background image

Cryptography used in VCM Software Components

VCM uses various software components that also use cryptography. Microsoft’s IIS, Internet Explorer,
and SChannel (SSL/TLS) systems also call the CryptoAPI, and thus use the Windows FIPS-validated
modules. VCM for Virtualization uses ActiveX COM components for SSH and SFTP, and for wodSSH,
wodSFTP, and wodKeys (by WeOnlyDo! Software at www.weonlydo.com), which utilize the FIPS-
certified OpenSSL crypto library. wodSSH is used for windowless communication with remote console-
type services in unattended mode on the VCM for Virtualization Agent Proxy’s host, which is a Windows
platform.

System

Platform

OpenSSLFIPS

1.1.2

OpenSSLFIPS

1.1.1

OpenSSLCrypt

0.9.7

+

CryptoAPI

UI

Windows

Used

VCMServer

Windows

Installed

Used

Virt Proxy

Windows

Installed

Used

AD Agent

Windows

Used

Win Agent

Windows

Used

UNIX
Agent

HP/UX

Installed

Installed

AIX

Installed

Installed

Solaris

Installed

Installed

Debian

Installed

Installed

Red Hat

Installed

Installed

SUSE

Installed

Installed

ESX Server

All

No cryptography modules are used or installed on ESX.

Table 1-1. Installed or Used Crytography Modules

Supported Windows and UNIX Platforms

For a list of supported Windows and UNIX platforms, and their architectures, see the

VCM Hardware and

Software Requirements Guide

. For information about TLS, see

Transport Layer Security (TLS) Implementation

for VCM

located on the VMware vCenter download site.

vCenter Configuration Manager Installation and Getting Started Guide

18

VMware, Inc.

Summary of Contents for VCENTER CONFIGURATION MANAGER 5.3

Page 1: ...ter Configuration Manager 5 3 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition To check for more recent ed...

Page 2: ...t is protected by U S and international copyright and intellectual property laws VMware products are covered by one or more patents listed at http www vmware com go patents VMware is a registered trad...

Page 3: ...ows and UNIX Platforms 18 Installing VCM Using Installation Manager 19 Using the Installation Manager 19 Navigating VCM Installation Manager Screens 19 Installing VCM and the Related Components 19 Upg...

Page 4: ...S X Machines 94 Licensing Mac OS X Machines 96 Installing the Agent on Mac OS X Machines 97 Performing a Mac OS X Collection 103 Exploring Mac OS X Collection Results 106 Discover License and Collect...

Page 5: ...ling the Remote Client manually 149 Making VCM Aware of VCM Remote Clients 156 Configuring VCM Remote Settings 156 Creating Custom Collection Filter Sets 156 Specifying Custom Filter Sets in the VCM R...

Page 6: ...dware Configuration Items 200 Editing Values for Devices 200 Modifying Other Devices 201 Adding Software Configuration Items 202 Further Reading 203 Getting Started with VCM Service Desk Integration 2...

Page 7: ...Content Wizard CW 243 VCM Import Export 244 Content Wizard 245 Maintaining VCM After Installation 247 Customize VCM and Component specific Settings 247 Configure Database File Growth 249 Configure Dat...

Page 8: ...vCenter Configuration Manager Installation and Getting Started Guide 8 VMware Inc...

Page 9: ...or system administrators who are experienced Windows or UNIX Linux system administrators and who are familiar with managing network users and resources and performing system maintenance To use the inf...

Page 10: ...ferings To find out how VMware support offerings can help meet your business needs go to http www vmware com support services VMware Professional Services VMware Education Services courses offer exten...

Page 11: ...ty precautions you should take before installing VCM see the VCM Security Environment Requirements Technical White Paper on the VMware vCenter download site This document assumes that your hardware an...

Page 12: ...res described in Using Installation Manager IMPORTANT When upgrading to VCM 5 3 0 be aware that you can use Installation Manager to upgrade from VCM 4 11 1 or later When performing a new installation...

Page 13: ...once it is installed If Foundation Checker returns no errors then you are ready to proceed If your machine s do not meet these requirements the installation cannot proceed If you are installing on HP...

Page 14: ...st also change the password in both the Services Management and Component Services DCOM Config consoles To change your services password in the Services Management console click Administrative Tools S...

Page 15: ...ctor or Collectors through the use and verification of certificates over HTTP Typically the server authenticates a client user by requiring information such as a user name and password When server aut...

Page 16: ...sted certificate In most cases VCM will deliver and install the Enterprise Certificate as needed n Installing the Agent from a Disk Windows only The VCM Installation DVD does not contain customer spec...

Page 17: ...n FIPS 46 3 Data Encryption Standard DES n FIPS 81 DES Modes of Operation n FIPS 113 Computer Data Authentication n FIPS 171 Key Management n FIPS 180 1 Secure Hash Standard SHA 1 n FIPS 186 2 Digita...

Page 18: ...1 1 2 OpenSSLFIPS 1 1 1 OpenSSLCrypt 0 9 7 Crypto CryptoAPI UI Windows Used VCMServer Windows Installed Used Virt Proxy Windows Installed Used AD Agent Windows Used Win Agent Windows Used UNIX Agent H...

Page 19: ...nstallation process Navigating VCM Installation Manager Screens Every VCM Installation Manager screen shows the progress of the installation in the left most pane VCM Installation Manager also has the...

Page 20: ...nager n View the Installation and Getting Started Guide Opens the VCM Installation and Getting Started Guide n Browse Contents of Installation CD Launches Windows Explorer showing the contents of the...

Page 21: ...ck boxes and then click Next The Identify Available and Installed Components page appears It may take a few minutes for Installation Manager to identify which components are available for installation...

Page 22: ...uld be selected Click Next The Gather System Information page appears 6 The Gather System Information displays the status of the Foundation Checker The Foundation Checker reviews the machine s configu...

Page 23: ...f you have only one or two errors do not close the Installation Manager On the Foundation Checker Results Web page review the Errors Click the link associated with the errors you must resolve A brief...

Page 24: ...appears in front of the Verify Components to be Activated page 8 Click Browse to locate the license file provided by VMware When you click OK the Verify Components to be Activated page appears NOTE If...

Page 25: ...rent file If you have selected an invalid or expired license file an error message will appear in a pop up dialog box Click OK and the VCM Specify License Location dialog box appears in which you can...

