VMware vcenter Server 5.5 Deploying a Centralized VMware vcenter Single Sign-On Server with a Network Load Balancer
|
|
|
- Susan Beasley
- 10 years ago
- Views:
Transcription
1 VMware vcenter Server 5.5 Deploying a Centralized VMware vcenter Single Sign-On Server with a Network Load Balancer Technical Reference TECHNICAL MARKETING DOCUMENTATION V 1.0/FebrUARY 2014/JUSTIN KING, MIKE BROWN
2 Table of Contents Overview When to Centralize vcenter Single Sign-On Server... 3 Centralized vcenter Single Sign-On Architecture Centralized Single Sign-On High-Availability Options... 4 VMware vsphere Data Protection VMware vsphere High Availability... 4 VMware vcenter Server Heartbeat Network Load Balancer Deploying vcenter Preinstallation Checklist Deploying vcenter Single Sign-On Server First vcenter Single Sign-On Installation Additional vcenter Single Sign-On Installations vcenter Single Sign-On Certificates Optional: Creating the Microsoft Certificate Authority Template Generate the Certificate Request Configuring CA-Signed SSL Certificates Configuring the Network Load Balancer VMware vcloud Networking and Security F5 BIG-IP Citrix NetScaler Postdeployment of a Centralized vcenter Single Sign-On Environment Installing vcenter Server Components Updating a Previously Installed vcenter Single Sign-On Configuration Conclusion TECHNICAL WHITE PAPER / 2
3 Overview With the release of VMware vsphere 5.5 and VMware vcenter Server 5.5, multiple components deliver the vcenter Server management solution. One component, VMware vcenter Single Sign-On server, offers an optional deployment configuration that enables the centralization of vcenter Single Sign-On services for multiple local solutions such as vcenter Server. If not architected correctly, centralization can increase risk, so use of vcenter Single Sign-On server is highly recommended. This paper highlights the high-availability options for a centralized vcenter Single Sign-On environment and provides a reference guide for deploying one of the more common centralized vcenter Single Sign-On configurations with an external network load balancer (NLB). When to Centralize vcenter Single Sign-On Server VMware highly recommends deploying all vcenter Server components into a single virtual machine excluding the vcenter Server database. However, large enterprise customers running many vcenter Server instances within a single physical location can simplify vcenter Single Sign-On architecture and management by reducing the footprint and required resources and specifying a dedicated vcenter Single Sign-On environment for all resources in each physical location. For vsphere 5.5, as a general guideline, VMware recommends centralization of vcenter Single Sign-On server when eight or more vcenter Server instances are present in a given location. Centralized vcenter Single Sign-On Architecture Centralized vcenter Single Sign-On Server 5.5 A data center with eight or more instances of vcenter Server Centralized vcenter Single Sign-On authentication Same physical location vcenter Single Sign-On Server Database Server VCDB1, VCDB2, VCDB3 vcenter Server 5.1 vsphere Web Client Inventory Svc vcenter Server 5.5 vsphere Web Client Inventory Svc vcenter Server 5.5 vsphere Web Client Inventory Svc vcenter Server 1 vcenter Server 2 vcenter Server 3 Backward compatible to vcenter Server 5.1 for staging of upgrades Figure 1. A Centralized vcenter Single Sign-On Server Environment TECHNICAL WHITE PAPER / 3
4 Centralized Single Sign-On High-Availability Options The absence of vcenter Single Sign-On server greatly impacts the management, accessibility, and operations within a vsphere environment. The type of availability required is based on the user s recovery time objective (RTO), and VMware solutions can offer various levels of protection. VMware vsphere Data Protection VMware vsphere Data Protection provides a disk-level backup-and-restore capability utilizing storage-based snapshots. With the release of vsphere Data Protection 5.5, VMware now provides the option of host-level restore. Users can back up vcenter Single Sign-On server virtual machines using vsphere Data Protection and can restore later as necessary to a specified vsphere host. VMware vsphere High Availability When deploying a centralized vcenter Single Sign-On server to a vsphere virtual machine environment, users can also deploy VMware vsphere High Availability (vsphere HA) to enable recovery of the vcenter Single Sign-On server virtual machines. vsphere HA monitors virtual machines via heartbeats from the VMware Tools package, and it can initiate a reboot of the virtual machine when the heartbeat no longer is being received or when the vsphere host has failed. VMware vcenter Server Heartbeat VMware vcenter Server Heartbeat provides a richer availability model for the monitoring and redundancy of vcenter Server and its components. It places a centralized vcenter Single Sign-On server into an active passive architecture, monitors the application, and provides an up-to-date passive node for recovery during a vsphere host, virtual machine, or application failure. Network Load Balancer A VMware or third-party NLB can be configured to allow SSL pass-through communications to a number of local vcenter Single Sign-On server instances and provide a distributed and redundant vcenter Single Sign-On solution. Although VMware provides NLB capability in some of its optional products, such as VMware vcloud Networking and Security, there also are third-party solutions available in the marketplace. VMware does not provide support for third-party NLB solutions. TECHNICAL WHITE PAPER / 4
5 Deploying vcenter Single Sign-On Server with a Network Load Balancer Preinstallation Checklist The guidance provided within this document will reference the following details: Host Name FQDN IP Address Load Balancer SSO sso.vmware.local SSO Server 01 SSO1 sso1.vmware.local SSO Server 02 SSO2 sso2.vmware.local Table 1. Centralized vcenter Single Sign-On Requirements Example Architecture SSO1 vmware.local SSO2 vmware.local vsphere.local Network Load Balancer SSO.vmware.local/ Database Server VCDB1, VCDB2, VCDB3 vcenter Server 5.1 vsphere Web Client Inventory Svc vcenter Server 5.5 vsphere Web Client Inventory Svc vcenter Server 5.5 vsphere Web Client Inventory Svc vcenter Server 1 vcenter Server 2 vcenter Server 3 Figure 2. Example of a vcenter The following steps must be completed before installing the vcenter Single Sign-On server and configuring for use with an NLB: TECHNICAL WHITE PAPER / 5
