter Server Data

IMPORTANT Click Administration > Job Manager > History > Instant Collections > Past 24 Hours toverify that all jobs have completed before

Seite 138 - Solution

NOTE VCM for AD will operate with only a single domain controller configured with VCM for AD asboth the FDS/RDS (Forest Data Source/Replication Data S

Seite 139 - VMware, Inc. 139

6. Upon completing the Setup DCs action, a collection will be submitted to the selected DCs. Forestinformation will be displayed in the Administration

Seite 140 - Option Description

3. Select a Forest Data Source (FDS) for each Forest to be managed in VCM for Active Directory, andthen click Next. The Select the Replication Data So

Seite 141

Performing an Active Directory Data CollectionYou are now ready to perform your first collection of Active Directory objects using the same collection

Seite 142

NOTE The delta collection feature makes subsequent collections run faster and more efficiently thanthe initial collection. For the initial collection,

Seite 143 - VMware, Inc. 143

11. Expand the Enterprise tree, and then select an AD Location.12. Click OK, to close the page.13. On the Location page, click Next.14. Click Finish.I

Seite 144

Note that several other Active Directory Dashboards are available. Take time to familiarize yourself withthe remainder of the VCM for AD Dashboards.Ac

Seite 145

NOTE The default view is the Summary Report. At any time, however, you may switch the default viewto go directly to the data grid by using the Enable/

Seite 146

Installing and Configuring the OS Pro-visioning Server and Components3Installing and Configuring the OSProvisioning Server and ComponentsThe Operating

Seite 147 - VMware, Inc. 147

Active Directory ReportsAn alternative way to view your collected AD data is by running VCM Reports or creating your owncustom reports using VCM’s rep

Seite 148 - 148 VMware, Inc

Accessing Additional Compliance Content16Accessing Additional Compliance ContentVMware provides several additional VCM Compliance Content Packages rel

Seite 149 - Workflow Diagram

If the particular Content Package(s) you have imported contains filter sets, they will appear underAdministration > Collection Filters > Filter

Seite 150 - Before Collecting Remote Data

Installing and Getting Started with VCMTools17Installing and Getting Started with VCMToolsSeveral VCM components and tools were automatically installe

Seite 151 - VMware, Inc. 151

The VCM tool or tools are now installed on this machine. Proceed to the following sections in this chapterto get started using the tools.NOTE The VCM

Seite 152 - 152 VMware, Inc

IMPORTANT Use of the CLI should be restricted to advanced users who exercise caution when testing outtheir scripts.Import/Export and CW were automatic

Seite 153 - VMware, Inc. 153

NOTE VMware recommends that you refer to Import/Export Help to gain a thorough understanding ofthe logging of Content that is not imported by Import/E

Seite 154 - 154 VMware, Inc

Maintaining VCM After Installation18Maintaining VCM After InstallationAfter you have performed the initial setup and familiarized yourself with VCM an

Seite 155 - VMware, Inc. 155

In addition to several general global settings, these components have specific settings that should beconsidered if you licensed the component.nAsset

Seite 156 - 156 VMware, Inc

Configure Database File GrowthAfter VCM is installed, the installer creates a single 2GB data file and a 1GB log file. As data is added toVCM through

Seite 157 - VMware, Inc. 157

Procedure1. Mount the VCM-OS-Provisioning-Server-<version number>.iso by either attaching to the media imageor mounting the image.When mounting

Seite 158 - 158 VMware, Inc

Configure Database Recovery SettingsSQL Server supports these recovery models, which you can set differently for each database:nSimple. In Simple reco

Seite 159 - VMware, Inc. 159

2. Open the Management folder, right-click Maintenance Plans and select Maintenance Plan Wizard.3. Click Next. The Select Plan Properties page appears

Seite 160 - 160 VMware, Inc

4. Enter a maintenance plan name, select Single schedule for the entire plan or no schedule, and clickChange.5. In the Job Schedule Properties - Maint

Seite 161 - VCM Patching for Windows

7. On the Select Maintenance Tasks page, select the maintenance tasks to be performed, including CheckDatabase Integrity, Rebuild Index, Update Statis

Seite 162 - Minimum System Requirements

9. On the Define Database Check Integrity Task page, click the Databases drop down menu and select theCSI_Domain, VCM, VCM_Coll, VCM_Raw, and VCM_UNIX