Page 26: ...istrators recommend that the Data files mdf and the log files ldf be placed on separate physical drives spindles and often require the files to be on a drive or partition other than the OS drive parti...

Page 27: ...ocalhost reports and http localhost reportserver are accessible through a web browser If that fails stop the installation and call VMware Customer Support The Install Collector Components to configura...

Page 28: ...n page appears At this point you will need the Default Network Authority Account Default Services Account and Application Services Account Additionally you will need your Virtual Directory credentials...

Page 29: ...Select or Generate your Collector Certificate configuration page appears 23 Select one of the following options n Select If you already have a pair of certificates with an established trust click Sele...

Page 30: ...the same Agent s or if you plan to replace renew your certificates at a later date there are special considerations for generating and selecting certificates in Installation Manager For more informati...

Page 31: ...rovided here are similar to the credentials used for Application Services providing client access using HTTP 27 Click Next The Install Package Manager Components to the Package Manager folder under pa...

Page 32: ...ion to store packages for distribution to other systems Either change the path or click Next The Virtual Directory page for the Software Repository appears 31 Enter a name for the virtual directory an...

Page 33: ...visioning functionality including creating and publishing packages Either change the path or click Next The Installation Summary page appears 33 Wait for the components to be installed The Installatio...

Page 34: ...t the error When you click OK both the pop up dialog box and Installation Manager close In this case read the information about the error in the installation log capture the log and contact the VMware...

Page 35: ...5 3 0 on a 32 bit System check for the following registry entry and rename or remove it if it exists HKEY_LOCAL_MACHINE SOFTWARE Wow6432node VCM 5 3 0 uses this registry entry to detect whether the s...

Page 36: ...running Windows Server 2003 SP2 64 bit with SQL Server 2005 64 bit and 32 bit SQL Server Reporting Services n Microsoft SQL Server 2005 CAUTION Before upgrading be sure to back up your database s to...

Page 37: ...or details n For 32 bit systems SQL Server 2005 and then install SQL Server 2005 SP3 n For 64 bit systems 64 bit SQL Server 2005 and SQL Server 2005 SP2 and 32 bit SQL Server Reporting Services and SS...

Page 38: ...onents to be installed To continue click Next The Configure Components page appears requesting confirmation of the Default Collector Service Account 8 If the account is changing type the new values If...

Page 39: ...it from the drop down list The Upgrade process n Will fail for any machine on which an Agent does not already exist n Will use an Agent s current settings For example if the Agent uses DCOM the Upgra...

Page 40: ...hen you upgrade to 5 2 0 or later the workstations previously managed with a server licenses will be unmanaged in VCM The unmanaged Red Hat workstations should be listed in the Available UNIX Machines...

Page 41: ...UNIX Machines To determine the latest version number for the Agent select About Versions 10 Click the arrow button to move the machines from the Available list to the Selected list Click Next 11 Sele...

Page 42: ...automatically upgraded and the Agent Proxy protected storage and user account configuration settings are preserved However for existing non Collector Agent Proxy machines you must upgrade VCM for Vir...

Page 43: ...machine name in one of the panes and use the arrow buttons to move it from one pane to the other Additionally you may double click a machine name to move it between panes 5 Click Next The Option page...

Page 44: ...on will allow the Agent to communicate through the HTTP port specified if DCOM is not available Locking an Agent will prevent the Agent from being removed or upgraded To use this mode select Allow HTT...

Page 45: ...o upgrade the vSphere Client VCM Plug in follow these steps 1 Upgrade VCM 2 Manually un register the pre VCM 5 3 version of the Plug in as described in Un register the Previous Version of the Plug in...

Page 46: ...vCenter Configuration Manager Installation and Getting Started Guide 46 VMware Inc...

Page 47: ...D_Admin allows full administration access to AD objects only Other user accounts can then be added after the Admin user logs in by going to Administration User Manager VCM Logins For instructions on h...

Page 48: ...een appears 2 Depending on your browser security settings you may have to supply your user network credentials 3 Optional Select Automatically log on using this role to have VCM automatically log you...

Page 49: ...e global toolbar provides you with easily accessible options to enhance control of your environment and data The left and right arrow buttons navigate to the previous or next page in the data area The...

Page 50: ...notifications n Manage both VCM discovered and non VCM discovered hardware and software assets n Review changes that occurred from one collection to the next n Create edit or run remote commands on a...

Page 51: ...Select machines to license set options for assessment and deployment or monitor VCM Patching jobs n Deploy patches Administration n Manage basic configuration options for VCM n Establish filters to li...

Page 52: ...are has intentionally ordered the instructions in the remainder of this guide such that they build upon one another as you proceed through this guide therefore it is imperative that you proceed in ord...

Page 53: ...ains 2 Checking the Network Authority 3 Assigning Network Authority Accounts 4 Discovering Windows machines 5 Licensing Windows machines 6 Installing the VCM Agent on your Windows machines 7 Performin...

Page 54: ...ract with the Windows machines in your enterprise An account having Domain Administrator rights must be created for each domain that has Windows machines you want to manage An initial account your def...

Page 55: ...for each domain that has machines that you intend to manage through VCM Assigning Network Authority Accounts VCM offers considerable flexibility in assigning Network Authority Accounts to domains and...

Page 56: ...ority Assigned Accounts By Domain and then select NetBios 2 Select a listed domain 3 Click Edit Assigned Accounts and follow the prompts Discovering Windows Machines The discovery process identifies w...

Page 57: ...and all discovered UNIX Linux machines will be placed in the Administration Machines Manager Available UNIX Machines list NOTE A Discovered Machines Import Tool DMIT is available from VMware Customer...

Page 58: ...n initial discovery do not select Also discover the presence and version of the VCM Agent when this rule is run Because the VCM Agent is not present on the machines yet you cannot discover the Agent v...

Page 59: ...Click the Jobs button at the top of the Portal to verify that your discovery job has completed before proceeding to the next step The Jobs Running window appears listing your job name and summary info...

Page 60: ...Data Grid found at Administration Machines Manager Available Machines Available Windows Machines If you need assistance resolving the machine type for machines you plan to license contact VMware Custo...

Page 61: ...licensed Windows machine You can install the VCM Windows Agent through VCM or manually Both methods are described here Machines that will be affected are those that are listed in the Administration Ma...