6 1. Download the vcenter Server distribution. The vcenter Server binaries located on the vcenter Server ISO are required to install vcenter Single Sign-On server. NOTE: vcenter Server 5.5.0b Build is the latest version available and is used throughout this document. 2. Deploy virtual machines. With a configuration similar to that in Figure 2, deploy at least two appropriately sized virtual machines running Microsoft Windows 2008 SP2 or higher. Table 2. Minimum Hardware Requirements for vcenter Single Sign-On Server NOTE: As of February 2014, Windows 2012 R2 is not a supported operating system (OS) for vcenter Single Sign-On server. 3. Install the Microsoft Visual C Redistributable Package. We will use OpenSSL to request the vcenter Single Sign-On certificates. The OpenSSL tool has a dependency on the Microsoft Visual C Redistributable Package (32-bit), which can be downloaded and installed from the following: This must be installed on each deployed vcenter Single Sign-On server. NOTE: There are newer versions of this file that might already be installed and might cause errors with the (step 4) download and install of WIN32 OpenSSL; the version provided is fully tested with WIN32 OpenSSL. 4. Download and install WIN32 OpenSSL. The specific version of OpenSSL that should be used for vcenter Single Sign-On server certificates (version 0.9.8) can be downloaded and installed from the following: NOTE: For the purposes of this document, WIN32OpenSSL-0_9_8y.exe is a specific requirement and not necessarily the latest version available. 5. Create certificate folder structure. On the first vcenter Single Sign-On server virtual machine, create the following folder structure: c:\certs\sso TECHNICAL WHITE PAPER / 6
7 6. Create a vcenter Single Sign-On configuration file. Create a text file and build the file based on the following template, saving the file to c:\certs\sso\sso.cfg. This file will provide all host names and FQDNs used in the example configuration as well as the IP address for the NLB. See VMware Knowledge Base article Creating certificate requests and certificates for vcenter Server 5.5 components. Filename: c:\certs\sso\sso.cfg [ req ] default_bits = 2048 default_keyfile = rui.key distinguished_name = req_distinguished_name encrypt_key = no prompt = no string_mask = nombstr req_extensions = v3_req [ v3_req ] basicconstraints = CA:FALSE keyusage = digitalsignature, keyencipherment, dataencipherment extendedkeyusage = serverauth, clientauth subjectaltname = DNS:sso1, DNS:sso1.vmware.local, DNS:sso2, DNS:sso2.vmware.local, DNS:sso.vmware.local, IP: [ req_distinguished_name ] countryname = Country stateorprovincename = State localityname = City 0.organizationName = Company Name organizationalunitname = vcentersso commonname = sso.vmware.local NOTE: The bold entries are specific to the environment as discussed in the preinstallation checklist and should be edited to reflect the environment you are installing into. TECHNICAL WHITE PAPER / 7
8 Deploying vcenter Single Sign-On Server In this example, we will deploy a vcenter Single Sign-On server instance, deploy a second vcenter Single Sign-On server instance, and configure a load balancer to provide an active active entry point for all vcenter Single Sign-On service requests in a single physical location. 1. First vcenter Single Sign-On Installation The following steps will deploy the first vcenter Single Sign-On server: a. Connect the vcenter Server ISO image to the sso1.vmware.local virtual machine. b. Log in to sso1.vmware.local. c. On the DVD menu, choose the vcenter Single Sign-On option listed under Custom Install. d. Click Install. e. After the Welcome to the vcenter Single Sign-On Setup Wizard screen is shown, click Next. f. Select I agree to the terms in the License Agreement and click Next. g. Review the vcenter Single Sign-On Prerequisites and click Next. h. On the vcenter Single Sign-On Information screen, select the first option, vcenter Single Sign-On for your first vcenter Server, because this is the first vcenter Server to be deployed. Click Next. i. Provide and confirm a Password for the built-in [email protected] account. Click Next. Refer to VMware Knowledge Base article Installing vcenter Single Sign-On 5.5 fails if the password for [email protected] contains certain special character. j. On the vcenter Single Sign-On Configure Site screen, provide a Site name. This can be based on location or organization for example, Palo Alto. Click Next. k. On the vcenter Single Sign-On Port Settings screen, click Next. l. On the Change destination folder screen, click Next. m. Confirm the vcenter Single Sign-On Information/Review install options screen. Click Install. n. On the Completed the vcenter Single Sign-On Setup Wizard screen, click Finish. 2. Additional vcenter Single Sign-On Installations The following steps will deploy additional vcenter Single Sign-On servers and partner them with the first server, deployed in step 1. a) Connect the vcenter Server ISO image to the sso2.vmware.local virtual machine. b) Log in to sso2.vmware.local. c) On the DVD menu, choose the vcenter Single Sign-On option listed under Custom Install. d) Click Install. e) After the Welcome to the vcenter Single Sign-On Setup Wizard screen appears, click Next. f) Select I agree to the terms in the License Agreement and click Next. g) Review the vcenter Single Sign-On Prerequisites and click Next. h) On the vcenter Single Sign-On Information screen, select the second option, vcenter Single Sign-On for an additional vcenter Server in an existing site, to pair with an existing local instance. Click Next. TECHNICAL WHITE PAPER / 8
9 i) Provide the Partner host name as sso1.vmware.local, to pair with the previously deployed vcenter Server Single Sign-On instance to replicate from. Provide the Password for the built-in account used with sso1.vmware.local. Click Next. NOTE: All internal vcenter Single Sign-On communications will be direct and will not use the NLB. j) To accept the host certificate, click Continue on the Partner certificate screen. k) On the vcenter Single Sign-On Join Site screen, choose the Site name used with the first vcenter Single Sign-On instance for example, Palo Alto. Click Next. l) On the vcenter Single Sign-On Port Settings screen, click Next. m) On the Change destination folder screen, click Next. n) On the vcenter Single Sign-On Information/Review install options screen, click Install. o) On the Completed the vcenter Single Sign-On Setup Wizard screen, click Finish. Repeat step 2 for any additional vcenter Single Sign-On servers. You now should have successfully deployed two or more separate vcenter Single Sign-On servers that are part of the same vsphere.local security domain. vcenter Single Sign-On Certificates When using an NLB, secure SSL communication with vcenter Single Sign-On server requires an update to the certificates to reflect the NLB entry point. All vcenter Single Sign-On servers that participate in the loadbalanced configuration require certificate updates. In our example, we will use a Microsoft certificate authority (CA) as our trusted root authority and will generate certificate requests with OpenSSL. The process is similar for other CAs. Optional: Creating the Microsoft Certificate Authority Template The Microsoft CA template that we will use to create updated signed certificates must have data encipherment and client authentication enabled. See VMware Knowledge Base