Seite 163 - VMware, Inc. 163

10. On the Define Rebuild Index Task page, specify how the Maintenance Plan should rebuild the Index.Click the Databases drop down menu, select the CS

Seite 164 - 164 VMware, Inc

11. On the Define Update Statistics Task page, specify how the Maintenance Plan should update thedatabase statistics. Click the Databases drop down me

Seite 165

13. On the Select Report Options page, select Write a report to a text file, specify the folder location tosave a record of the maintenance plan actio

Seite 166

15. When the Maintenance Plan Wizard completes, verify that the actions were successful.16. To view, save, copy, or send the report, click Report and

Seite 167 - Prerequisite

Troubleshooting Problems with VCMATroubleshooting Problems with VCMThis chapter provides important information that will help you troubleshoot issues

Seite 168

# su - fsrepo[fsrepo@<machine name>~]$ create-repository11. When the action completes, run the [fsrepo@<machine name>~]$ exit command.If n

Seite 169

oSupport for additional UNIX platforms was added in 5.1, along with the automateddistribution of bulletin information to Agent machines.nThe process o

Seite 170

1. Open a command prompt.2. Navigate to the C:\Program Files (x86)\VMware\VCM\AgentData\protected directory, anddelete these files: ECMv.csi.pds and E

Seite 171

1. Log into VCM and select Administration > Settings > General Settings > Database.2. In the Database settings, click to highlight the settin

Seite 172 - Store the UNIX Patches

Index%%Systemroot% environment variable 79AAbout Patching 161about this book 11access by user 61accessingcompliance content 231accountapplication serv

Seite 173

collection resultsAD 227Oracle 129Remote 159UNIX/Linux 107virtualization 143collection scriptscustom for WCI 93collection user accountcreating, Config

Seite 174 - Running VCM Patching Reports

collection resultsOracle 129UNIX/Linux 107virtualization 143Windows 84imported content 231Remote collection results 159Ffilter setsimported content 23

Seite 175 - VMware, Inc. 175

collection 119collection results 121licensing 112maintenanceafter installation 237backup/disaster recovery plan 248configure database file growth 239c

Seite 176 - 176 VMware, Inc

assets 208Oracle 129Service Desk 211registeringvSphere Client Plug-in 59, 143, 145remediationcompliance rulesoftware provisioning 197Remotecollection

Seite 177 - Provisioning

check for Windows 165updatingIIS settings 251virtual directory 251upgrading 45agent 53agent proxy 57agent proxy manually 58automatic 54failed, trouble

Seite 178 - Provision Machines Workflow

Whether you use a private provisioning network or a shared network you can use either the OSProvisioning Server DHCP server or a separate DHCP server;

Seite 179 - Collect OS Distributions

3. On the corporate DHCP server, update the dhcpd.conf file with the following options:allow bootp;allow booting;next-server <IP address of the OS

Seite 180 - Provision Machines

[Thu Jul 22 08:57:08 IST 2010] UNINSTALL-ME: Command : /sbin/service FastScalestopShutting down FSnetfs: [ OK ]Shutting down FSsyslog: [ OK ]Shutting

Seite 181 - Post-Provisioning Action

Option DescriptionProvisioningServerPublic IP><OSProvisioningServerPrivate IP>OS Provisioning Server's Private Interface IP Address. The

Seite 182 - Re-Provision Machines

ContentsUpdated Information 9About This Book 11Preparing for Installation 13Use Installation Manager 14Understand Installation Configurations 14Unders

Seite 183

For example, # cp -R /media/cdrom/Win2003-R2-SP2-Standard /tmp/Win2003-R2-SP2-Standard3. Replace the first CD with the second CD and type:# cp -R /med

Seite 184 - 184 VMware, Inc

8. The script runs as follows with a specific example:Importing data into repository...Importing source data...No recipes are accessible.Adding new re

Seite 185 - Package Manager for Windows

7. The script runs as follows:Importing data into repository...Importing source data...No recipes are accessible.Adding new recipe ESX4.0ulBasicRecipe

Seite 186 - 186 VMware, Inc

nAll private keys are RSA keys.nCertificates are created or obtained, and copied to the required locations using industry best practices.nOn the VCM C