Page 62: ...ovide the option to uninstall the existing version EXE files can also be used for unattended silent installations n MSI files are database files executed by the Windows MSIEXEC EXE executable which re...

Page 63: ...or WINDOWS Where n CMAgentInstall exe is the executable used to install the Agent n s indicates a silent install which means that popups and menus do not appear When running this command from the comm...

Page 64: ...erating in a full Public Key Infrastructure PKI and the client can validate the Collector root certificate Enterprise Certificate the pem file is not necessary 4 On the target machine double click the...

Page 65: ...ed i parameter Quotation marks are necessary only when a path includes spaces For example when one or more spaces exist in the source file location and the INSTALLDIR parameter The optional parameters...

Page 66: ...in OU to which the target machines belong and then click OK 8 On the Select Group Policy Object dialog box click Finish 9 On the Add or Remove Snap Ins dialog box click OK 10 The domain OU policy is a...

Page 67: ...ctions on a regular basis This ensures that the data you are reporting on is current When performing a full collection on your entire enterprise you may want to run VCM overnight because the collectio...

Page 68: ...Controller PDC of each domain The PDCs have the necessary account information and doing so automatically resolves the SIDs The data types that cause the automatic additional query are User Rights Regi...

Page 69: ...dows Dashboards Windows Collection Results are also available to you in a more raw format by data class This level of reporting is more relevant for day to day operations troubleshooting and analysis...

Page 70: ...above of the data class that you selected Click View Data Grid to go directly to the data grid or click an area of the Summary Report to filter the data before the data grid is displayed vCenter Confi...

Page 71: ...ning Reports or creating your own custom reports using the reporting wizard To begin exploring VCM s Reporting functionality go to the Reports slider then click Machine Group Reports Windows Like Dash...

Page 72: ...arameters relating to the execution of the script and the handling of its results When this filter is used in a collection the VCM agent will call a script engine to run the script and will then parse...

Page 73: ...l execution policy on the VCM machine must be set to Remote Signed All Signed or Unrestricted If the policy is set to All Signed the scripts must be signed and the appropriate certificates distributed...

Page 74: ...ractice because both filters would generate new file and deleted file events each time a new file was added or removed n For an element such as NetStat only one filter should be used n For an element...

Page 75: ...ted with errors status at the collection job level Running Reports Several reports are included for reporting on Windows Custom Information including n Netstat Open Ports Reports port and protocol inf...

Page 76: ...l version NET version and execution policy settings of a system n Script file Requires that the execution policy be set to Remote Signed at the most restrictive since the script is being run from a fi...

Page 77: ...attribute names used must be valid XML when returned by the script If data is to be returned as an element or an attribute name that is not valid for XML the name can be encoded using the ToCMBase64St...

Page 78: ...ommand Viewing the result set by looking at schtasks n shows that that the first line schtasks 0 is blank schtasks 1 contains column names and schtasks 2 is the first row of task data The goal then is...

Page 79: ...oes not include any unique and repeatable identifier for specific task entries For example many test systems observed had more than one task with the name GoogleUpdateTaskMachineCore Unique element na...

Page 80: ...pt runs correctly within PowerShell run the script from a file 1 Save the script to a ps1 file 2 From a command line run the script directly n For PowerShell 2 0 execute PowerShell command set executi...

Page 81: ...IT is available from VMware Customer Support to assist you with the following process This tool imports machines discovered by the Network Mapper Nmap into the configuration database To use the tool c...

Page 82: ...r workstations or servers were licensed as Red Hat servers Beginning with version 5 2 0 Red Hat machines were licensed as either workstations or servers When you upgrade to 5 2 0 or later the workstat...

Page 83: ...ng a custom configuration file perform the installation in Silent Mode Installing the Agent on UNIX Linux machines is a manual operation NOTE A Deployment Tool is available from Customer Support to as...

Page 84: ...3 and 6L 6 1 CMAgent version AIX 5 3 Copy the installation package to the machine on which you want to install the agent You can use ftp sftp or cp using an NFS share NOTE If you use ftp to copy the p...

Page 85: ...customize the settings for the installation variables modify the installation configuration file csi config and then save your changes If this file has only read permissions set you will need to give...

Page 86: ...up to the high security group privileges CSI_CREATE_USER_ PRIMARY_GROUP Y Recommend keeping default value This value indicates the need to create a low security primary group for the CSI_USER CSI_USER...

Page 87: ...llectors collecting from the same set of Agents can be supported If this package was copied from a collector installation this package already contains that Collector s Enterprise Certificate CSI_PARE...

Page 88: ...ig file is modified To run the installation in interactive mode enter CSIInstall InstallCMAgent During the pre installation stage of interactive mode the check for a valid user CSI_USER is performed I...

Page 89: ...the command etc init d xinetd start After you have installed the Agent on the UNIX Linux machines you are now ready to start collecting data from them To do this see Performing a UNIX Linux Collectio...

Page 90: ...MAgent NOTE Consider these points when uninstalling an Agent The uninstall reverses all changes made by installation however the installation log files are retained in AgentRoot install AgentRoot defa...

Page 91: ...conflicts with previously scheduled or running jobs containing the same data types Click Finish 6 Verify that your collection job has completed before proceeding to the next step To do so click the Jo...

Page 92: ...ore raw format as well This level of reporting is more relevant for day to day operations troubleshooting and analysis and can be viewed in a Summary report or data grid format Look at your UNIX Opera...

Page 93: ...of information regarding your UNIX Linux Collection are available under the UNIX tab The UNIX tab is where the remainder of your collected UNIX Linux data is visible through the Portal Reports An alte...

Page 94: ...achines 1 Add Mac OS X machines 2 License your Mac OS X machines 3 Install the VCM Agent on your Mac OS X machines 4 Perform an initial Mac OS X collection 5 Explore the Mac OS X collection results Th...

Page 95: ...hines Basic page appears NOTE When you expand your Mac OS X collections to a broader set of machines you may want to use other methods to add your Mac OS X machines Refer to the online Help for the ad...

Page 96: ...them Licensing Mac OS X Machines When the Mac OS X machines are displayed in your Available UNIX Machines list you may begin licensing these machines Use the following procedure to license your Mac O...