article Creating a Microsoft Certificate Authority Template for SSL certificate creation in vsphere 5.x. Generate the Certificate Request You must run the following commands from a command line to prepare and generate the certificate request: a) Open a command prompt and type the following: CD \OpenSSL\bin b) Run the following to create a certificate request and export the private key: openssl req -new -nodes -out c:\certs\sso\rui.csr keyout c:\certs\sso\rui-orig.key -config c:\certs\sso\sso.cfg c) Run the following to convert the key into the proper RSA format: openssl rsa -in c:\certs\sso\rui-orig.key -out c:\certs\sso\rui.key d) Download your CA s root certificate with Base64 encoding. In our example, the file generated is named certnew.cer and is saved in C:\certs renamed as follows: Root64.cer e) With a text editor, open the private key C:\certs\sso\rui.csr and copy the entire contents into the CA certificate request field. Select the template with data encipherment enabled (optional step previously mentioned) and download the certificate as Base64 encoded. In our example, the file generated is named certnew.cer and is renamed as rui.crt and then placed into the following: C:\certs\sso TECHNICAL WHITE PAPER / 9
10 f) Run the following to create an archive file (ssoserver.p12) of all certificates and keys: openssl pkcs12 export in c:\certs\sso\rui.crt inkey c:\certs\sso\rui.key certfile c:\certs\root64.cer name ssoserver passout pass:changeme out c:\certs\ sso\ssoserver.p12 g) Change to the VMware directory by typing the following: CD C:\Program Files\Common Files\VMware\VMware vcenter Server Java Components\bin\ h) Run the following to create the Java KeyStore: keytool v importkeystore srckeystore C:\certs\sso\ssoserver.p12 srcstoretype pkcs12 srcstorepass changeme srcalias ssoserver destkeystore C:\certs\sso\roottrust.jks -deststoretype JKS deststorepass testpassword destkeypass testpassword If asked whether the existing entry alias ssoserver exists, overwrite? Type: yes i) Run the following to add the root certificate to the Java KeyStore: keytool v importcert keystore C:\certs\sso\root-trust.jks deststoretype JKS storepass testpassword keypass testpassword file C:\certs\Root64.cer alias root-ca When asked whether to trust this certificate, type: yes j) Run the following to copy the Java KeyStore to the required Java KeyStore name: Copy C:\certs\sso\root-trust.jks C:\certs\sso\server-identity.jks Configuring CA-Signed SSL Certificates Log in to sso1.vmware.local and open an elevated command prompt. a) Run the following to set the correct environment variables: SET JAVA_HOME=C:\Program Files\Common Files\VMware\VMware vcenter Server Java Components SET PATH=%PATH%;C:\Program Files\VMware\Infrastructure\VMware\CIS\vmware-sso;%JAVA_ HOME%\bin b) Change to the OpenSSL directory; type and run the following: CD \OpenSSL\bin c) Register the new root certificate in the VMware trust store; type and run the following: openssl x509 noout subject_hash in C:\certs\Root64.cer This will create an eight-digit hexadecimal value that will be used in step e). d) Run the following to create an SSL directory: mkdir c:\programdata\vmware\ssl e) Run the following to copy the Root64.cer certificate to the SSL folder: Copy C:\certs\Root64.cer C:\ProgramData\VMware\SSL\<eight digit hexadecimal value>.0 This is the result from step c). f) Run the following to copy the Root64.cer file to the SSL folder and rename it to ca_certificates.crt: more C:\certs\Root64.cer >> C:\ProgramData\VMware\SSL\ca_certificates.crt g) To change the vcenter Single Sign-On server configuration to reflect the NLB, with a text editor, create three text files within the C:\certs directory and name as shown. These files are used to update the individual vcenter Single Sign-On services with the NLB VIP. TECHNICAL WHITE PAPER / 10
11 Filename: C:\certs\admin.properties [service] friendlyname=the administrative interface of the SSO server version=1.5 ownerid= productid=product:sso type=urn:sso:admin description=the administrative interface of the SSO server [endpoint0] uri= ssl=c:\certs\root64.cer protocol=vmomi Filename: C:\certs\gc.properties [service] friendlyname=the group check interface of the SSO server version=1.5 ownerid= productid=product:sso type=urn:sso:groupcheck description=the group check interface of the SSO server [endpoint0] uri= ssl=c:\certs\root64.cer protocol=vmomi Filename: C:\certs\sts.properties [service] friendlyname=sts for Single Sign On version=1.5 ownerid= productid=product:sso type=urn:sso:sts description=the Security Token Service of the Single Sign On server. [endpoint0] uri= ssl=c:\certs\root64.cer protocol=wstrust h) Run the following to list the vcenter Single Sign-On services: ssolscli listservices TECHNICAL WHITE PAPER / 11
12 The return should be three services: Figure 3. Example of the vcenter Single Sign-On Server CLI List Services Command i) For each service returned, the first field will display as the following: <serviceid=<ssositename>:<thirty two digit hexadecimal value> Each service site name and 32-digit hexadecimal value must be saved to a text file by using the service type (line 3) and the following syntax for each corresponding service type: ECHO Palo Alto:<thirty two digit hexadecimal value> >> C:\certs\gc_id ECHO Palo Alto:<thirty two digit hexadecimal value> >> C:\certs\sts_id ECHO Palo Alto:<thirty two digit hexadecimal value> >> C:\certs\admin_id Figure 4. Example of Exporting Service Information to a Text File j) Open a Windows Explorer window and navigate to the following: C:\ProgramData\VMware\CIS\runtime\VMwareSTS\conf k) Create a backup directory and make a backup of the following files by copying them into the backup folder: ssoserver.crt ssoserver.key ssoserver.p12 TECHNICAL WHITE PAPER / 12
13 l) In the command prompt windows, copy the three certificate files to the correct destination by typing the following: copy C:\certs\sso\ssoserver.p12 c:\programdata\vmware\cis\runtime\vmwarests\conf\ ssoserver.p12 copy C:\certs\Root64.cer c:\programdata\vmware\cis\runtime\vmwarests\conf\ ssoserver.crt copy C:\certs\sso\rui.key c:\programdata\vmware\cis\runtime\vmwarests\conf\ ssoserver.key Select YES to overwrite the existing file. m) Before we can update the vcenter Single Sign-On service information, we must add the sso.vmware.local into the local host files, because this entry will create an error prior to configuration of the load balancer. Type the following: notepad C:\Windows\System32\Drivers\etc\hosts Then add the following: sso.vmware.local n) Run the following to update the three vcenter Single Sign-On services with the service files created with the NLB configuration. Type the following: ssolscli updateservice -d -u -p <password> -si C:\certs\gc_id ip C:\certs\ gc.properties ssolscli updateservice -d -u -p <password> -si C:\certs\admin_id ip C:\certs\admin. properties ssolscli updateservice -d -u -p <password> -si C:\certs\sts_id ip C:\certs\sts. properties NOTE: If you receive a Server certificate assertion not verified and thumbprint not matched error, follow step o) to restart the VMware Security Token Service and repeat the command. o) You must restart the VMware Security Token Service for the previous step to take effect. Type the following: net stop VMwareSTS net start VMwareSTS p) Confirm that the updates have been applied by listing the vcenter Single Sign-On services. Type the following: ssolscli listservices The endpoints entry (line 4) should now show the load balance URL sso.vmware.local for each service. q) Remove the temporary host entry applied to the local hosts file by deleting the sso.vmware.local entry added in step m). Log in to sso2.vmware.local and open an elevated command prompt. a) Open a Windows Explorer window. Navigate to \\sso1.vmware.local\c$ and copy the certs directory to C:\ on sso2.vmware.local \\sso1.vmware.local\c$\programdata\vmware and copy the SSL directory to C:\ProgramData\VMware on sso2.vmware.local TECHNICAL WHITE PAPER / 13