Seite 187

; The hash can be obtained with the command: openssl x509 -noout -incert.pem -hashCApath = /opt/FastScale/var/certsclient = noforeground = nooutput =

Seite 188 - Install Package Studio

Procedure1. Place the VCM Stunnel certificate in[C:]\Program Files (x86)\VMware\VCM\Tools\sTunnel\certs\vcm_stunnel_cert.pem.2. Place the VCM Stunnel

Seite 189

;; verify = level;; level 1 - verify peer certificate if present;; level 2 - verify peer certificate;; level 3 - verify peer with locally installed ce

Seite 190

Procedure1. From the VCM Collector, start Internet Explorer and go to http://localhost:21307/.If the connection is properly configured, the following

Seite 191 - Creating Packages

Procedure1. Log in as the fsrepo user.# su - fsrepo2. Run the backup command to backup the repository files to /temp/fs-backup.[fsrepo@localhost~]$ mk

Seite 192

[fsrepo@localhost~]$ db2 CONNECT RESET;[fsrepo@localhost~]$ db2 RESTORE DATABASE FSREPO FROM /tmp/fs-backup TAKEN AT<timestamp> WITH 2 BUFFERS B

Seite 193 - VMware, Inc. 193

vCenter Configuration Manager Installation and Getting Started GuideUpgrade and Migration Scenarios 45Prerequisites 46Back up Your Databases 47Back up

Seite 194 - 194 VMware, Inc

key = /opt/FastScale/var/certs/private/service.key; Either CAfile or CAPath, but not both, should be defined; CAfile = /opt/FastScale/var/certs/ca-cer

Seite 195 - Install Packages

PrerequisitesnBefore placing the VCM Stunnel certificate and the VCM Stunnel private key, you must ensure thefiles are secured according to your corpo

Seite 196 - 196 VMware, Inc

;; cert (the first 4 bytes of the MD5 hash in least significant byte order).;; The hash can be obtained with the command: openssl x509 -noout -in cert

Seite 197 - VMware, Inc. 197

PrerequisitesnConfigure Stunnel on the OS Provisioning Server as described in "Configure Stunnel on the OSProvisioning Server " on page 39.n

Seite 198 - 198 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide44 VMware, Inc.

Seite 199 - Further Reading

Upgrading or Migrating vCenter Con-figuration Manager4Upgrading or Migrating vCenterConfiguration ManagerWhen you migrate vCenter Configuration Manage

Seite 200 - 200 VMware, Inc

PrerequisitesVCM 5.4 now supports 64-bit environments only, which include 64-bit hardware, a 64-bit operatingsystem, and SQL Server 2008 R2. If you mi

Seite 201 - Extensions for Assets

Back up Your DatabasesBack up all of the databases used in your configuration. Depending on which version you migrate, thedatabase names differ slight

Seite 202 - View Available Fields

Migration ProcessYou can migrate these environments to support VCM 5.4:n"Migrate a 32-bit environment running VCM 5.3 or earlier to VCM 5.4"

Seite 203 - VMware, Inc. 203

Replace your existing 32-Bit Environment with the Supported 64-bitEnvironmentA 32-bit environment must be functional before you migrate to VCM 5.4. Be

Seite 204 - 204 VMware, Inc

ContentsGetting Started with VCM for Mac OS X 110Adding Mac OS X Machines 111Licensing Mac OS X Machines 112Installing the Agent on Mac OS X Machines

Seite 205 - Editing Values for Devices

Migrate a 32-bit environment running VCM 5.3 or earlier to VCM 5.4Your 32-bit environment must be functional before you migrate to VCM 5.4.CAUTION Bef

Seite 206 - Modifying Other Devices

For information about the sp_changedbowner stored procedure, see SQL Server 2008 R2 Books Online.Migrate a 64-bit environment running VCM 5.3 or earli

Seite 207 - VMware, Inc. 207

11. During the installation, do not select SSL unless your machine is already configured for SSL.12. After the upgrade completes, copy the contents of

Seite 208

To upgrade to VCM 5.4:1. Upgrade the operating system to Windows Server 2008 R2.2. Uninstall the 32-bit version of SQLServer Reporting Services (SSRS

Seite 209 - Integration

nWill fail for any machine on which an Agent does not already exist.nWill use an Agent's current settings. For example, if the Agent uses DCOM, t