Page 97: ...are using a custom configuration file perform the installation in Silent Mode Installing the Agent on Mac OS X machines is a manual operation The Agent is packaged as a Universal Binary Installer Use...

Page 98: ...options n packages Contains the installation packages n scripts Contains the scripts needed for the install 8 To customize the settings for the installation variables modify the installation configura...

Page 99: ...roup privileges CSI_CREATE_USER_ PRIMARY_GROUP Y Recommend keeping default value This value indicates the need to create a low security primary group for the CSI_USER CSI_USER_PRIMARY_GID 501 Recommen...

Page 100: ...ctors collecting from the same set of Agents can be supported If this package was copied from a collector installation this package already contains that Collector s Enterprise Certificate CSI_PARENT_...

Page 101: ...lation in interactive mode enter CSIInstall InstallCMAgent During the pre installation stage of interactive mode the check for a valid user CSI_USER is performed If the user already exists either the...

Page 102: ...commands will increase slightly The time required will vary based on how much new or updated content needs to by synchronized between the Collector and the agent This content push will happen when th...

Page 103: ...ing your collection instead of Windows data types 1 Click Collect located on the Portal toolbar 2 The Collection Type wizard page appears Select Machine Data and then click OK The Machines page appear...

Page 104: ...nformation n Security Groups n Custom Information subset of CITs n Properties files plist n Machines General n File System File Structure n System Logs syslog events n IP Information General n IP Info...

Page 105: ...Click Finish 6 Verify that your collection job has completed before proceeding to the next step To do so click the Jobs button at the top of the Portal window to access the Jobs Summary NOTE You can...

Page 106: ...uested To view Mac OS data begin by looking at the UNIX Operating System Dashboard under Console Dashboards UNIX Operating Systems Note that several other UNIX Dashboards are also available Take time...

Page 107: ...appears Several other categories called data classes of information regarding your Mac OS X Collection are available under the UNIX tab The UNIX tab is where the remainder of your collected Mac OS X d...

Page 108: ...slider then follow the steps described in the online Help to create rule groups rules filters and templates Discover License and Collect Oracle Data from UNIX Machines Welcome to VCM for Oracle Now th...

Page 109: ...ngine data files containing database metadata control files and log files of data changes for backup and recovery Use this view to add and configure an Oracle Instance on a machine After an Oracle Ins...

Page 110: ...tance Click Next The Configuration Values wizard page appears 3 Check the box next to a configuration value you want to modify See the VCM for Oracle data grid for definitions of these values Click Ne...

Page 111: ...ines For instructions on removing access to the Oracle database see Removing Access to the Oracle Database Setting Account Permissions on Oracle 10g If you will be creating the Oracle Collection User...

Page 112: ...you no longer want to collect from an Oracle database you can remove access to the Oracle database Removing Access to the Oracle Database To remove access to the Oracle database follow these steps 1...

Page 113: ...t the Oracle Collection User account that is created has appropriate access to the required binaries For the Oracle Collection User account to execute SQL Plus you must grant Oracle directories read r...

Page 114: ...l be used in collections of data performed during the discovery process NOTE To limit the amount of data stored in the change log from collections performed using the Oracle Management Views data clas...

Page 115: ...ou want to collect from the machines that VCM manages A default Collection Filter is provided for each data type You can choose to add custom Collection Filters that are specific to your enterprise Fi...

Page 116: ...n logoff session timeouts changes in managing users changes to passwords and administration settings changes in network accounts and authority collection requests and service and registry changes NOTE...

Page 117: ...logical grouping of the configurations of VM Host servers and VM Guests This grouping allows you to view your Virtual Environments at an enterprise level and to drill into the specific details Additi...

Page 118: ...ting from ESXi attempting to collect any data other than VM Hosts or VM Guests data from the ESXi machine will result in a collection failure This includes collection filters supplied with the product...

Page 119: ...Server Configuring Agent Proxy Machines Step 1 Licensing Agent Proxy Machines Step 2 Installing the Agent on the Agent Proxy Machines Step 3 Performing Collections Using the Machines Data Type Step 4...

Page 120: ...ers and to remotely collect data from those servers Using a separate Windows machines as your Agent Proxy is the most effective way to manage the virtualization environments The recommendation to use...

Page 121: ...hines Manager Licensed Machines Licensed Windows Machines 2 In the data grid select your Agent Proxy machine and then click Install The Machines page of the Install Product wizard appears 3 Confirm th...

Page 122: ...1 Click Administration Machines Manager Additional Products vCenter CM for Virtualization Agent Proxies 2 Select the machine or machines on which you are installing the Agent Proxy If your designated...

Page 123: ...ve full control of the Configuresoft registry key HKEY_LOCAL MACHINE Software Configuresoft If keys have already been generated the agentdata protected folder must be deleted and new keys generated up...

Page 124: ...gent Proxy drive Program Files VMware VCM Tools Virtualization machine _ssh_public_key txt Located on the Collector drive Program Files VMware VCM Tools Virtualization csiprep py drive Program Files V...

Page 125: ...n that requires root access from the ESX Service Console Operating System If you have a root access password execute the following in the command prompt su cd directory location of files copied python...

Page 126: ...dentification name including the domain as displayed in the vSphere Virtual Infrastructure Client s Configuration tab DNS and Routing section The name on the ESX Web Server certificate must also match...

Page 127: ...2 Click License The Virtualization Host page of the License VM Host wizard appears 3 The upper pane displays the available machines The lower pane displays the machines to be licensed Double click the...

Page 128: ...he ESX vSphere Servers 9 Confirm that Machines General data was collected by navigating to Console UNIX Operating Systems Machines General Review the data grid and note the versions of your ESX vSpher...

Page 129: ...o access the Web Services interface on the VirtualCenter machine NOTE A Deployment Tool is available from VMware Customer Support to assist you with the following process for ESX 3 x vSphere 4 and ESX...

Page 130: ...he Virtual Infrastructure VI Web Services interface As stated above to collect from ESX 2 5 Servers VCM collects data for those ESX 2 5 Servers from VirtualCenter 2 0 However the VirtualCenter 2 0 out...

Page 131: ...y For example https ESXhost vSpherehost or https VirtualCenterhost vCenterhost box Internet Explorer displays an error message indicating a problem with the security certificate NOTE For older version...