14 b) Run the following to set the correct environment variables: SET JAVA_HOME=C:\Program Files\Common Files\VMware\VMware vcenter Server Java Components SET PATH=%PATH%;C:\Program Files\VMware\Infrastructure\VMware\CIS\vmware-sso;%JAVA_ HOME%\bin c) Before we can update the vcenter Single Sign-On service information, we must add the sso.vmware. local into the local host s files on sso2.vmware.local because this entry will create an error prior to configuration of the load balancer. Type notepad C:\Windows\System32\Drivers\etc\hosts and add sso.vmware.local d) In the command prompt window, copy the three update files to the correct destination. Type the following: copy C:\certs\sso\ssoserver.p12 c:\programdata\vmware\cis\runtime\vmwarests\conf\ ssoserver.p12 copy C:\certs\Root64.cer c:\programdata\vmware\cis\runtime\vmwarests\conf\ ssoserver.crt copy C:\certs\sso\rui.key c:\programdata\vmware\cis\runtime\vmwarests\conf\ ssoserver.key Select YES to overwrite the existing file. e) Restart the VMware Security Token Service to accept the updated certificate files. Type the following: net stop VMwareSTS net start VMwareSTS f) Update the three services with the current information. Type the following: ssolscli updateservice -d -u [email protected] -p <password> -si C:\certs\gc_id ip C:\certs\ gc.properties ssolscli updateservice -d -u [email protected] -p <password> -si C:\certs\admin_id ip C:\certs\admin. properties ssolscli updateservice -d -u [email protected] -p <password> -si C:\certs\sts_id ip C:\certs\sts. properties NOTE: If you receive a Server certificate assertion not verified and thumbprint not matched error, follow step g) to restart the VMware Security Token Service and repeat the command. g) You must restart the VMware Security Token Service to effect the previous step. Type the following: net stop VMwareSTS net start VMwareSTS h) Confirm by typing the following that the updates have been applied: ssolscli listservices The endpoints entry (line 4) should now show the load balance URL sso.vmware.local for each service. i) Remove the temporary host entry applied to the local host s file by deleting the sso.vmware.local entry added in step c). TECHNICAL WHITE PAPER / 14
15 Configuring the Network Load Balancer The following are examples of NLB configurations that can be used for placement with centralized vcenter Single Sign-On servers to provide an active active distribution of load as well as redundancy. This is to be used as a guide for configuring such NLBs, because VMware does not provide support for the configuration of third-party products. It is important to have a solid understanding of the setup and administration of the intended NLB prior to proceeding. The following procedures provide guidance on configuring the NLB for use with vcenter Single Sign-On server only and are not intended to provide general guidance on setup and administration of a load balancer. NOTE: The following NLB configurations will not work with the VMware vcloud Automation Center, due to its having different vcenter Single Sign-On server communication requirements from those of vcenter Server. A revision is planned for enactment as soon as testing has been completed. VMware vcloud Networking and Security Using a supported Web browser, open the VMware vshield Manager interface. 1. In the left-hand menu, expand Datacenters and choose the data center your vcenter Single Sign-On environment resides in. 2. Configure the virtual IP address (VIP): a. Click the Network Virtualization tab. b. Select your Edge gateway device. c. Click Actions. d. Choose Manage. e. Click Configure. f. Select the vnic that will house the VIP IP address. g. Select Edit. h. Click the Green plus icon. i. Enter the IP Address of the load balancer: j. Click Add. 3. Create the virtual server pool: a. Click the Load Balancer tab on the edge1 screen. b. Click the green plus icon to add a pool. c. Provide a name: enter SSO-POOL. d. Click Next. e. Under Services: i. Select TCP. ii. Choose LEAST_CONN as Balancing Method. iii. Enter 7444 as Port. TECHNICAL WHITE PAPER / 15
16 f. Click Next. g. Change the TCP Monitor Port to h. Click Next. i. Under Members: i. Click the green plus icon. ii. Enter an IP address: iii. Click Add. iv. Click the green plus icon again. v. Enter an IP address: vi. Click Add. vii. Click Next. viii. Click Finish. j. Click Enable. k. Publish Changes to update configuration. 4. Create a virtual server: a. Click Virtual Servers under the configuration tabs. b. Click the green plus icon. c. Enter a name: SSO-VIP. d. Enter an IP address: e. Under Services: i. Select TCP. ii. Change the TCP Port to iii. Click Add. f. Click Publish Changes to update configuration. 5. (Optional) Configure firewall if the default rule is set to Deny. a. Click the Firewall tab. b. Click the green plus icon. c. In the new entry: i. Enter a rule name: SSO. ii. Provide a destination: select Add IP Addresses. iii. Enter a name: SSO-VIP. iv. Enter an IP address: d. Click OK. e. Click Publish. TECHNICAL WHITE PAPER / 16
17 F5 BIG-IP 1. Before you start, make a copy of the C:\certs\sso directory and Root64.cer from one of the installed vcenter Single Sign-On servers. Using a supported Web browser, open the F5 BIG-IP management interface. 2. Provide SSO certificates to F5 BIG-IP: a. Choose System. b. Choose File Management. c. Choose SSL Certificate List. d. On the SSL Certificate List screen, click Import. e. Under Import Type, select Certificate. f. For Certificate Name, select Create New and enter ssocert. g. For Certificate Source, select Upload File and browse to the rui.crt file from the copy of the SSO directory in step 1. h. Click Import. i. On the SSL Certificate List screen, click Import. j. Under Import Type, select Key. k. For Key Name, select Create New and enter ssokey. l. For Key Source, select Upload File and browse to the rui.key file from the copy of the SSO directory in step 1. m. Click Import. n. On the SSL Certificate List screen, click Import. o. For Import Type, select Certificate. p. For Certificate Name, select Create New and enter VMwareLocalRoot. q. For Certificate Source, select Upload File and browse to the Root64.cer file from the copy in step 1. r. Click Import. s. Confirm that the ssocert entry shows sso.vmware.local under Common Name. 3. Create the load balancer pool: a. Choose Local Traffic from the left-hand menu. b. Choose Pools. c. Choose Pool List. d. On the Pool List screen, click Create. e. Provide a Name: enter SSO. f. For Health Monitors, select and add tcp to active column. TECHNICAL WHITE PAPER / 17