Seite 210 - 210 VMware, Inc

Platforms Not Supported for Upgrade to 5.4 AgentInstalling or upgrading on the following platforms is supported only to the 5.1.3 UNIX Agent. You cani

Seite 211

To Upgrade the UNIX Agent(s) with a Remote PackageThis method sends the upgrade package with the remote command to execute on the UNIX machine. Thefol

Seite 212 - 212 VMware, Inc

CAUTION When upgrading VCM for Virtualization, take the following precautions:Do not change the password for the CSI Communication Proxy service. Doin

Seite 213 - Directory

7. Click Next. The Important page appears. Review the contents, click Back to make any necessaryalterations.8. Click Finish. The Agent Proxy is upgrad

Seite 214 - 214 VMware, Inc

6. The installer proceeds with the installation. When the VCM Windows Agent has been successfullyinstalled, click Finish.7. Copy the following executa

Seite 215 - VMware, Inc. 215

vCenter Configuration Manager Installation and Getting Started GuideRunning VCM Patching Reports 174Customize Your Environment for VCM Patching 175Get

Seite 216 - 216 VMware, Inc

Procedure1. Go to https://vCenter machine name/mob/?moid=ExtensionManager.vCenter machine name represents the name of your vCenter Server 4.0 instance

Seite 217 - VMware, Inc. 217

Getting Started with VCM Componentsand Tools5Getting Started with VCM Components andToolsThis chapter covers global getting started procedures for VCM

Seite 218 - 218 VMware, Inc

All VCM user accounts must have the following rights on the VCM Collector machine:nAbility to log on locally to access IIS.nRead access to the System3

Seite 219 - VMware, Inc. 219

2. Depending on your browser security settings, you may have to supply your user network credentials.3. (Optional) Select Automatically log on using t

Seite 220 - 220 VMware, Inc

General Information BarThe general information bar displays the VCM Collector’s (active SQL Server) name, your VCM username and active Role, and these

Seite 221 - VMware, Inc. 221

The Copy button is used to copy information from the selected rows in the data gridto the clipboard.The Copy link to clipboard button is used to copy

Seite 222 - 222 VMware, Inc

Select: If you want to:nView Active Directory Group Policy Container Settings.nView information about Active Directory Domains, DCs, and Trusts.nTrack

Seite 223 - Running the Setup DCs Action

Where to Go NextYou are now ready to proceed to Getting Started with VCM to start using VCM and all of its componentsand tools.After you have complete

Seite 224 - 224 VMware, Inc

vCenter Configuration Manager Installation and Getting Started Guide68 VMware, Inc.

Seite 225 - VMware, Inc. 225

Getting Started with VCM6Getting Started with VCMBefore you can begin using VCM to manage the machines in your enterprise, you must complete thefollow

Seite 226 - 226 VMware, Inc

ContentsMaking VCM Aware of Domain Controllers 213Confirming the Presence of Domains 214Adding and Assigning Network Authority Accounts 215Discovering

Seite 227 - Active Directory Dashboards

If the Windows machines that you want to manage belongs to a domain that is not shown in this list, thenyou must add that domain manually. Click Add,

Seite 228 - 228 VMware, Inc

1. Click Administration > Settings > Network Authority > Available Accounts.2. If you need to add a new account, click Add and follow the pro

Seite 229 - VMware, Inc. 229

The following procedure illustrates how to assign Network Authority to accounts by NetBios domain.However, you can also assign Network Authority by Ac

Seite 230

Your initial discovery can take anywhere from one afternoon to a couple of days, depending on the size ofyour network. You may not have a 100% success

Seite 231 - VMware, Inc. 231

3. Type a Name and Description for this new Discovery Rule, then click Next. The Discovery Methodpage appears.4. If you have Active Directory in your

Seite 232 - 232 VMware, Inc

8. Create the filter. For more specific filtering of machines for discovery and other advanced features,refer to the online Help. Click Next. The Impo

Seite 233 - Installing the VCM Tools Only

VCM requires that you specify the machines you want to manage. Remember, the number of licenses youhave purchased may not match the number of machines

Seite 234 - Foundation Checker

4. Leave the Install VCM Agents for the selected machines box unchecked during your first pass atlicensing machines. Once you have more experience lic

Seite 235 - VCM Import/Export

3. Click Install and follow the prompts.NOTE To use advanced options such as HTTP communication for your agent, or to deploy the agentfrom an alternat

Seite 236 - Content Wizard

1. On your Collector, navigate to the Agent files directory at:C:\Program Files (x86)\VMware\VCM\AgentFiles2. Locate the CMAgentInstall.exe file, and

Seite 237 - VMware, Inc. 237

vCenter Configuration Manager Installation and Getting Started Guide8 VMware, Inc.