Page 132: ...og box appears with information about the error message 5 Click View certificates at the bottom of this dialog box The Certificate dialog box appears with information about the certificate vCenter Con...

Page 133: ...tes in the following store and then click Browse The Select Certificate Store dialog box appears 8 Click Show physical stores Select Third Party Root Certification Authorities Local Computer Click OK...

Page 134: ...e ready to perform your collection of Virtual Environments data using the same Collection wizard you have previously used for Windows and UNIX Linux Collections In VCM 1 Click Collect on the Portal to...

Page 135: ...em Machines General From here you can view a graphical summary of information about your ESX Servers Click View data grid to view more details in a data grid format NOTE For the full list of UNIX and...

Page 136: ...uding security network and storage information Several other categories of information data types are available under the Virtual Environments node This is where the remainder of your collected virtua...

Page 137: ...ring vCenter Server Data Collections Collecting vCenter Server data is based on a process that is different from the standard collection process This process has several prerequisites that must be in...

Page 138: ...required to register on the VMware Web site http www vmware com support developer PowerCLI index html Configuring PowerShell on the Collector On the Collector machine configure the PowerShell executi...

Page 139: ...o directly to opening the command prompt Select Start Run and then type cmd exe Otherwise perform the following steps a If you are not logged on locally to the Collector machine as the EcmAgtStartup u...

Page 140: ...the files to meet your local needs The cloned files you create are the mechanism used to collect vCenter Server data from the ESX vSphere Server machines The collected data classes in VCM are vCenter...

Page 141: ...the VCM Collector not the vCenter Servers The scripts collect the data and update the VCM database After validating the collection process using one of the methods below you have the option to create...

Page 142: ...click the machine in the Available list to add it to the Selected list 5 Click Next The Schedule page appears 6 Select one of the following schedule options n Run Action now Runs the job immediately w...

Page 143: ...t The vSphere Client VCM Plug in provides contextual access to VCM s change compliance and management functions in addition to direct access to vCenter and Host and Guest dashboards CAUTION Each user...

Page 144: ...ude VCM Summary and VCM Actions You are ready to use the vSphere Client VCM Plug in 8 After confirming you can access the VCM Summary and VCM Actions tabs you must configure the vSphere Client VCM Plu...

Page 145: ...l data collection capabilities to manage Compliance Assessment and Reporting on Virtual Machines commonly managed in the vSphere Client Working with an Invalid Certificate on a vSphere Client When log...

Page 146: ...ough the upgrade to VCM removes files for the previous Plug in and installs the new Plug in files in new locations and with new names it does not register the new Plug in with the vSphere Client To un...

Page 147: ...lector initiates a collection Consider patch management You need up to date information to perform the Assessments to ensure your machines and production networks are protected from the latest vulnera...

Page 148: ...Filter Sets Step 3b Specifying Custom Filter Sets in the VCM Remote Settings Step 4 Performing a Collection Using VCM Remote Step 5 Reviewing the VCM Remote Collection Results Installing the VCM Remot...

Page 149: ...the installation of a Windows VCM base agent in HTTP mode adds the Collector s Enterprise Certificate to the certificate store of the client system and this certificate can also be used by the VCM Rem...

Page 150: ...ame of the machine on which the VCM Collector and Microsoft IIS are installed n Path to ASP Page This path was created in the IIS default web site by the VCM Remote server installation The virtual dir...

Page 151: ...time the Remote Client connects with the Collector it requests a Collector certificate If the Collector certificate is trusted by the Enterprise certificate on the client the Collector certificate is...

Page 152: ...can use SKIP_CERTIFICATE_FILE 1 instead of CERTIFICATE_ FILE YourEnterpriseCertificateName pem IMPORTANT Do not use this option unless you are certain the Enterprise certificate exists in the client c...

Page 153: ...ork Copyright 1999 2010 VMware Inc Coded by Ryan L Description Installs VCM Remote ver 2 Modified 4 27 2008 Stephen S Included Certificate file options Modified 7 7 2010 VCM Dim sCollName sInstallDir...

Page 154: ...AppToRun msiexec exe qn i Chr 34 EcmAgtContext JobDownloadDirectory sMSIPackageName Chr 34 ALLUSERS 1 COLLECTOR Chr 34 sCollName Chr 34 PATHTOASP Chr 34 sVirDir Chr 34 INSTALLDIR Chr 34 sInstallDir C...

Page 155: ...x 10 Click Next The Files page appears 11 Select the CM Remote Client msi file and the pem file then move them to the right box 12 Click Next When you are ready to save the new remote command click Fi...

Page 156: ...n In the VCM Remote settings enter the names of the filter sets to be used for each type of connection See Specifying Custom Filter Sets in the VCM Remote Settings on page 156 for more information Cre...

Page 157: ...the Collector auto license the machine install or upgrade the VCM Windows Agent and determine whether it should submit a VCM Collection job for that machine Exploring VCM Remote Collection Results Co...

Page 158: ...vCenter Configuration Manager Installation and Getting Started Guide 158 VMware Inc...

Page 159: ...for UNIX Patch Assessment results see the online Help Getting Started with VCM Patching for Windows Machines Welcome to VCM Patching for Windows Now that you have installed VCM successfully proceed t...

Page 160: ...job queue When the job completes the content will be available in VCM Collect Data from Windows Machines Using the VCM Patching Filter Sets The next step is to perform a collection VCM Patching requir...

Page 161: ...eferenced by the bulletins need to be installed For example you might create a template containing all of the bulletins related to Internet Explorer 7 to ensure all of the installed copies have the la...

Page 162: ...te VCM Patching Assessment templates n Create a Template Based on a VCM Patching Bulletin n Create a Template based on a Name Create a Template Based on a VCM Patching Bulletin To create a template ba...

Page 163: ...specific product follow these steps 1 Click Patching Windows Bulletins By Affected Product 2 In the middle pane locate and select the product 3 In the data grid VCM displays the bulletins listed by p...

Page 164: ...sment Templates Run the Assessment To complete the VCM Patching assessment you must run the template that you just created IMPORTANT VCM PatchingAssessments are run against the data from every VCM man...

Page 165: ...assessment template and evaluating the results you can deploy security patches on Windows machines that are managed by VCM Patching To view a data grid containing your VCM Patching managed machines cl...