18 g. For New Members: i. Enter a Node Name: sso1. ii. Enter an Address: iii. Enter a service port: iv. Click Add. v. Enter a Node Name of sso2. vi. Enter an Address: vii. Enter a Service Port: viii. Click Add. ix. Click Finished. 4. Create SSL client: a. Choose Local Traffic from left-hand menu. b. Choose Profiles. c. Choose SSL. d. Choose Client. e. On the Client screen, click Create. f. Enter a Name: SSO-Client. g. Select Custom. h. Under Configuration: i. For Certificate, choose ssocert. ii. For Key, choose ssokey. iii. Click Finished. 5. Create SSL server: a. Choose Local Traffic from left-hand menu. b. Choose Profiles. c. Choose SSL. d. Choose Server. e. On the Server screen, click Create. f. Enter a Name: SSO-Server. g. Select Custom. h. Under Configuration: i. For Certificate, choose ssocert. ii. For Key, choose ssokey. iii. Click Finished. TECHNICAL WHITE PAPER / 18
19 6. Create virtual server: a. Choose Local Traffic from left-hand menu. b. Choose Virtual Servers. c. Choose Virtual Server List. d. On the Server screen, click Create. e. Enter a Name: SSO-VIP. f. Provide a Destination: i. For Type, select Host. ii. Enter an Address: iii. Enter a Service Port: g. Under Configuration: i. For HTTP Profile, choose http. ii. For SSL Profile (Client): choose SSO-Client. iii. For SSL Profile (Server): choose SSO-Server. h. Under Resources: i. For Default Pool: choose SSO. i. Click Finished. 7. Create SNAT: a. Choose Local Traffic from left-hand menu. b. Choose Address Translation. c. Choose SNAT List. d. On the SNAT List screen, click Create. e. Enter a Name: SNAT-SSO-NGC. f. Under Configuration: i. For Translation IP address: choose g. Click Finished. Citrix NetScaler Using a supported Web browser, open the Citrix NetScaler management interface. 1. Create a virtual server: a. Choose Traffic Management. b. Choose Load Balancing. c. Choose Virtual Servers. d. Click Add. e. Enter a Name: SSO. TECHNICAL WHITE PAPER / 19
20 f. Change the protocol from the default HTTP to TCP. g. Enter an IP address: h. Enter a Port: Create the services for the virtual server: a. Select Add under the Services tab. b. Enter a Service Name: enter sso1. c. Change the protocol from default HTTP to TCP. d. Select Server and enter e. Select Port and enter f. Under available Monitors, select TCP and click Add. g. Click Create. h. Click Add again under the Services tab. i. Enter a Service Name: sso2. j. Change the protocol from default HTTP to TCP. k. Select Server and enter l. Select Port and enter m. Under available Monitors, select TCP and click Add. n. Click Create. 3. Under available monitors, select TCP and click Add. a. Click Create. 4. On the Create Virtual Server screen: a. Click Create. b. Click the Method and Persistence tab. c. Confirm that LB Method is set for Least Connection. d. Click Close. 5. Refresh the configuration. You now have an NLB that is configured to receive vcenter Single Sign-On requests and to pass through to a member server running vcenter Single Sign-On server. TECHNICAL WHITE PAPER / 20
21 Postdeployment of a Centralized vcenter Single Sign-On Environment Having completed the previous steps of installing a centralized vcenter Single Sign-On solution, you can complete the deployment of all vcenter Single Sign-On enabled solutions. Installation of additional VMware solutions is not recommended on the virtual machines hosting the vcenter Single Sign-On environment. Installing vcenter Server Components Almost all vcenter Server components utilize a vcenter Single Sign-On solution. They can be deployed in the following order: 1. VMware vsphere Web Client Specify sso.vmware.local for the vcenter Single Sign-On server. 2. vcenter Inventory Service Specify sso.vmware.local for the vcenter Single Sign-On server. 3. vcenter Server Specify sso.vmware.local for the vcenter Single Sign-On server. Any other VMware component that requires vcenter Single Sign-On registration should also specify sso.vmware.local when asked for the vcenter Single Sign-On server. Updating a Previously Installed vcenter Single Sign-On Configuration If you have deployed a different vcenter Single Sign-On architecture or are upgrading and plan to move to a centralized vcenter Single Sign-On environment, the following is an overview of the process involved. 1. If upgrading, you must do so from the existing vcenter Single Sign-On server to the latest release; that is, vcenter Server 5.5.0b Build Deploy a new vcenter Single Sign-On server, as discussed, for an additional vcenter Single Sign-On server, using the existing vcenter Single Sign-On server as the partner host name. This will enable replication of vcenter Single Sign-On configuration, including users and groups, to the newly deployed vcenter Single Sign-On server. This server will become the first vcenter Single Sign-On server in a centralized environment, for placement behind an NLB. 3. Deploy a new vcenter Single Sign-On server, as discussed, for an additional vcenter Single Sign-On server, using the vcenter Single Sign-On server deployed in the previous step as the partner host name. This server will be the second vcenter Single Sign-On server in a centralized environment, for placement behind an NLB. 4. Proceed with the preceding instructions, starting from the vcenter Single Sign-On certificates. Conclusion With the release of VMware vcenter Server 5.5 and an improved VMware vcenter Single Sign-On server, the use of network load balancers with a centralized vcenter Single Sign-On environment can provide robust load distribution and redundancy without the limitations found in previous versions. For customers with multiple vcenter Single Sign-On enabled solutions, the centralized model eases the duplication of vcenter Single Sign-On administration. This document provides the necessary steps for deploying and configuring a centralized vcenter Single Sign-On environment with the benefits of utilizing a network load balancer. TECHNICAL WHITE PAPER / 21
22 VMware, Inc Hillview Avenue Palo Alto CA USA Tel Fax Copyright 2014 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Item No: TBD Docsource: OIC - 13VM004.09
Using VMware vcenter SSO 5.5 with VMware vcloud Automation Center 6.1
Using VMware vcenter SSO 5.5 with VMware vcloud Automation Center 6.1 Deployment Guide for High-Availability Configurations T E C H N I C A L W H I T E P A P E R Table of Contents Introduction... 2 Overview...
Replacing Default vcenter Server 5.0 and ESXi Certificates
Replacing Default vcenter Server 5.0 and ESXi Certificates vcenter Server 5.0 ESXi 5.0 This document supports the version of each product listed and supports all subsequent versions until the document
Replacing vcenter Server 4.0 Certificates VMware vsphere 4.0
Technical Note Replacing vcenter Server 4.0 Certificates VMware vsphere 4.0 Certificates are automatically generated when you install vcenter Server and ESX/ESXi. These default certificates are not signed
VMware vcenter Server 5.5 Deployment Guide TECHNICAL MARKETING DOCUMENTATION V 1.0/NOVEMBER 2013/JUSTIN KING
VMware 5.5 TECHNICAL MARKETING DOCUMENTATION V 1.0/NOVEMBER 2013/JUSTIN KING Table of Contents Overview.... 3 Components of 5.5.... 3 vcenter Single Sign-On.... 3 vsphere Web Client.... 3 vcenter Inventory
Scenarios for Setting Up SSL Certificates for View
Scenarios for Setting Up SSL Certificates for View VMware Horizon 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
Installing and Configuring vcloud Connector
Installing and Configuring vcloud Connector vcloud Connector 2.7.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Installing and Configuring vcenter Multi-Hypervisor Manager
Installing and Configuring vcenter Multi-Hypervisor Manager vcenter Server 5.1 vcenter Multi-Hypervisor Manager 1.1 This document supports the version of each product listed and supports all subsequent
Managing Multi-Hypervisor Environments with vcenter Server
Managing Multi-Hypervisor Environments with vcenter Server vcenter Server 5.1 vcenter Multi-Hypervisor Manager 1.0 This document supports the version of each product listed and supports all subsequent
Obtaining SSL Certificates for VMware Horizon View Servers
Obtaining SSL Certificates for VMware Horizon View Servers View 5.2 View Composer 5.2 This document supports the version of each product listed and supports all subsequent versions until the document is
vrealize Automation Load Balancing
vrealize Automation Load Balancing Configuration Guide Version 6.2 T E C H N I C A L W H I T E P A P E R A U G U S T 2 0 1 5 V E R S I O N 1. 0 Table of Contents Introduction... 4 Load Balancing Concepts...
Installing and Configuring vcloud Connector
Installing and Configuring vcloud Connector vcloud Connector 2.0.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Replacing VirtualCenter Server Certificates VMware Infrastructure 3
Technical Note Replacing VirtualCenter Server Certificates VMware Infrastructure 3 This technical note provides information about replacing the default certificates supplied with VirtualCenter Server hosts.
Director and Certificate Authority Issuance
VMware vcloud Director and Certificate Authority Issuance Leveraging QuoVadis Certificate Authority with VMware vcloud Director TECHNICAL WHITE PAPER OCTOBER 2012 Table of Contents Introduction.... 3 Process
vsphere Replication for Disaster Recovery to Cloud
vsphere Replication for Disaster Recovery to Cloud vsphere Replication 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
Obtaining SSL Certificates for VMware View Servers
Obtaining SSL Certificates for VMware View Servers View 5.1 View Composer 3.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
vsphere Replication for Disaster Recovery to Cloud
vsphere Replication for Disaster Recovery to Cloud vsphere Replication 5.8 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
VMware vcenter Support Assistant 5.1.1
VMware vcenter.ga September 25, 2013 GA Last updated: September 24, 2013 Check for additions and updates to these release notes. RELEASE NOTES What s in the Release Notes The release notes cover the following
VMware vsphere Data Protection Evaluation Guide REVISED APRIL 2015
VMware vsphere Data Protection REVISED APRIL 2015 Table of Contents Introduction.... 3 Features and Benefits of vsphere Data Protection... 3 Requirements.... 4 Evaluation Workflow... 5 Overview.... 5 Evaluation
Reconfiguring VMware vsphere Update Manager
Reconfiguring VMware vsphere Update Manager vsphere Update Manager 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
Reconfiguration of VMware vcenter Update Manager
Reconfiguration of VMware vcenter Update Manager Update 1 vcenter Update Manager 4.1 This document supports the version of each product listed and supports all subsequent versions until the document is
Offline Data Transfer to VMWare vcloud Hybrid Service
Offline Data Transfer to VMWare vcloud Hybrid Service vcloud Connector 2.5.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
App Orchestration 2.5
Configuring NetScaler 10.5 Load Balancing with StoreFront 2.5.2 and NetScaler Gateway for Prepared by: James Richards Last Updated: August 20, 2014 Contents Introduction... 3 Configure the NetScaler load
Getting Started with ESXi Embedded
ESXi 4.1 Embedded vcenter Server 4.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent
Activating HTTPS using wildcard certificate in Horizon Application Manager 1.5
Activating HTTPS using wildcard certificate in Horizon Application Manager 1.5 Authors: Rasmus Jensen, Sr. Specialist Consultant EUC, NEMEA, VMware Inc. Peter Björk, EMEA Horizon & ThinApp Specialist Systems
vsphere Upgrade vsphere 6.0 EN-001721-03
vsphere 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of this document,
Reconfiguring VMware vsphere Update Manager
Reconfiguring VMware vsphere Update Manager vsphere Update Manager 5.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication
Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication Authentication is about security and user experience and balancing the two goals. This document describes the authentication
App Orchestration 2.0
App Orchestration 2.0 Configuring NetScaler Load Balancing and NetScaler Gateway for App Orchestration Prepared by: Christian Paez Version: 1.0 Last Updated: December 13, 2013 2013 Citrix Systems, Inc.
VMware vsphere Replication Administration
VMware vsphere Replication Administration vsphere Replication 6.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.4.1
VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.4.1 This document supports the version of each product listed and supports all subsequent versions
Installing and Configuring vcenter Support Assistant
Installing and Configuring vcenter Support Assistant vcenter Support Assistant 5.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
Using the vcenter Orchestrator Plug-In for vsphere Auto Deploy 1.0
Using the vcenter Orchestrator Plug-In for vsphere Auto Deploy 1.0 vcenter Orchestrator 4.2 This document supports the version of each product listed and supports all subsequent versions until the document
VMware vsphere Data Protection 6.0
VMware vsphere Data Protection 6.0 TECHNICAL OVERVIEW REVISED FEBRUARY 2015 Table of Contents Introduction.... 3 Architectural Overview... 4 Deployment and Configuration.... 5 Backup.... 6 Application
vsphere Upgrade Update 1 ESXi 6.0 vcenter Server 6.0 EN-001804-02
Update 1 ESXi 6.0 vcenter Server 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent
Configuring Multiple ACE Management Servers VMware ACE 2.0
Technical Note Configuring Multiple ACE Management Servers VMware ACE 2.0 This technical note describes how to configure multiple VMware ACE Management Servers to work together. VMware recommends this
Management Pack for vrealize Infrastructure Navigator
Management Pack for vrealize Infrastructure Navigator This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To
VMware vsphere Data Protection 5.8 TECHNICAL OVERVIEW REVISED AUGUST 2014
VMware vsphere Data Protection 5.8 TECHNICAL OVERVIEW REVISED AUGUST 2014 Table of Contents Introduction.... 3 Features and Benefits of vsphere Data Protection... 3 Additional Features and Benefits of
Migrating to vcloud Automation Center 6.1
Migrating to vcloud Automation Center 6.1 vcloud Automation Center 6.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
IBM Security QRadar Vulnerability Manager Version 7.2.1. User Guide
IBM Security QRadar Vulnerability Manager Version 7.2.1 User Guide Note Before using this information and the product that it supports, read the information in Notices on page 61. Copyright IBM Corporation
vcenter Chargeback User s Guide
vcenter Chargeback 1.6 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions
Upgrading Horizon Workspace
Horizon Workspace 1.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of
vcenter Configuration Manager Backup and Disaster Recovery Guide VCM 5.3
vcenter Configuration Manager Backup and Disaster Recovery Guide VCM 5.3 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by
SC-T35/SC-T45/SC-T46/SC-T47 ViewSonic Device Manager User Guide
SC-T35/SC-T45/SC-T46/SC-T47 ViewSonic Device Manager User Guide Copyright and Trademark Statements 2014 ViewSonic Computer Corp. All rights reserved. This document contains proprietary information that
vcloud Director User's Guide
vcloud Director 5.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of
Oracle WebCenter Content Service for Microsoft Exchange
Oracle WebCenter Content Service for Microsoft Exchange Installation and Upgrade Guide 10g Release 3 (10.3) November 2008 Oracle WebCenter Content Service for Microsoft Exchange Installation and Upgrade
Installing and Using the vnios Trial
Installing and Using the vnios Trial The vnios Trial is a software package designed for efficient evaluation of the Infoblox vnios appliance platform. Providing the complete suite of DNS, DHCP and IPAM
Veeam Backup Enterprise Manager. Version 7.0
Veeam Backup Enterprise Manager Version 7.0 User Guide August, 2013 2013 Veeam Software. All rights reserved. All trademarks are the property of their respective owners. No part of this publication may
VMware Identity Manager Connector Installation and Configuration
VMware Identity Manager Connector Installation and Configuration VMware Identity Manager This document supports the version of each product listed and supports all subsequent versions until the document
Introduction to Mobile Access Gateway Installation
Introduction to Mobile Access Gateway Installation This document describes the installation process for the Mobile Access Gateway (MAG), which is an enterprise integration component that provides a secure
Core Protection for Virtual Machines 1
Core Protection for Virtual Machines 1 Comprehensive Threat Protection for Virtual Environments. Installation Guide e Endpoint Security Trend Micro Incorporated reserves the right to make changes to this
NSi Mobile Installation Guide. Version 6.2
NSi Mobile Installation Guide Version 6.2 Revision History Version Date 1.0 October 2, 2012 2.0 September 18, 2013 2 CONTENTS TABLE OF CONTENTS PREFACE... 5 Purpose of this Document... 5 Version Compatibility...
Deployment Guide. Deploying F5 BIG-IP Global Traffic Manager on VMware vcloud Hybrid Service
Deployment Guide Deploying F5 BIG-IP Global Traffic Manager on VMware vcloud Hybrid Service A. Introduction VMware vcloud Hybrid Service is an effective, flexible and reliable platform for enterprise customers
vshield Administration Guide
vshield Manager 5.1 vshield App 5.1 vshield Edge 5.1 vshield Endpoint 5.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by
vsphere Host Profiles
ESXi 5.1 vcenter Server 5.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions
Copyright 2012 Trend Micro Incorporated. All rights reserved.
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files,
How to Migrate Citrix XenApp to VMware Horizon 6 TECHNICAL WHITE PAPER
How to Migrate Citrix XenApp to VMware Horizon 6 TECHNICAL WHITE PAPER Table of Contents Introduction... 3 Horizon and XenApp Components Comparison.... 4 Preparing for the Migration.... 5 Three Approaches
Setup for Failover Clustering and Microsoft Cluster Service
Setup for Failover Clustering and Microsoft Cluster Service ESX 4.0 ESXi 4.0 vcenter Server 4.0 This document supports the version of each product listed and supports all subsequent versions until the
System Administration Training Guide. S100 Installation and Site Management
System Administration Training Guide S100 Installation and Site Management Table of contents System Requirements for Acumatica ERP 4.2... 5 Learning Objects:... 5 Web Browser... 5 Server Software... 5
Deploying the BIG-IP System v10 with Oracle Application Server 10g R2
DEPLOYMENT GUIDE Deploying the BIG-IP System v10 with Oracle Application Server 10g R2 Version 1.1 Table of Contents Table of Contents Deploying the BIG-IP system v10 with Oracle s Application Server 10g
vcenter Operations Manager for Horizon Supplement
vcenter Operations Manager for Horizon Supplement vcenter Operations Manager for Horizon 1.6 This document supports the version of each product listed and supports all subsequent versions until the document
User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream
User Manual Onsight Management Suite Version 5.1 Another Innovation by Librestream Doc #: 400075-06 May 2012 Information in this document is subject to change without notice. Reproduction in any manner
Acronis Backup & Recovery 11.5 Quick Start Guide
Acronis Backup & Recovery 11.5 Quick Start Guide Applies to the following editions: Advanced Server for Windows Virtual Edition Advanced Server SBS Edition Advanced Workstation Server for Linux Server
Setting Up Resources in VMware Identity Manager
Setting Up Resources in VMware Identity Manager VMware Identity Manager 2.4 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
RSA Authentication Manager 8.1 Virtual Appliance Getting Started
RSA Authentication Manager 8.1 Virtual Appliance Getting Started Thank you for purchasing RSA Authentication Manager 8.1, the world s leading two-factor authentication solution. This document provides
BlackBerry Enterprise Service 10. Version: 10.2. Configuration Guide
BlackBerry Enterprise Service 10 Version: 10.2 Configuration Guide Published: 2015-02-27 SWD-20150227164548686 Contents 1 Introduction...7 About this guide...8 What is BlackBerry Enterprise Service 10?...9
Configuring Secure Socket Layer and Client-Certificate Authentication on SAS 9.3 Enterprise BI Server Systems That Use Oracle WebLogic 10.
Configuring Secure Socket Layer and Client-Certificate Authentication on SAS 9.3 Enterprise BI Server Systems That Use Oracle WebLogic 10.3 Table of Contents Overview... 1 Configuring One-Way Secure Socket
VMware Data Recovery. Administrator's Guide EN-000193-00
Administrator's Guide EN-000193-00 You can find the most up-to-date technical documentation on the VMware Web site at: http://www.vmware.com/support/ The VMware Web site also provides the latest product
Deployment and Configuration Guide
vcenter Operations Manager 5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions
Connection Broker Managing User Connections to Workstations, Blades, VDI, and More. Quick Start with Microsoft Hyper-V
Connection Broker Managing User Connections to Workstations, Blades, VDI, and More Quick Start with Microsoft Hyper-V Version 8.1 October 21, 2015 Contacting Leostream Leostream Corporation http://www.leostream.com
CA Nimsoft Unified Management Portal
CA Nimsoft Unified Management Portal HTTPS Implementation Guide 7.6 Document Revision History Document Version Date Changes 1.0 June 2014 Initial version for UMP 7.6. CA Nimsoft Monitor Copyright Notice
VMware vcenter Operations Manager for Horizon Supplement
VMware vcenter Operations Manager for Horizon Supplement vcenter Operations Manager for Horizon 1.7 This document supports the version of each product listed and supports all subsequent versions until
VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.7
VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.7 This document supports the version of each product listed and supports all subsequent versions
VMware vcenter Single Sign-On Server
VMware Single Sign-On Technical White Paper TECHNICAL MARKETING DOCUMENTATION V 1.0/AUGUST 2013/JUSTIN KING Table of Contents Introduction.... 3 Background.... 3 Single Sign-On Operations.... 4 Deployment
Configuring High Availability for VMware vcenter in RMS Distributed Setup
Configuring High Availability for VMware vcenter in RMS Distributed Setup This chapter describes the process of configuring high availability for the VMware vcenter. It provides the prerequisites and procedures
VMware vsphere 5.0 Evaluation Guide
VMware vsphere 5.0 Evaluation Guide Auto Deploy TECHNICAL WHITE PAPER Table of Contents About This Guide.... 4 System Requirements... 4 Hardware Requirements.... 4 Servers.... 4 Storage.... 4 Networking....
VMware Software Manager - Download Service User's Guide
VMware Software Manager - Download Service User's Guide VMware Software Manager 1.1 This document supports the version of each product listed and supports all subsequent versions until the document is
Quick Start Guide. for Installing vnios Software on. VMware Platforms
Quick Start Guide for Installing vnios Software on VMware Platforms Copyright Statements 2010, Infoblox Inc. All rights reserved. The contents of this document may not be copied or duplicated in any form,
Secure IIS Web Server with SSL
Secure IIS Web Server with SSL EventTracker v7.x Publication Date: Sep 30, 2014 EventTracker 8815 Centre Park Drive Columbia MD 21045 www.eventtracker.com Abstract The purpose of this document is to help
Monitoring Hybrid Cloud Applications in VMware vcloud Air
Monitoring Hybrid Cloud Applications in ware vcloud Air ware vcenter Hyperic and ware vcenter Operations Manager Installation and Administration Guide for Hybrid Cloud Monitoring TECHNICAL WHITE PAPER
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER Table of Contents Introduction.... 3 Requirements.... 3 Horizon Workspace Components.... 3 SAML 2.0 Standard.... 3 Authentication
vcloud Air - Virtual Private Cloud OnDemand Networking Guide
vcloud Air - Virtual Private Cloud OnDemand Networking Guide vcloud Air This document supports the version of each product listed and supports all subsequent versions until the document is replaced by
Introduction to VMware vsphere Data Protection TECHNICAL WHITE PAPER
Introduction to VMware vsphere Data Protection TECHNICAL WHITE PAPER Table of Contents Introduction.... 3 Architectural Overview... 3 Deployment and Configuration.... 5 Administration.... 5 Backup....
vrealize Air Compliance OVA Installation and Deployment Guide
vrealize Air Compliance OVA Installation and Deployment Guide 14 July 2015 vrealize Air Compliance This document supports the version of each product listed and supports all subsequent versions until the
Configuring Single Sign-on from the VMware Identity Manager Service to WebEx
Configuring Single Sign-on from the VMware Identity Manager Service to WebEx VMware Identity Manager SEPTEMBER 2015 V 2 Configuring Single Sign-On from VMware Identity Manager to WebEx Table of Contents
Implementing Federal Personal Identity Verification for VMware View. By Bryan Salek, Federal Desktop Systems Engineer, VMware
Implementing Federal Personal Identity Verification for VMware View By Bryan Salek, Federal Desktop Systems Engineer, VMware Technical WHITE PAPER Introduction This guide explains how to implement authentication
VMware vrealize Operations for Horizon Installation
VMware vrealize Operations for Horizon Installation vrealize Operations for Horizon 6.0 This document supports the version of each product listed and supports all subsequent versions until the document
Setup for Failover Clustering and Microsoft Cluster Service
Setup for Failover Clustering and Microsoft Cluster Service Update 1 ESX 4.0 ESXi 4.0 vcenter Server 4.0 This document supports the version of each product listed and supports all subsequent versions until
Browser-based Support Console
TECHNICAL PAPER Browser-based Support Console Mass deployment of certificate Netop develops and sells software solutions that enable swift, secure and seamless transfer of video, screens, sounds and data
WHITE PAPER Citrix Secure Gateway Startup Guide
WHITE PAPER Citrix Secure Gateway Startup Guide www.citrix.com Contents Introduction... 2 What you will need... 2 Preparing the environment for Secure Gateway... 2 Installing a CA using Windows Server
Ajera 7 Installation Guide
Ajera 7 Installation Guide Ajera 7 Installation Guide NOTICE This documentation and the Axium software programs may only be used in accordance with the accompanying Axium Software License and Services
Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide
Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your computer.
Unifying Information Security. Implementing TLS on the CLEARSWIFT SECURE Email Gateway
Unifying Information Security Implementing TLS on the CLEARSWIFT SECURE Email Gateway Contents 1 Introduction... 3 2 Understanding TLS... 4 3 Clearswift s Application of TLS... 5 3.1 Opportunistic TLS...
VMware Mirage Web Manager Guide
Mirage 5.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of this document,
Advanced Service Design
vcloud Automation Center 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions
VMware Identity Manager Integration with Active Directory Federation Services 2.0
VMware Identity Manager Integration with Active Directory Federation Services 2.0 VMware Identity Manager J ULY 2015 V 2 Table of Contents Active Directory Federation Services... 2 Configuring AD FS Instance
1. If there is a temporary SSL certificate in your /ServerRoot/ssl/certs/ directory, move or delete it. 2. Run the following command:
C2Net Stronghold Cisco Adaptive Security Appliance (ASA) 5500 Cobalt RaQ4/XTR F5 BIG IP (version 9) F5 BIG IP (pre-version 9) F5 FirePass VPS HSphere Web Server IBM HTTP Server Java-based web server (generic)
DEPLOYMENT GUIDE Version 1.1. Deploying F5 with Oracle Application Server 10g
DEPLOYMENT GUIDE Version 1.1 Deploying F5 with Oracle Application Server 10g Table of Contents Table of Contents Introducing the F5 and Oracle 10g configuration Prerequisites and configuration notes...1-1
RSA Security Analytics
RSA Security Analytics Event Source Log Configuration Guide Microsoft Windows using Eventing Collection Last Modified: Thursday, July 30, 2015 Event Source Product Information: Vendor: Microsoft Event
SolarWinds Technical Reference
SolarWinds Technical Reference Using SSL Certificates in Web Help Desk Introduction... 1 How WHD Uses SSL... 1 Setting WHD to use HTTPS... 1 Enabling HTTPS and Initializing the Java Keystore... 1 Keys
VMware vcloud Automation Center 6.1
VMware vcloud Automation Center 6.1 Reference Architecture T E C H N I C A L W H I T E P A P E R Table of Contents Overview... 4 What s New... 4 Initial Deployment Recommendations... 4 General Recommendations...