Seite 238 - 238 VMware, Inc

NOTE For Vista, Windows7, and Windows 2008 only: If you set compatibility mode on any Agentexecutables to a prior version of Windows, the operating sy

Seite 239 - VMware, Inc. 239

nPORTNUMBER: Installs the Windows Agent on the port number specified, using HTTP instead ofDCOM. For HTTP installs, where PORTNUMBER is set, you must

Seite 240 - 240 VMware, Inc

8. Restart the machine to apply the changes.9. Install the Agent as specified in Licensing and Deploying the VCM Agent.10. After installing the Agent

Seite 241 - VMware, Inc. 241

Performing an Initial CollectionYou are now ready to collect data. VMware recommends using the default filter set, which collects ageneral view of the

Seite 242 - 242 VMware, Inc

5. For initial collections, there should be no conflicts with previously scheduled or running jobscontaining the same data types. Click Finish.6. Veri

Seite 243 - VMware, Inc. 243

1. Begin by looking at the Windows Operating Systems Dashboard under Console > Dashboards >Windows > Operating Systems.2. Note that several o

Seite 244 - 244 VMware, Inc

4. When you select the node, you will see a Summary Report as displayed above of the data class thatyou selected. Click View Data Grid to go directly

Seite 245 - VMware, Inc. 245

TIP The default view is the Summary Report; however, at any time you may switch the defaultview to go directly to the data grid by using the ’Enable/D

Seite 246 - 246 VMware, Inc

Getting Started Collecting Windows Custom InformationAs a System Administrator, you can extend the data that VCM can collect by using a script, which

Seite 247 - VMware, Inc. 247

nYou must obtain or write a PowerShell script that will return data in a VCM-compatible element-normal XML format.nThe VCM agent (for VCM 5.3 or later

Seite 248 - 248 VMware, Inc

Updated InformationUpdated InformationVCM Installation and Getting Started Guide is updated with each release of the product or when necessary.This ta

Seite 249 - VMware, Inc. 249

11. Click Next and then Finish.12. Run a collection using your new collection filter.13. Ensure the job completes.14. View data in the Custom Informat

Seite 250 - To Resolve the Problem

The Job History Machine Detail view displays a single row for each WCI filter included in the collectionjob. These rows provide information about the

Seite 251 - VMware, Inc. 251

Executing PowerShell ScriptsPowerShell contains built-in policies, which limit its use as an attack vector. The primary policy is for scriptexecution.

Seite 252 - 252 VMware, Inc

For additional information about Windows PowerShell and signing scripts, see:nScripting with Windows PowerShell: http://technet.microsoft.com/en-us/sc

Seite 253 - VMware, Inc. 253

nThe default WCI filter returns PowerShell version information from VCM-managed machines.nDo not include any formatting white space. For example, do n

Seite 254 - 254 VMware, Inc

The <schtasks> top-level name is an arbitrary name picked to distinguish the results of this script fromothers. A couple of additional challenge

Seite 255 - VMware, Inc. 255

the task name is used as the element name for task rows, but the “increment” option is selected forduplicate handling when creating a collection filte

Seite 256 - 256 VMware, Inc

Discover, License, and Install UNIX/Linux MachinesThe following steps must be performed before collecting data from UNIX/Linux machines:1. Add UNIX/Li

Seite 257 - VMware, Inc. 257

3. Select Basic, and then click Next. The Manually Add Machines - Basic page appears.NOTE When you expand your UNIX/Linux collections to a broader set

Seite 258 - 258 VMware, Inc

NOTE Remember, discovered machines with an indeterminate Machine Type will not be licensed ifthey are included in your selection.2. Select the machine

Kommentare zu diesen Handbüchern

Keine Kommentare