Page 166: ...t to locate the patch or patches through the Internet If access to the Internet is denied locate the patches manually and save them to the collector_ name cmfiles SUM Downloads directory on your Colle...

Page 167: ...ment completes VCM Patching automatically runs a delta collection of the VCM Patching Security Bulletins filter set so that the assessment information is up to date 10 As a final verification step VMw...

Page 168: ...Patching to install the patches on them NOTE Assessments of UNIX Linux based machines operate differently from Windows assessments UNIX assessments require new data to be collected while Windows asses...

Page 169: ...request Follow the prompts to check for updates to bulletins Collect Assessment Data from UNIX Linux Machines You can collect UNIX Linux assessment data in several ways n Using Bulletins n Using a Tem...

Page 170: ...are performed against previously collected data Machine Assessments are Run Against Known Patches Assessments of UNIX Linux machines are run against the patches known by VMware at the time the assess...

Page 171: ...ates navigation pane select the new template and view the data grid 6 In the data grid for the template click Assess The assessment on UNIX Linux machines uses the Patch Assessment Data Class filter t...

Page 172: ...rted in the Assessment Results node Scheduling UNIX Linux Assessments Because UNIX Linux assessments are VCM collections you can schedule these assessments by using the Patch Assessment collection fil...

Page 173: ...patches In Patching UNIX Linux Platform Assessment Results follow these steps to view the results 1 Click All Bulletins to display the Patch Assessment Results for all bulletins that VCM assessed agai...

Page 174: ...us cannot be determined NOTE If machine data has not been collected for a machine VCM Patching may not display assessment results for the machine and the machine will not be available for deployment I...

Page 175: ...for UNIX must be licensed on the UNIX Linux machine n Ensure that the assessments have run successfully n The patches must be available locally to the VCM managed machine IMPORTANT If you will be dep...

Page 176: ...actions are saved in the VCM change log in Console Change Management VCM or Non VCM Initiated Change By Data Type Patch Assessment These change actions are also available to Compliance and Reports IMP...

Page 177: ...hat the patch will not be assessed until you run an assessment Further Reading Refer to Customizing VCM for information on how to customize for your environment Several of these areas regarding custom...

Page 178: ...vCenter Configuration Manager Installation and Getting Started Guide 178 VMware Inc...

Page 179: ...x Packages support commercial and custom software that may be installed using any installation technology including msi exe or scripts Python VBScript PowerShell and others Once a package is created a...

Page 180: ...nents The software provisioning components should be installed on machines with the following relationships NOTE By default all the components are installed on the VCM Collector however it is recommen...

Page 181: ...the supported hardware requirements operating system and software requirements See VCM Hardware and Software Requirements Guide for currently supported platforms and requirements Access to the Reposi...

Page 182: ...he following n hive Contains the repository management files including such files as repository index and repository toc n crates Contains alphabetical sub folders It is to this location that the pack...

Page 183: ...s 6 Use the default path or click Change to modify the path When the path is correct click Next The Repository Root Folder page appears 7 Verify the path is to your installed repository files To modif...

Page 184: ...ager upzips the files to the TMP directory and runs the configured installation When a Remove Package action is sent to Package Manager it checks first for the package in the cratecache If it is not f...

Page 185: ...nd metadata necessary to install and remove programs One of the most useful features of a package is the metadata regarding dependencies conflicts and other relationships that are not represented by s...

Page 186: ...d Platforms to add a platform b Select a platform and then click Add Sections c Select a section and then click Publish Package d Select the package crate and then click Open The Publish Package dialo...

Page 187: ...age Managers 7 Click Next The Important page appears 8 Review the information resolve any conflicts and then click Finish You can monitor the process in the Jobs Manager See Viewing Provisioning Jobs...

Page 188: ...The Enter or Select Source page appears 5 Select either Add source at the beginning of existing source lists or Add source at the end of the existing source list 6 Type the URI or click Browse Sources...

Page 189: ...ailable from the sources configured for the Package Manager 7 Configure the Security Options This option determines if a package is installed or removed based on the state of the signature Select one...

Page 190: ...ions are not eligible for rollback through Change Management The undoing of any unwanted changes can be handled using Compliance enforcement remediation actions See Creating Compliance Rules containin...

Page 191: ...m Any and Section Release 13 Next The Options page appears 14 Select a Severity in the drop down list 15 Select Make available for enforcement where possible 16 Select Software Provisioning action 17...

Page 192: ...ftware based you will later configure the software provisioning remediation In this example select Services 7 Click Next The Rule Type for Services page appears 8 Select Conditional if then and then c...

Page 193: ...to verify the signature n Allow unsigned package to be installed Not recommended The package is installed or removed even if it is unsigned 22 Click OK to close the page and then click Next The Colle...

Page 194: ...vCenter Configuration Manager Installation and Getting Started Guide 194 VMware Inc...

Page 195: ...steps Step 1 Add Edit or Delete Hardware and Software Configuration Item Fields Step 2 Add Hardware Configuration Items Step 3 Add Software Configuration Items Review Hardware and Software Configurat...

Page 196: ...by VCM These machines are listed in Administration Machines Manager Licensed Machines n Other Devices Include machines that are not managed by VCM as well as other hardware devices such as bridges ro...

Page 197: ...you want to delete 3 If you are editing an existing field select the field and then click Edit Otherwise to add a field click Add The Add Edit Fields wizard appears 4 Enter the name and description of...

Page 198: ...nd then click Finish The field now appears in the Administration Settings Asset Extension Settings Hardware Configuration Items VCM Devices or Other Devices data grid and as a column in the Console As...

Page 199: ...appears 3 Enter the name and description of the field This name appears as the column heading in Console Asset Extensions Software Configuration Items Click Next 4 If you are adding a field determine...

Page 200: ...a Locked icon 4 Click OK to confirm VCM deletes the field from VCMMXA Adding Hardware Configuration Items Now that you have configured your VCMMXA fields for both VCM managed and non managed devices...

Page 201: ...ing data Modifying Other Devices In addition to accommodating VCM licensed machines VCMMXA also allows you to add up to 135 000 non VCM managed assets Use the Other Devices node to add edit or delete...

Page 202: ...that support your organization s processes When you configure the values for these fields they are available in Compliance also where you can create rules to actively check inventory For example use o...

Page 203: ...environment refer to Customizing VCM Each of these areas regarding customization also applies to VCMMXA You can also read Maintaining VCM after Installation for important information regarding additi...

Page 204: ...vCenter Configuration Manager Installation and Getting Started Guide 204 VMware Inc...

Page 205: ...ation implemented during the VMware services engagement and as determined by the customer s change management process If you have licensed VCM Service Desk Integration will you be able to see the Serv...

Page 206: ...ated with VCM Service Desk Integration are listed by RFC in the Job Manager data grids Click Administration Job Manager to display the VCM Job Manager node NOTE Jobs for VCM Patching managed machines...

Page 207: ...also read Maintaining VCM after Installation for important information regarding additional data retention settings and database maintenance steps which should be taken When using VCM for Service Des...

Page 208: ...vCenter Configuration Manager Installation and Getting Started Guide 208 VMware Inc...

Page 209: ...tion by data class Before you begin collecting Active Directory data with VCM for Active Directory you must complete the following required steps These steps are explained in this chapter 1 Making VCM...

Page 210: ...Network Authority Available Domains 2 Confirm that all Domains that you want to manage with VCM for Active Directory are displayed in the data grid with their fully qualified DNS names and a Domain Ty...

Page 211: ...MPORTANT When assigning accounts assign an available account to both the NetBIOS and Active Directory Domains Discovering Domain Controllers VCM offers several options for the discovery of Domain Cont...

Page 212: ...roller Type two single quotes 7 Click Next The Important page appears 8 For the Would you like to run this Discovery Rule now option select Yes 9 Click Finish IMPORTANT Click Administration Job Manage...

Page 213: ...y Domain Controllers in VCM for Active Directory that you can license You should begin licensing Domain Controllers that have a Status Connection State of OK If a connection state other than OK exists...

Page 214: ...n on each Domain Controller Disabling UAC for Agent Installation The following steps are required only if you are installing the Agent on a Windows 2008 or Vista machine When installing the Agent on W...

Page 215: ...appears 6 Click Browse The Browse for a Group Policy Object dialog box appears 7 On the Domains OUs tab select the domain OU to which the target machines belong and then click OK 8 On the Select Group...

Page 216: ...nes IMPORTANT Click Administration Job Manager History Instant Collections Past 24 Hours to verify that all jobs have completed before proceeding to the next step Configuring VCM for Active Directory...

Page 217: ...s from which you want to collect Active Directory data 3 Select the Domain Controllers on which you want to install VCM for Active Directory We recommend that you install VCM for Active Directory on a...

Page 218: ...be submitted to the selected DCs Forest information will be displayed in the Administration Machines Manager Additional Products VCM for Active Directory data grid Each Setup DCs job initiates the fol...

Page 219: ...er data from the new RDS 1 Click Administration Machines Manager Additional Components VCM for Active Directory 2 Click Setup DCs The Set the Forest Data Source s FDS page appears 3 Select a Forest Da...

Page 220: ...tory Data Collection You are now ready to perform your first collection of Active Directory objects using the same collection wizard used for Windows and UNIX Linux collections The first time you run...

Page 221: ...ction feature makes subsequent collections run faster and more efficiently than the initial collection For the initial collection make sure that you click the check box so that the delta feature is di...

Page 222: ...t an AD Location 12 Click OK to close the page 13 On the Location page click Next 14 Click Finish IMPORTANT Click Administration Job Manager History Instant Collections Past 24 Hours to verify that al...

Page 223: ...y of the data requested Active Directory Dashboards Begin by looking at the VCM for Active Directory dashboard under Active Directory Dashboards Managed Objects Note that several other Active Director...

Page 224: ...he default view to go directly to the data grid by using the Enable Disable Summary feature on the data grid view See Help for more information on how to filter and sort your data and get full use of...

Page 225: ...ly as current as of the time that the data was collected In addition it may require time for the report to generate based upon the volume or complexity of the data requested Refer to the online Help f...

Page 226: ...taining VCM After Installation on page 247 for important information regarding additional data retention settings and database maintenance steps which should be taken When using VCM for Active Directo...

Page 227: ...ctions 4 Explore VCM for SMS collection results Making VCM Aware of the SMS Servers In order for your SMS Servers to be available for VCM collections they must first be discovered and licensed in VCM...

Page 228: ...st perform a VCM collection using the Microsoft SMS Server Filter set This collection enables VCM to identify these machines as SMS Servers NOTE Before performing a collection on your SMS Servers you...

Page 229: ...itial Collection on page 67 to initiate your SMS Client collection 2 Using this procedure instead of selecting the default filter set choose the Select a Collection Filter Set to apply to these machin...

Page 230: ...Client links or the Chart bars to drill down to detailed information on the machine or group of machines Viewing SMS Server Data The Windows tab of the Console contains information about your SMS Ser...

Page 231: ...erver collection select Console Enterprise Applications SMS SMS Sites Site Information Sites 2 View the list of Servers currently hosting SMS in the data grid Viewing SMS Client Data The Windows tab o...

Page 232: ...in the data grid along with details about the SMS component they contain the Resource file and Version number Viewing SMS Reports An alternative way to view your collected SMS data is by running Repo...

Page 233: ...ou may now begin to check Compliance on your collected data by creating rule groups rules filters and templates See About Compliance in the online Help Further Reading Refer to Customize VCM for your...

Page 234: ...vCenter Configuration Manager Installation and Getting Started Guide 234 VMware Inc...

Page 235: ...your WSUS Servers have been discovered and licensed and are therefore available for WSUS Collections follow these steps 1 Click Administration Machines Manager Licensed Machines Licensed Windows Mach...

Page 236: ...er Filter set This collection will enable VCM to identify these machines as WSUS Servers 1 To perform a VCM collection see the procedure described in Performing an Initial Collection on page 67 2 Usin...

Page 237: ...hese machines option and then select Microsoft WSUS Client Filters from the Filter Sets list Exploring WSUS Collection Results After performing initial WSUS Server and Client collections you can explo...

Page 238: ...equested For more information on how to schedule and disseminate reports see the online Help You may now begin to check Compliance on your collected data by creating rule groups rules filters and temp...

Page 239: ...ard to Import Relevant Content If you are loading content into VCM for the first time refer to Section 15 4 VCM Import Export and VMware Content Wizard for information on how to launch VMware Content...

Page 240: ...ns in the Portal Once this content has been imported into the Portal further collections using custom filters may be required to use it These are included in the Content Package Refer to the online He...

Page 241: ...on which you want to install the tools The Installation Manager appears 2 Click Run Installation Manager 3 Complete the initial pages clicking Next to move to each subsequent page until the Select In...

Page 242: ...un Foundation Checker and confirm the configuration results Installation Manager also installs a command line version of Foundation Checker on your Collector machine during installation For more infor...

Page 243: ...ayed job information with any data now available from the server to which you just connected NOTE Once a valid server is added it automatically appears in the Current Server drop down list Each time y...

Page 244: ...ommand Line Interface CLI is a powerful extension of the Import Export graphic user interface GUI In addition to supporting the scenarios noted above the CLI allows content to be overwritten as oppose...

Page 245: ...items and elements in the target database Any duplicate items and elements must be resolved before you can continue with the import operation For detailed procedures on any of these steps click Help C...

Page 246: ...etwork issue impacting the download and or import process we recommend that you subdivide your imports to no more than two to three packages at a time Follow the wizard to completion Since the Import...

Page 247: ...omponent specific settings 2 Configure Database file growth 3 Configure Database recovery settings 4 Create a Maintenance Plan for SQL Server 2005 5 Incorporate the VCM CMDB into your backup disaster...

Page 248: ...ensions VCMMXA n VCM for Active Directory n VCM for Virtualization n UNIX n Windows For more information on settings specific to those products refer to the Help associated with each product To access...

Page 249: ...s window appears 5 In the left pane select Files The right pane displays VCM and VCM_Log 6 In the Autogrowth column click the ellipsis button The Change Autogrowth for VCM dialog box appears 7 Select...

Page 250: ...s involved that make point in time recovery at best tenuous It is recommended that you do not use this model If you do decide to implement Full Recovery it is critical to set up scheduled generally da...

Page 251: ...older right click Maintenance Plans and then select Maintenance Plan Wizard The SQL Server Maintenance Plan Wizard opens 3 Click Next The Select Plan Properties page appears Maintaining VCM After Inst...

Page 252: ...ng properties for the job as shown in this example It is best to schedule the run time when the system is idle or has low usage 6 After you have set the job schedule properties to your own specificati...

Page 253: ...ild Index Update Statistics and Clean Up History Click Next The Select Maintenance Task Order page appears 8 Specify the order for the maintenance tasks to be performed Click Next The Define Database...

Page 254: ...field Check the option Include indexes Click Next The Define Rebuild Index Task page appears NOTE Select the databases shown here including the VCM_Raw database The VCM_Raw database contains transien...

Page 255: ...nd then click OK When the databases are selected Specific databases appears in the drop down field In the Advanced options area of the dialog box select Sort results in tempdb Click Next The Define Up...

Page 256: ...tabases appears in the drop down field Click Next The Define History Cleanup Task page appears 12 Specify the historical data to be removed from the SQL Server 2005 machine VMware recommends saving hi...

Page 257: ...f the maintenance plan actions for future reference Click Next The Complete the Wizard page appears 14 Verify the selections in the Maintenance Plan Wizard Expand the tree selections to view the setti...

Page 258: ...ance plan to assure that SQL Server 2005 continues to operate efficiently Incorporate the VCM CMDB into your Backup Disaster Recovery Plans Consider your VCM CMDB as you would any other SQL database i...

Page 259: ...may not be including any of the bulletins that apply to the selected machine type Certain filter attributes may not apply to bulletins across all platforms For example Severity is not used by some pl...

Page 260: ...g messages may appear n Server Unavailable n The web application you are attempting to access on this web server is currently unavailable n Client found response content type of text html but expected...

Page 261: ...check box in the VCM virtual directory properties may become unchecked This problem can occur on a VCM Collector that is using SSL when all of the settings listed above have been configured After upg...

Page 262: ...performing these steps you can operate VCM through a secure channel Resolving a Report Parameter Error After upgrading VCM if you encounter a problem with a report your report may not have been upload...

Page 263: ...will be prompted to be sure that you want to delete this item Click OK 6 Click Upload File 7 On the Upload File screen next to the File to Upload text box select Browse 8 Select the report from the re...

Page 264: ...vCenter Configuration Manager Installation and Getting Started Guide 264 VMware Inc...

Page 265: ...ps 3 Double click the CSI_COMM_PROXY_SVC group 4 Add the Network Authority account to the CSI_COMM_PROXY_SVC group This account is the VCM Collector Service account that was specified during installat...

Page 266: ...then one of the following problems has occurred 1 You did not add users or groups to the CSI_COMM_PROXY_SVC group OR you did not reboot or 2 You are not running in a CMD shell as a user in the CSI_CO...

Page 267: ...tInstall exe for Windows 63 installation 16 61 installation manually 62 installation Oracle 109 installing agent proxy 121 Mac OS X 97 platforms supported 40 83 proxy platform not supported 43 upgradi...

Page 268: ...OS X 106 rule remediation software provisioning 191 software provisioning 190 components getting started 47 configurations AD 216 assets 195 collector as agent proxy 265 database file growth 249 inst...

Page 269: ...tive directory 209 foundation checker 241 installation 242 ftp use binary mode 84 97 G getting started 53 active directory 209 assets 195 auditing 116 components tools 47 deploy patches UNIX Linux 175...

Page 270: ...igurations 196 assets software configurations 198 N network authority account 13 AD 211 checking 54 node summaries resolving problems 260 O operating systems agent binaries 84 97 Oracle 10g installati...

Page 271: ...ctor aware 156 installing 149 command line 151 remote command 152 remote package UNIX agent upgrade 41 repairing uninstall troubleshooting 34 reports parameter error resolving 262 resolving problems 2...

Page 272: ...261 upgrading 35 agent 38 agent proxy 43 agent proxy manually 43 automatic 39 failed troubleshooting 34 Red Hat workstations 40 82 UNIX agent 40 local package 40 remote package 41 virtualization 42 vS...

Page 273: ...Information WCI 72 Windows machines collecting 67 disabling UAC 61 65 214 discover license install 53 discovering 56 install agent 61 licensing 59 uninstalling agent 64 Windows Server Update Services...

Page 274: ...274 VMware Inc vCenter Configuration Manager Installation and Getting Started Guide...

Reviews: