Using VMware vcenter SSO 5.5 with VMware vcloud Automation Center 6.1
|
|
|
- Willis Griffin
- 10 years ago
- Views:
Transcription
1 Using VMware vcenter SSO 5.5 with VMware vcloud Automation Center 6.1 Deployment Guide for High-Availability Configurations T E C H N I C A L W H I T E P A P E R
2 Table of Contents Introduction... 2 Overview... 2 Environment Prerequisites... 2 Create Certificate Authority Signed Certificates for vcenter SSO nodes and the vcenter SSO load balancer... 3 Configure the F5 Load Balancer for Use with vcenter SSO Nodes Deployed in an HA Configuration... 6 Install and Configure vcenter SSO 5.5 for High Availability Install vcenter SSO Server Node Install vcenter SSO Server Node Set Up the vcenter Single Sign-On System Environment Update the vcenter SSO Services to the vcenter SSO Load Balancer FQDN on vcenter SSO Server Node Updating Certificates on vcenter SSO Server Node Updating Certificates on vcenter SSO Server Node Configure an HA Deployment of vcenter SSO 5.5 for Integration with vcloud Automation Center Configure vcloud Automation Center to Use vcenter SSO T E C H N I C A L W H I T E P A P E R / 1
3 Introduction This white paper outlines the steps for performing an end-to-end implementation of vcenter Single Sign-On 5.5 U2 in a High Availability (HA) configuration (Active Passive configuration with automatic failover), and integration with vcloud Automation Center 6.1 for Single Sign-On that uses an F5 load balancer. Supported software components are: vcloud Automation Center 6.1 vcenter SSO 5.5 U2, U2a, or U2b (Windows-based installation). U2b is recommended. F5 load balancer, version BIG-IP Build Final Overview The installation and configuration of vcenter Single Sign-On 5.5 in a highly available (HA) configuration requires the use of an external load balancer (F5 load balancer); it also requires that the various components are implemented in the correct sequence. Failing to follow the documented sequence can create unpredictable consequences and/or dependencies on other components where dependencies should not be placed. The following list summarizes the steps for deploying vcenter SSO in a high-availability environment with vcloud Automation Center Creating Certificate Authority Signed Certificates for vcenter SSO nodes and vcenter SSO load balancer FQDN 2. Configuring an F5 Load Balancer for use with vcenter SSO nodes deployed in a HA Configuration (Active Passive configuration with automatic failover) 3. Installation and Configuration of vcenter SSO 5.5 U2 for High Availability a. Install vcenter SSO Server Node1 b. Install vcenter SSO Server Node 2 c. Setup vcenter Single Sign-On System Environment d. Update the vcenter SSO Services to vcenter SSO Load Balancer FQDN on vcenter SSO Server Node1 e. Updating Certificates on vcenter SSO Server Node1 f. Updating Certificates on vcenter SSO Server Node2 4. Configuring vcenter SSO 5.5 U2 HA setup for integration with vcloud Automation Center Configuring vcloud Automation Center 6.1 with vcenter SSO 5.5 U2 deployed in a HA Configuration (Active Passive configuration with automatic failover) for SSO Environment Prerequisites Before starting the implementation of vcenter SSO HA, you must ensure that certain elements of the environment are in place and fully functional, the following list identifies these elements. The process to create CA-signed certificates comprises following steps: 1. Creating a certificate request (csr) 2. Generating a signed certificate (cer) VMware has developed a tool called VMware vcenter Certificate Automation Tool that can be obtained from the VMware Download Center and is located in the Drivers and Tools section of the vsphere and vcloud Suite download pages (version: 5.5). You can use the vcenter Certificate Automation Tool to generate the certificate request (csr file) for vcenter SSO, but it does not provide the ability to create SubjectAltName values, in some scenarios this may be acceptable as the team providing certificates may ask for this information at request time. However, if this is not the case, you can manually create the certificate request (csr file) with the SubjectAltName values added, which is a requirement for the vcenter Single Sign- On HA configuration. The examples in this guide reference the values in the following table: Name Host Name FQDN IP Address SSO Load Balancer FQDN sso sso.vmware.local SSO Server 1 sso1 sso1.vmware.local SSO Server 2 sso2 sso2.vmware.local T E C H N I C A L W H I T E P A P E R / 2
4 Create Certificate Authority Signed Certificates for vcenter SSO nodes and the vcenter SSO load balancer After you complete and verify the prerequisites, you create certificates signed by a certificate authority. You configure vcenter SSO server nodes with these certificates later. Task ID Task Description Screenshot (optional) 1. Download and extract the VMware vcenter Certificate Automation Tool to a directory on vcenter SSO Server Node1. (In this example the zip file, ssl-certificate-updater-tool zip, is extracted to the C:\SSL-Tool directory). 2. On the first node for vcenter Single Sign-On, create a folder in which you can store the certificate files. These steps use the C:\Certs folder. 3. In the C:\Certs folder, create an SSO folder to organize your certificate requests and configuration files. T E C H N I C A L W H I T E P A P E R / 3
5 Task ID Task Description 4. Open a text editor on node1 and create a configuration file using the format provided here. Edit the text highlighted in bold and red with values for your environment. Save the configuration file to the C:\Certs\SSO directory as openssl_sso.cfg. Screenshot [ req ] default_bits = 2048 default_keyfile = rui.key distinguished_name = req_distinguished_name encrypt_key = no prompt = no string_mask = nombstr req_extensions = v3_req [ v3_req ] basicconstraints = CA:false keyusage = digitalsignature, keyencipherment, dataencipherment extendedkeyusage = serverauth, clientauth subjectaltname = DNS:sso1, DNS:sso1.vmware.local, DNS:sso2, DNS:sso2.vmware.local, DNS:sso.vmware.local, IP: [ req_distinguished_name ] countryname = US stateorprovincename = CA localityname = PA 0.organizationName = VMware organizationalunitname = vcenter Single Sign On commonname = sso.vmware.local 5. Open a command prompt and go to the VMware vcenter Certificate Automation Tool directory. In this example the files are extracted to the C:\SSL- Tool folder/ Type the following command: cd C:\SSL-Tool\tools\openssl 6. Run the following command to create the vcenter SSO certificate request and export the private key: openssl req -new -nodes -out C:\Certs\SSO\rui.csr -keyout C:\Certs\SSO\rui.key -config C:\Certs\SSO\openssl_sso.cfg The vcenter SSO certificate request and the private key files (rui.csr and rui.key) are now available at C:\Certs\SSO directory. T E C H N I C A L W H I T E P A P E R / 4
6 Task ID Task Description Screenshot (optional) 7. You can send the certificate request to your certificate issuing team or you can use Microsoft CA as the trusted root Certificate Authority. o If you are using your certificate issuing team, follow these steps: Send the vcenter SSO certificate request (rui.csr) to your Certificate issuing team and get the CA signed certificate (sso.cer) for vcenter SSO in Base-64 encoded X.509 (.CER) format. Copy the SSO CA-signed certificate (sso.cer) to the C:\Certs\SSO directory. o If you are using Microsoft CA as the trusted root Certificate authority to sign and issue the certificates for vcenter SSO, enable data encipherment, nonrepudiation, and client authentication on the certificate template. For more information about creating certificate templates in the Microsoft CA server, see VMware Knowledge Base article Creating a Microsoft Certificate Authority Template for SSL certificate creation in vsphere 5.x For more information about obtaining the vcenter SSO certificate using Microsoft CA, see Obtain vcenter SSO certificate (part of VMware KB article ) 8. Verify that the certificate issuing team has provided the root CA certificate (root64.cer) in Base-64 encoded X.509 (.CER) format. Copy the root CA certificate (root64.cer) to the C:\Certs\SSO directory. Note: Also get the intermediate CA certificates in Base-64 encoded X.509 (.CER) format if you have intermediate CA servers signing the certificate requests. 9. Open a command prompt and run the following commands to merge the sso.cer and root64.cer file into a.pem file: a) more C:\Certs\SSO\sso.cer >> C:\Certs\SSO\chain.pem b) more C:\Certs\SSO\root64.cer >> C:\Certs\SSO\chain.pem Note: If you have intermediate CA servers signing the certificate requests then you must to add them to t h e chain.pem file. The order must be vcenter SSO certificate, intermediate CA certificates, and root CA certificate. 10. Ensure that both the vcenter SSO certificate and key files (sso.cer and rui.key), and the root CA certificate (root64.cer) are provided to the F5 load balancer team for F5 configuration. T E C H N I C A L W H I T E P A P E R / 5
7 Configure the F5 Load Balancer for Use with vcenter SSO Nodes Deployed in an HA Configuration You can use the procedures in this section to configure an F5 load balancer to run vcenter SSO nodes that have been deployed in a high-availability configuration, an active/passive configuration with automatic failover. vcenter SSO 5.5 U2, U2a, and U2b are supported for use with vcloud Automation Center 6.1. U2b is the recommended version. The examples in this section reference the values shown in the following table. Name Host Name FQDN IP Address SSO Load Balancer FQDN sso sso.vmware.local SSO Server 1 sso1 sso1.vmware.local SSO Server 2 sso2 sso2.vmware.local Procedures in this section are based on the following load balancer environment: 1. F5 load balancer that is installed and licensed and for which DNS server configuration is complete 2. F5 load balancer running version Build Final for BIG-IP These steps may vary in a different F5 load balancer version. Procedure 1. Make a backup copy of the C:\Certs\sso directory on the vcenter SSO Server Node 1. This directory contains vcenter SSO CA signed certificates and the root CA certificate file root64.cer. 2. Using a supported web browser, open the F5 BIG-IP load balancer management interface ( and log in. 3. Upload the vcenter SSO certificate to the F5 load balancer. T E C H N I C A L W H I T E P A P E R / 6
8 a. From the Main tab on F5 user interface, select System>File Management. b. Click the SSL Certificate List tab. c. On the SSL Certificate List screen, click Import. d. For Import Type, select Certificate. e. For Certificate Name, select Create New and enter ssocert as the name. f. For Certificate Source, select Upload File and browse to the sso.cer file (the vcenter SSO certificate file) in the C:\Certs\sso directory you copied in step 1. g. Select the certificate file and click Open. The sso.cer file is selected in our example. T E C H N I C A L W H I T E P A P E R / 7
9 h. Click Import on the F5 load balancer interface. The ssocert is now imported. 4. Upload the vcenter SSO key to the F5 load balancer. a. On the SSL Certificate List screen, click Import. b. For Import Type, select Key. c. For Key Name, select Create New and enter ssokey as the name. d. For Key Source, select Upload File and browse to the rui.key file (vcenter SSO key file) in the C:\Certs\sso directory you copied in step 1. e. Click Open to select the rui.key file. T E C H N I C A L W H I T E P A P E R / 8
10 f. From the F5 load balancer interface, click Import. The ssokey is now imported. 5. Upload the CA root certificate to the F5 load balancer. a. On the SSL Certificate List screen, click Import. b. For Import Type, select Certificate. c. For Certificate Name, select Create New and enter VMwareLocalRoot. d. For Certificate Source, select Upload File and browse to the Root64.cer file (CA root certificate file) available at the C:\Certs\sso directory copied in step 1. e. Click Open to select the CA root certificate file. In our example, this is Root64. T E C H N I C A L W H I T E P A P E R / 9
11 f. Click Import. The CA root certificate is now imported. 6. Verify that the Common Name for ssocert is sso.vmware.local, 7. Create a VLAN as specified in the next screenshot. a. Select Network>VLANs>VLAN list. b. Click Create. c. Provide the details and click Finished. T E C H N I C A L W H I T E P A P E R / 10
12 8. Configure the Interfaces List. Ensure that interface 1.1 is up and interfaces 1.2 and 1.3 are disabled. a. Select Network>Interfaces >Interface List. b. Select 1.2 and 1.3 under Name and then click Disable. Note: This solution uses Management and Internal Interfaces. External (1.2) and HA (1.3) are disabled in this configuration. 9. Configure Self-IP. a. In the F5 load balancer console, select Network > Self IPs. b. Click Create. c. In the Name text box, enter Internal. d. Enter values for the Self IP in the IP Address and Netmask text boxes. e. From the VLAN/Tunnel dropdown menu, select internal. f. From the Port Lockdown dropdown menu, select Allow Default. g. From the Traffic Group dropdown menu, select traffic-group-local-only (non-floating). h. Click Finished. T E C H N I C A L W H I T E P A P E R / 11
13 10. Create the load balancer pool by using the two SSO servers as the two member nodes. a. Select Local Traffic>Pools>Pools List. b. On the Pools List screen, click Create. c. Enter a name in the Name text box; for example, SSO. d. In the Health Monitors area, select and add tcp to the Active column. e. Select Round Robin from the Load Balancing Method drop-down menu. f. Select Less than from the Priority Group Activation text box. g. Enter 1 in the Available Members text box. h. In the New Members area, select the New Node option and create a new member: Enter sso1 as the node name in the Node Name text box. Enter an Address: (this is the IP address of SSO Server Node1 in our example). Enter a Service Port: 7444 and HTTPS. Enter a Priority: 10. Click Add. Enter a Node Name for the second node: sso2. Enter an Address: (this is the IP address of SSO Server Node2 in our example). Enter a Service Port: 7444 and HTTPS. Enter a Priority: 1. Click Add. Click Finished. T E C H N I C A L W H I T E P A P E R / 12
14 11. Add ICMP as the Default Monitor for Nodes. a. Select Local Traffic>Nodes> Default Monitor. b. Select and add icmp to the Active column. c. Click Update. 12. Create an SSL client profile: a. Select Local Traffic>Profiles from the left-hand menu. b. Click SSL. c. Click Client. d. On the Client screen, click Create. T E C H N I C A L W H I T E P A P E R / 13
15 e. Enter a name, for example, SSO-Client, in the Name text box. f. Select the Custom checkbox. g. In the Configuration area, select Basic from the drop-down menu. h. Select ssocert from the Certificate drop-down menu. i. Select ssokey from the Key drop-down menu. j. Clicked Finished. 13. Create an SSL server profile: a. Select Local Traffic > Profiles. b. Click SSL. c. Click Server. d. On the Server screen, click Create. e. Enter a Name: SSO-Server. f. Select the Custom checkbox on the right-hand side. g. Under Configuration: i. For Certificate, choose ssocert. ii. For Key, choose ssokey. T E C H N I C A L W H I T E P A P E R / 14
16 h. Click Finished. 14. Create a Virtual Server. This will use the load balancer IP address ( in our example): a. Choose Local Traffic from left-hand menu. b. Choose Virtual Servers. c. Choose Virtual Server List. d. On the Virtual Servers screen, click Create. e. Enter a Name: SSO-VIP f. Provide a Destination: i. For Type, select Host. ii. Enter an Address: (this is the load balancer IP address in our example) g. Enter a Service Port: 7444 and HTTPS h. Under Configuration. i. For HTTP Profile, choose http. T E C H N I C A L W H I T E P A P E R / 15
17 ii. For SSL Profile (Client): choose SSO-Client. iii. For SSL Profile (Server): choose SSO-Server. iv. For Source Address Translation choose Auto Map. i. Under Resources: i. For Default Pool: choose SSO. ii. For Default Persistence Profile, select None. j. Click Finished. 15. Do not make any entry for SNAT. 16. Ensure the vcenter SSO load balancer virtual address is added to your DNS server. Using our example, add an entry for sso.vmware.local into your DNS server) T E C H N I C A L W H I T E P A P E R / 16
18 Install and Configure vcenter SSO 5.5 for High Availability Before you begin the implementation of vcenter SSO HA verify that the following prerequisites are met: o o o o o o Creation of SSO nodes as Virtual Machines Registration of SSO nodes within a DNS service Installation of the VMware vcenter Certificate Automation Tool (ssl-certificate-updater-tool zip) on both SSO nodes. You can obtain the tool from the VMware Download Center in the Drivers and Tools section of the vsphere and vcloud Suite download pages (version: 5.5). CA-signed certificates for SSO nodes and SSO load balancer FQDN A fully configured F5 load balancer The SSO load balancer FQDN must be registered within a DNS service The examples in this section reference the values in the following table: Component Hostname FQDN IP Address SSO Node1 sso1 sso1.vmware.local SSO Node2 sso2 sso2.vmware.local SSO Load Balancer FQDN sso sso.vmware.local T E C H N I C A L W H I T E P A P E R / 17
19 Install vcenter SSO Server Node 1 Once you have completed all environmental preparation tasks, you are ready to start following the procedure captured here to implement the first node of the vcenter Single Sign-On HA setup. Task ID Task Description Screenshot 1. Start the VMware vsphere installer by clicking autorun.exe. 2. From the VMware vsphere installer menu, select vcenter Single Sign-On. Click Install. 3. At the Welcome to the vcenter Single Sign-On Setup dialog, click Next. T E C H N I C A L W H I T E P A P E R / 18
20 Task ID Task Description Screenshot 4. At the End-User License Agreement dialog, click the I accept the terms in the License Agreement check box. Click Next. 5. The vcenter Single Sign-On Prerequisites Check dialog appears and the installation wizard detects the system configuration. Verify that the FQDN and IP Address are correct. By default the Add domain_name as a native Active Directory identity source check box is selected. Note: For large Active Directory domains the installer can appear to hang and eventually times out and rolls back while trying to complete this task, in these situations clear the checkbox and add the domain at a later stage. Click Next. 6. At the vcenter Single Sign-On Information dialog for deployment mode, select the Standalone vcenter Single Sign-On Server button. Click Next. T E C H N I C A L W H I T E P A P E R / 19
21 Task ID Task Description Screenshot 7. At the vcenter Single Sign-On Information dialog for administrator account credentials, type the password for the administrator in the Password text box. Reenter the password in the Confirm Password text box. Click Next. 8. At the vcenter Single Sign-On Configure Site dialog, type a unique site name into the Site name text box or accept the default. Click Next. 9. At the vcenter Single Sign-On Port Settings dialog, unless you have a requirement to alter the default HTTPS port, leave the default value of Click Next. Note: The remaining procedures assume that the default port of 7444 is used. T E C H N I C A L W H I T E P A P E R / 20
22 Task ID Task Description Screenshot 10. At the Change destination folder dialog, accept the default path by clicking Next. 11. At the vcenter Single Sign-On Information dialog for install options, review the install options. Click Install. 12. At the Completed the vcenter Single Sign-On Setup Wizard dialog, click Finish. T E C H N I C A L W H I T E P A P E R / 21
23 Install vcenter SSO Server Node 2 Once the first node has been installed, you must proceed to performing the installation of the second node, this is performed in similar way as the first node but with one key alteration in that you must specify a different deployment mode. Follow the step-by-step procedure documented to complete the installation of the second node of the vcenter Single Sign-On HA setup. Task ID Task Description Screenshot 1. Launch the VMware vsphere installer by clicking the autorun.exe. 2. From the VMware vsphere installer menu, select vcenter Single Sign-On. Click Install. 3. At the Welcome to the vcenter Single Sign- On Setup dialog, click Next. T E C H N I C A L W H I T E P A P E R / 22
24 Task ID Task Description Screenshot 4. At the End-User License Agreement dialog, click the I accept the terms in the License Agreement check box. Click Next. 5. At the vcenter Single Sign-On Prerequisites Check dialog, the install wizard detects the system configuration. Verify that the FQDN and IP Address are correct. Because this the second node in the site, uncheck the Add domain_name as a native Active Directory identity source check box. Click Next. 6. At the vcenter Single Sign-On Information dialog for deployment modes, select High availability. Click Next. T E C H N I C A L W H I T E P A P E R / 23
25 Task ID Task Description Screenshot 7. At the vcenter Single Sign-On Information dialog for partner information, enter the following values: FQDN of the first Single Sign-On node in the Partner host name text box (sso1.vmware.local) Password used for account during the first node installation in the Password text box Click Next. 8. At the Partner certificate dialog, click Continue to accept the certificate. 9. At the vcenter Single Sign-On Join Site dialog, use the drop-down menu to select the vcenter Single Sign-On site you wish to join. Click Next. Note: The site name should match the site name specified in Step 8 in the Install vcenter SSO Server Node1 section. T E C H N I C A L W H I T E P A P E R / 24
26 Task ID Task Description Screenshot 10. At the vcenter Single Sign-On Port Settings dialog, unless you have a requirement to alter the default HTTPS port, leave the default value of Click Next. 11. At the Change destination folder dialog, accept the default path by clicking Next. 12. At the vcenter Single Sign-On Information dialog for install options, review your selections. Click Install. T E C H N I C A L W H I T E P A P E R / 25
27 Task ID Task Description Screenshot 13. At the Completed the vcenter Single Sign- On Setup Wizard dialog, click Finish. Set Up the vcenter Single Sign-On System Environment During the configuration process there are numerous command line tasks that must be performed which by default require you to be positioned within the physical directory; this can be alleviated by simply performing a few simple environmental configuration steps within each vcenter Single Sign-On node. This section provides the steps to perform the following tasks: Configure the JAVA_HOME system variable Add additional paths to the PATH system variable Perform these steps on all SSO nodes (SSO node1 and SSO node2) Task ID Task Description Screenshot 1. Launch the system properties by clicking Start. Then right click on Computer and select Properties from the menu. T E C H N I C A L W H I T E P A P E R / 26
28 Task ID Task Description Screenshot 2. On the left-hand side, click Advanced system settings. 3. At the System Properties dialog, click Environment Variables. 4. At the Environment Variables dialog, under System variables, click New. T E C H N I C A L W H I T E P A P E R / 27
29 Task ID Task Description Screenshot 5. Create a new variable for the java home folder by entering the following details: Enter JAVA_HOME in the Variable Name text box Enter the path C:\Program Files\Common Files\VMware\VMware vcenter Server - Java Components in the Variable Value text box Click OK. 6. At the Environment Variables dialog under System variables, locate Path. Click Edit. 7. At the Edit System Variables dialog, within the Variable Values text box go to the end and add the following entries with a ; between each: C:\Program Files\VMware\Infrastructure\VM ware\cis\vmware-sso %JAVA_HOME%\bin Click OK three times to save and exit the Environment Variables dialog. T E C H N I C A L W H I T E P A P E R / 28
30 Update the vcenter SSO Services to the vcenter SSO Load Balancer FQDN on vcenter SSO Server Node1 We now need to create property files with the vcenter SSO load balancer FQDN (sso.vmware.local) and update the vcenter SSO services (STS, Admin and GroupCheck). Task ID Task Description Screenshot 1. Open a command prompt and create three empty text files using the following commands: cd C:\Certs\SSO copy con C:\Certs\SSO\sts.properties Press F6 and Enter copy con C:\Certs\SSO\admin.properties Press F6 and Enter copy con C:\Certs\SSO\gc.properties Press F6 and Enter 2. Copy the root certificate to the VMware STS folder on both nodes using the following command: copy C:\Certs\SSO\root64.cer C:\ProgramData\VMware\CIS\runti me\vmwarests\conf\ 3. Edit the sts.properties file in a text editor and enter the details as they appear on the right. Save the file. [service] friendlyname=the security token service interface of the SSO server version=1.5 ownerid= type=urn:sso:sts description=the security token service interface of the SSO server [endpoint0] uri= Service/vsphere.local ssl=c:\programdata\vmware\cis\runtime\vmw arests\conf\root64.cer protocol=wstrust T E C H N I C A L W H I T E P A P E R / 29
31 Task ID Task Description Screenshot 4. Edit the admin.properties file in a text editor and enter the details as they appear on the right. Save the file. [service] friendlyname=the administrative interface of the SSO server version=1.5 ownerid= type=urn:sso:admin description= The administrative interface of the SSO server [endpoint0] uri= ssl=c:\programdata\vmware\cis\runtime\vmw arests\conf\root64.cer protocol=vmomi 5. Edit the gc.properties file in a text editor and enter the details as they appear on the right. Save the file. [service] friendlyname=the group check interface of the SSO server version=1.5 ownerid= type=urn:sso:groupcheck description= The group check interface of the SSO server [endpoint0] uri= ssl=c:\programdata\vmware\cis\runtime\vmw arests\conf\root64.cer protocol=vmomi 6. Using the ssolscli command, list the vcenter SSO services (STS, Admin and GroupCheck) to obtain their service IDs: ssolscli listservices upservice/sdk Capture the service ID for each service returned as the first field, will be displayed as: serviceid=<ssositename>:<thirty two digit hexadecimal value> T E C H N I C A L W H I T E P A P E R / 30
32 Task ID Task Description Screenshot 7. Using the service IDs captured for vcenter SSO services (STS, Admin and GroupCheck) in step 6, run the following echo commands to capture the service IDs to a file for use in the service update steps: echo <sts-serviceid> >> C:\Certs\SSO\sts_id echo <admin-serviceid> >> C:\Certs\SSO\admin_id echo <gc-serviceid> >> C:\Certs\SSO\gc_id 8. Updating vcenter SSO services must be performed in the order stated within this document which is STS, Admin and GroupCheck. 9. Update the STS service by running the following command: ssolscli updateservice -d upservice/sdk -u [email protected] -p <password> -si C:\Certs\SSO\sts_id -ip C:\Certs\SSO\sts.properties Note: Wait at least 30 seconds to allow the SSO nodes to sync. 10. Update the Admin service by running the following command: ssolscli updateservice -d upservice/sdk -u [email protected] -p password -si C:\Certs\SSO\admin_id -ip C:\Certs\SSO\admin.properties Note: Wait at least 30 seconds to allow the SSO nodes to sync. 11. Update the Groupcheck service by running the following command: ssolscli updateservice -d upservice/sdk -u [email protected] -p password -si C:\Certs\SSO\gc_id -ip C:\Certs\SSO\gc.properties Note: Wait at least 30 seconds to allow the SSO nodes to sync 12. If you receive a Server certificate assertion not verified and thumbprint not matched error during update of vcenter SSO services, follow step 14 to restart the VMware Security Token Service and repeat the command. T E C H N I C A L W H I T E P A P E R / 31
33 Task ID Task Description Screenshot 13. Verify that the vcenter SSO services (STS, Admin and GroupCheck) have been updated on SSO Node1 to the VCenter SSO load balancer FQDN by running the following command: ssolscli listservices upservice/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. 14. Restart the VMwareSTS service by running the following commands: net stop VMwareSTS net start VMwareSTS 15. Verify that the vcenter SSO Node1 responds with the correct vcenter SSO services information by running the following command: ssolscli listservices upservice/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. T E C H N I C A L W H I T E P A P E R / 32
34 Updating Certificates on vcenter SSO Server Node1 Now we must update the certificates on the first vcenter SSO node before we can reconfigure the remaining services. This procedure is performed using the VMware vcenter Certificate Automation Tool on both SSO nodes, which can be obtained from the VMware Download Center and is located in the Drivers and Tools section of the vsphere and vcloud Suite download pages (version: 5.5). Task ID Task Description Screenshot 1. Open a command prompt and go to the VMware vcenter Certificate Automation Tool directory (for this example the files were extracted to the C:\SSL-Tool folder). cd C:\SSL-Tool 2. Start the SSL Updater tool by running the following command: ssl-updater.bat The main menu appears. Type 3, and then press Enter. 3. The Update the Single Sign-On SSL Certificate menu appears. Type 1, and then press Enter. 4. You are presented with a series of questions about your environment. Sample responses are shown in red and boldface type; use these values as guidelines for your responses and alter them as needed for your environment. Enter location to the new Single Sign-On SSL chain: C:\Certs\SSO\chain.pem Enter location to the new Single Sign-On private key: C:\Certs\SSO\rui.key Enter Single Sign-On Administrator user: [email protected] Enter Single Sign-On Administrator password: <password> Do you have a load balancer installed?: yes Is the current machine hosting a primary Single Sign-On node?: yes Is the Single Sign-On administration services accessed via the load balancer?: yes Enter the Single Sign-On HA Load Balancer certificate: C:\Certs\SSO\sso.cer Enter the Single Sign-On HA Load Balancer hostname: sso.vmware.local T E C H N I C A L W H I T E P A P E R / 33
35 Task ID Task Description Screenshot 5. When the process finishes, the status message Last operation update Single Sign- On SSL certificates completed successfully appears. Type 3 at the prompt, and press Enter to return to the main menu. 6. Type 9 at the main menu prompt and press Enter to exit the SSL Update tool. 7. Verify that the vcenter SSO Node1 responds with the correct vcenter SSO services information by running the following command: ssolscli listservices service/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. T E C H N I C A L W H I T E P A P E R / 34
36 Task ID Task Description Screenshot 8. Verify that the vcenter SSO load balancer FQDN responds with the correct vcenter SSO services information by running the following command: ssolscli listservices ervice/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. 9. Verify that the vcenter SSO Node2 responds with the correct vcenter SSO services information by running the following command: ssolscli listservices service/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. T E C H N I C A L W H I T E P A P E R / 35
37 Updating Certificates on vcenter SSO Server Node2 We can now update the certificates on the second vcenter SSO node by following the procedure below. Task ID Task Description Screenshot 1. Copy the C:\Certs\SSO folder from vcenter SSO node1 to node2. 2. Open a command prompt and go to the VMware vcenter Certificate Automation Tool directory (for this example the files were extracted to the C:\SSL-Tool folder). cd C:\SSL-Tool T E C H N I C A L W H I T E P A P E R / 36
38 Task ID Task Description Screenshot 3. Start the SSL Updater tool by running the following command: ssl-updater.bat The main menu appears. Type 3, and then press Enter. 4. The Update the Single Sign-On SSL Certificate menu appears. Type 1, and then press Enter. 5. You are presented with a series of questions about your environment. Sample responses are shown in red and boldface type; use these values as guidelines for your responses and alter them as needed for your environment. Note: Remember that this is not a primary node. Enter location to the new Single Sign-On SSL chain: C:\Certs\SSO\chain.pem Enter location to the new Single Sign-On private key: C:\Certs\SSO\rui.key Enter Single Sign-On Administrator user: [email protected] Enter Single Sign-On Administrator password: <password> Do you have a load balancer installed?: yes Is the current machine hosting a primary Single Sign-On node?: no Is the Single Sign-On administration services accessed via the load balancer?: yes Enter the Single Sign-On HA Load Balancer certificate: C:\Certs\SSO\sso.cer Enter the Single Sign-On HA Load Balancer hostname: sso.vmware.local 6. When the process finishes, the status message Last operation update Single Sign- On SSL certificates completed successfully appears. Type 3 at the prompt, and press Enter to return to the main menu. 7. Type 9 at the main menu prompt and press Enter to exit the SSL Update tool. T E C H N I C A L W H I T E P A P E R / 37
39 Task ID Task Description Screenshot 8. Verify that the vcenter SSO Node2 responds with the correct vcenter SSO services information by running the following command: ssolscli listservices ervice/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. 9. Verify that the vcenter SSO load balancer FQDN responds with the correct vcenter SSO services information by running the following command: ssolscli listservices service/sdk Note: The endpoints entry should now show the vcenter SSO load balancer URL (sso.vmware.local) for each service. 10. Test vcenter SSO automatic failover by shutting down vcenter SSO Node1. You can simulate the node1 down scenario by updating the node1s state to Forced Offline from F5 load balancer Admin UI. Repeat steps 8 and 9. T E C H N I C A L W H I T E P A P E R / 38
40 Configure an HA Deployment of vcenter SSO 5.5 for Integration with vcloud Automation Center This procedure is used to configure a high availability (HA) deployment of vcenter SSO 5.5 for integration with vcloud Automation Center 6.1. You must use a supported version of vcenter SSO 5.5 U2. Before you begin, back up or take a snapshot of all vcenter SSO nodes. Edit the hostname.txt and sever.xml Files Edit the hostname.txt and server.xml files for each vcenter SSO node to specify new host name and proxy information. 1. Locate and open the hostname.txt file in the C:\ProgramData\VMware\CIS\cfg\wmware-sso directory. 2. Replace the hostname with the fully qualified domain name (FQDN) for the vcenter SSO load balancer, as shown in the following example: 3. Locate and open the server.xml file in the C:\ProgramData\VMware\CIS\runtime\VMwareSTS\conf directory. 4. Locate the element <Connector SSLEnabled= true > and add the following attributes: proxyname= sso.vmware.local proxyport= 7444 T E C H N I C A L W H I T E P A P E R / 3 9
41 5. Repeat these steps for each vcenter SSO node. Replace the STS Certificate and Reinstall the STS Component Replace the STS Signing Certificate on all additional vcenter SSO nodes with that of the first vcenter SSO node. Perform the following steps on all vcenter SSO nodes except the first vcenter SSO node. 1. Open a Windows Explorer window and go to C:\ProgramData\VMware\CIS\cfg\vmware-sso on second vcenter SSO node. 2. Create a new folder named backup. 3. Copy the files in the sso folder to the backup folder. 4. Copy the following files in the C:\ProgramData\VMware\CIS\cfg\vmware-sso directory from the first vcenter SSO node to the second vcenter SSO node (replace the files if prompted). ssoserverroot.crt ssoserversign.crt ssoserversign.pub ssoserversign.key 5. Stop STS and Identity Management services by opening a command prompt and entering the following commands: net stop VMwareSTS net stop VMwareIdentityMgmtService 6. Use Jxplorer to connect to LDAP on the second vcenter SSO node. You can download and install JXplorer from Use the following selections to establish a connection. Host: Port: sso2.vmware.local Protocol: <use the default> Base DN: DC=vsphere,DC=local Level: User + Password T E C H N I C A L W H I T E P A P E R / 40
42 User DN: CN=administrator,CN=users,DC=vsphere,DC=local Password: <password> 7. Locate the STS Certificate records for the second vcenter SSO node and delete the TenantCredential-1 and TrustedCertChain-1 attributes. a. Select local>vsphere>componentmanager>ldus. Each SSO node is listed. b. Expand the entries under Ldus. c. Select TenantCredential-1 for the second node, d. Click Properties. e. From the Table Editor tab, locate the modifiersname attribute. Check that the value matches the second vcenter SSO node to confirm that this is the second vcenter SSO. If it is not, continue checking entries under Ldus. f. Delete the TenantCredential-1 entry that references the second vcenter SSO node. g. Expand TrustedCertificateChains and select TrustedCertChain-1 for the second vcenter SSO node. h. Click Properties. i. From the Table Editor tab, locate the modifiersname attribute. Check that the value matches the second vcenter SSO node. j. Delete the TrustedCertChain -1 entry. Note: Repeat this process for every vcenter SSO node except for the first node. T E C H N I C A L W H I T E P A P E R / 41
43 8. Start the Identity Management Service by opening a command prompt and typing the following command. net start VMwareIdentityMgmtService 9. Reinstall the STS component using the following procedure. a. Open a command prompt and navigate to C:\ProgramData\VMware\CIS\cfg\vmware-sso. b. Cut and paste the following command to your command prompt. Note that this is a single command. c:\program Files\Common Files\VMware\VMware vcenter Server - Java Components\bin\java.exe -cp c:\program Files\VMware\Infrastructure\VMware\CIS\vmware-sso\*;c:\Program Files\VMware\Infrastructure\VMware\CIS\vmware-sso\lib\*;.;* com.vmware.identity.installer.stsinstaller --install --root-cert-path ssoserverroot.crt --cert-path ssoserversign.crt --private-key-path ssoserversign.key --retry-count 2 --retry-interval Verify that the command returns a success message. T E C H N I C A L W H I T E P A P E R / 42
44 11. Open a command prompt and enter the following command to start the STS Service. net start VMware STS 12. For all nodes, run the following command to verify that the vcenter SSO services are running and reference the vcenter SSO load balancer URL. ssolsclistservices Validate the vcenter SSO Configuration Verify that certificates are correctly updated for all vcenter SSO nodes in the HA deployment, including the first node. Perform the following steps for each vcenter SSO node. 1. Download and open the file where <ssonode> represents the SSO node server name 2. Verify that the value for <ds:x509certificate> is the same for all SSO nodes. 3. Verify that each Location attribute uses the FQDN for the load balancer and not the hostname of the node T E C H N I C A L W H I T E P A P E R / 43
45 Configure vcloud Automation Center to Use vcenter SSO Configure the SSO settings that the vcloud Automation Center Appliance uses to interact with the vcenter SSO. You must use a supported version of vcenter SSO Deploy the vcloud Automation Center appliances as described in the vcloud Automation Center 6.1 Installation Guide, available at: Automation Center-61/topic/com.vmware.ICbase/PDF/vcloudautomation-center-61-installation-and-configuration.pdf. 2. Configure the vcloud Automation Center Appliance as described in the topic Configure the vcloud Automation Center Appliance in the vcloud Automation Center 6.1 Installation Guide. When you configure SSO settings, provide the FQDN and port for the vcenter SSO load balancer in the SSO Host and Port text box. For example: sso.vmware.local: After you configure the appliance, verify that you can log in to the vcloud Automation Center console. a. Open a browser and go to b. If you are prompted, continue past the certificate warnings. c. Login with [email protected] and the password that you specified when you configured the single sign-on server. 4. Verify that automatic failover is working. a. Shut down vcenter SSO node1. You can do this from the F5 administrator user interface by changing the node state to Forced Offline. b. Repeat step 3 to confirm that you can login to vcloud Automation Center console after automatic failover of vcenter SSO node1 to node2. This completes the configuration and integration of vcenter SSO 5.5 U2 with vcloud Automation Center 6.1 in a highavailability environment. T E C H N I C A L W H I T E P A P E R / 44
46 About the Author Muzibur Shaik is a Staff Engineer at VMware in the vcloud Automation Center group. Acknowledgements VMware would like to acknowledge the following individuals for their contributions to this paper and help with content review: VCloud Automation Center Carl Prahl Technical Documentation Sally Hehir VMware, Inc Hillview Avenue Palo Alto CA USA Tel Fax Copyright 2014 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
VMware vcenter Server 5.5 Deploying a Centralized VMware vcenter Single Sign-On Server with a Network Load Balancer
VMware vcenter Server 5.5 Deploying a Centralized VMware vcenter Single Sign-On Server with a Network Load Balancer Technical Reference TECHNICAL MARKETING DOCUMENTATION V 1.0/FebrUARY 2014/JUSTIN KING,
Installing and Configuring vcloud Connector
Installing and Configuring vcloud Connector vcloud Connector 2.7.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Replacing Default vcenter Server 5.0 and ESXi Certificates
Replacing Default vcenter Server 5.0 and ESXi Certificates vcenter Server 5.0 ESXi 5.0 This document supports the version of each product listed and supports all subsequent versions until the document
Installing and Configuring vcloud Connector
Installing and Configuring vcloud Connector vcloud Connector 2.0.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Replacing vcenter Server 4.0 Certificates VMware vsphere 4.0
Technical Note Replacing vcenter Server 4.0 Certificates VMware vsphere 4.0 Certificates are automatically generated when you install vcenter Server and ESX/ESXi. These default certificates are not signed
Reconfiguring VMware vsphere Update Manager
Reconfiguring VMware vsphere Update Manager vsphere Update Manager 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
VMware vcenter Support Assistant 5.1.1
VMware vcenter.ga September 25, 2013 GA Last updated: September 24, 2013 Check for additions and updates to these release notes. RELEASE NOTES What s in the Release Notes The release notes cover the following
Installing and Configuring vcenter Support Assistant
Installing and Configuring vcenter Support Assistant vcenter Support Assistant 5.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
Installing and Configuring vcenter Multi-Hypervisor Manager
Installing and Configuring vcenter Multi-Hypervisor Manager vcenter Server 5.1 vcenter Multi-Hypervisor Manager 1.1 This document supports the version of each product listed and supports all subsequent
Reconfiguration of VMware vcenter Update Manager
Reconfiguration of VMware vcenter Update Manager Update 1 vcenter Update Manager 4.1 This document supports the version of each product listed and supports all subsequent versions until the document is
Deployment Guide. Deploying F5 BIG-IP Global Traffic Manager on VMware vcloud Hybrid Service
Deployment Guide Deploying F5 BIG-IP Global Traffic Manager on VMware vcloud Hybrid Service A. Introduction VMware vcloud Hybrid Service is an effective, flexible and reliable platform for enterprise customers
VMware Identity Manager Connector Installation and Configuration
VMware Identity Manager Connector Installation and Configuration VMware Identity Manager This document supports the version of each product listed and supports all subsequent versions until the document
Reconfiguring VMware vsphere Update Manager
Reconfiguring VMware vsphere Update Manager vsphere Update Manager 5.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
vrealize Automation Load Balancing
vrealize Automation Load Balancing Configuration Guide Version 6.2 T E C H N I C A L W H I T E P A P E R A U G U S T 2 0 1 5 V E R S I O N 1. 0 Table of Contents Introduction... 4 Load Balancing Concepts...
Managing Multi-Hypervisor Environments with vcenter Server
Managing Multi-Hypervisor Environments with vcenter Server vcenter Server 5.1 vcenter Multi-Hypervisor Manager 1.0 This document supports the version of each product listed and supports all subsequent
Configuring Multiple ACE Management Servers VMware ACE 2.0
Technical Note Configuring Multiple ACE Management Servers VMware ACE 2.0 This technical note describes how to configure multiple VMware ACE Management Servers to work together. VMware recommends this
App Orchestration 2.5
Configuring NetScaler 10.5 Load Balancing with StoreFront 2.5.2 and NetScaler Gateway for Prepared by: James Richards Last Updated: August 20, 2014 Contents Introduction... 3 Configure the NetScaler load
Activating HTTPS using wildcard certificate in Horizon Application Manager 1.5
Activating HTTPS using wildcard certificate in Horizon Application Manager 1.5 Authors: Rasmus Jensen, Sr. Specialist Consultant EUC, NEMEA, VMware Inc. Peter Björk, EMEA Horizon & ThinApp Specialist Systems
Configuring Single Sign-On from the VMware Identity Manager Service to Office 365
Configuring Single Sign-On from the VMware Identity Manager Service to Office 365 VMware Identity Manager JULY 2015 V1 Table of Contents Overview... 2 Passive and Active Authentication Profiles... 2 Adding
Offline Data Transfer to VMWare vcloud Hybrid Service
Offline Data Transfer to VMWare vcloud Hybrid Service vcloud Connector 2.5.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
Scenarios for Setting Up SSL Certificates for View
Scenarios for Setting Up SSL Certificates for View VMware Horizon 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
F-Secure Messaging Security Gateway. Deployment Guide
F-Secure Messaging Security Gateway Deployment Guide TOC F-Secure Messaging Security Gateway Contents Chapter 1: Deploying F-Secure Messaging Security Gateway...3 1.1 The typical product deployment model...4
Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates
Entrust Managed Services Entrust Managed Services PKI Configuring secure LDAP with Domain Controller digital certificates Document issue: 1.0 Date of issue: October 2009 Copyright 2009 Entrust. All rights
Sophos Mobile Control Installation guide. Product version: 3.5
Sophos Mobile Control Installation guide Product version: 3.5 Document date: July 2013 Contents 1 Introduction...3 2 The Sophos Mobile Control server...4 3 Set up Sophos Mobile Control...10 4 External
Configuring VMware vrealize Automation High Availability Using an F5 Load Balancer
Configuring VMware vrealize Automation High Availability Using an F5 Load Balancer Deployment Guide for High-Availability Configurations Version 6.1 and Later T E C H N I C A L W H I T E P A P E R Contents
How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal 1.1.3 On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (
Avaya one X Portal 1.1.3 Lightweight Directory Access Protocol (LDAP) over Secure Socket Layer (SSL) Configuration This document provides configuration steps for Avaya one X Portal s 1.1.3 communication
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER Table of Contents Introduction.... 3 Requirements.... 3 Horizon Workspace Components.... 3 SAML 2.0 Standard.... 3 Authentication
Upgrading VMware Identity Manager Connector
Upgrading VMware Identity Manager Connector VMware Identity Manager This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
ADFS Integration Guidelines
ADFS Integration Guidelines Version 1.6 updated March 13 th 2014 Table of contents About This Guide 3 Requirements 3 Part 1 Configure Marcombox in the ADFS Environment 4 Part 2 Add Relying Party in ADFS
NSi Mobile Installation Guide. Version 6.2
NSi Mobile Installation Guide Version 6.2 Revision History Version Date 1.0 October 2, 2012 2.0 September 18, 2013 2 CONTENTS TABLE OF CONTENTS PREFACE... 5 Purpose of this Document... 5 Version Compatibility...
WhatsUp Gold v16.3 Installation and Configuration Guide
WhatsUp Gold v16.3 Installation and Configuration Guide Contents Installing and Configuring WhatsUp Gold using WhatsUp Setup Installation Overview... 1 Overview... 1 Security considerations... 2 Standard
Installation and Configuration Guide
Entrust Managed Services PKI Auto-enrollment Server 7.0 Installation and Configuration Guide Document issue: 1.0 Date of Issue: July 2009 Copyright 2009 Entrust. All rights reserved. Entrust is a trademark
Installing and Configuring DB2 10, WebSphere Application Server v8 & Maximo Asset Management
IBM Tivoli Software Maximo Asset Management Installing and Configuring DB2 10, WebSphere Application Server v8 & Maximo Asset Management Document version 1.0 Rick McGovern Staff Software Engineer IBM Maximo
User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream
User Manual Onsight Management Suite Version 5.1 Another Innovation by Librestream Doc #: 400075-06 May 2012 Information in this document is subject to change without notice. Reproduction in any manner
Sophos Mobile Control Installation guide. Product version: 3.6
Sophos Mobile Control Installation guide Product version: 3.6 Document date: November 2013 Contents 1 Introduction...3 2 The Sophos Mobile Control server...5 3 Set up Sophos Mobile Control...11 4 External
CA Nimsoft Service Desk
CA Nimsoft Service Desk Single Sign-On Configuration Guide 6.2.6 This Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referred to as the Documentation
App Orchestration 2.0
App Orchestration 2.0 Configuring NetScaler Load Balancing and NetScaler Gateway for App Orchestration Prepared by: Christian Paez Version: 1.0 Last Updated: December 13, 2013 2013 Citrix Systems, Inc.
Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide
Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your computer.
System Administration Training Guide. S100 Installation and Site Management
System Administration Training Guide S100 Installation and Site Management Table of contents System Requirements for Acumatica ERP 4.2... 5 Learning Objects:... 5 Web Browser... 5 Server Software... 5
RSA Authentication Manager 8.1 Virtual Appliance Getting Started
RSA Authentication Manager 8.1 Virtual Appliance Getting Started Thank you for purchasing RSA Authentication Manager 8.1, the world s leading two-factor authentication solution. This document provides
DEPLOYING EMC DOCUMENTUM BUSINESS ACTIVITY MONITOR SERVER ON IBM WEBSPHERE APPLICATION SERVER CLUSTER
White Paper DEPLOYING EMC DOCUMENTUM BUSINESS ACTIVITY MONITOR SERVER ON IBM WEBSPHERE APPLICATION SERVER CLUSTER Abstract This white paper describes the process of deploying EMC Documentum Business Activity
Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background
Xerox Multifunction Devices Customer Tips June 5, 2007 This document applies to these Xerox products: X WC Pro 232/238/245/ 255/265/275 for the user Xerox Network Scanning HTTP/HTTPS Configuration using
Deploying F5 with Microsoft Active Directory Federation Services
F5 Deployment Guide Deploying F5 with Microsoft Active Directory Federation Services This F5 deployment guide provides detailed information on how to deploy Microsoft Active Directory Federation Services
VMware vcenter Server 5.5 Deployment Guide TECHNICAL MARKETING DOCUMENTATION V 1.0/NOVEMBER 2013/JUSTIN KING
VMware 5.5 TECHNICAL MARKETING DOCUMENTATION V 1.0/NOVEMBER 2013/JUSTIN KING Table of Contents Overview.... 3 Components of 5.5.... 3 vcenter Single Sign-On.... 3 vsphere Web Client.... 3 vcenter Inventory
How to Migrate Citrix XenApp to VMware Horizon 6 TECHNICAL WHITE PAPER
How to Migrate Citrix XenApp to VMware Horizon 6 TECHNICAL WHITE PAPER Table of Contents Introduction... 3 Horizon and XenApp Components Comparison.... 4 Preparing for the Migration.... 5 Three Approaches
Installing and Using the vnios Trial
Installing and Using the vnios Trial The vnios Trial is a software package designed for efficient evaluation of the Infoblox vnios appliance platform. Providing the complete suite of DNS, DHCP and IPAM
Sophos for Microsoft SharePoint startup guide
Sophos for Microsoft SharePoint startup guide Product version: 2.0 Document date: March 2011 Contents 1 About this guide...3 2 About Sophos for Microsoft SharePoint...3 3 System requirements...3 4 Planning
VMware vsphere Data Protection Evaluation Guide REVISED APRIL 2015
VMware vsphere Data Protection REVISED APRIL 2015 Table of Contents Introduction.... 3 Features and Benefits of vsphere Data Protection... 3 Requirements.... 4 Evaluation Workflow... 5 Overview.... 5 Evaluation
Configuring Global Protect SSL VPN with a user-defined port
Configuring Global Protect SSL VPN with a user-defined port Version 1.0 PAN-OS 5.0.1 Johan Loos [email protected] Global Protect SSL VPN Overview This document gives you an overview on how to configure
LAB: Enterprise Single Sign-On Services. Last Saved: 7/17/2006 10:48:00 PM
LAB: Enterprise Single Sign-On Services LAB: Enterprise Single Sign-On Services 2 TABLE OF CONTENTS HOL: Enterprise Single Sign-On Services...3 Objectives...3 Lab Setup...4 Preparation...5 Exercise 1:
Sophos Mobile Control Installation guide
Sophos Mobile Control Installation guide Product version: 2.5 Document date: July 2012 Contents 1 Introduction... 3 2 The Sophos Mobile Control server... 4 3 Set up Sophos Mobile Control... 13 4 Running
Configuration Guide. BES12 Cloud
Configuration Guide BES12 Cloud Published: 2016-04-08 SWD-20160408113328879 Contents About this guide... 6 Getting started... 7 Configuring BES12 for the first time...7 Administrator permissions you need
Thinspace deskcloud. Quick Start Guide
Thinspace deskcloud Quick Start Guide Version 1.2 Published: SEP-2014 Updated: 16-SEP-2014 2014 Thinspace Technology Ltd. All rights reserved. The information contained in this document represents the
Deploying the BIG-IP System v10 with Oracle Application Server 10g R2
DEPLOYMENT GUIDE Deploying the BIG-IP System v10 with Oracle Application Server 10g R2 Version 1.1 Table of Contents Table of Contents Deploying the BIG-IP system v10 with Oracle s Application Server 10g
Unifying Information Security. Implementing TLS on the CLEARSWIFT SECURE Email Gateway
Unifying Information Security Implementing TLS on the CLEARSWIFT SECURE Email Gateway Contents 1 Introduction... 3 2 Understanding TLS... 4 3 Clearswift s Application of TLS... 5 3.1 Opportunistic TLS...
IP Application Security Manager and. VMware vcloud Air
Securing Web Applications with F5 BIG- IP Application Security Manager and VMware vcloud Air D E P L O Y M E N T G U I D E Securing Web Applications Migrating application workloads to the public cloud
Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]
Cox Managed CPE Services RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft] September, 2015 2015 by Cox Communications. All rights reserved. No part of this document may be reproduced or transmitted
Secure IIS Web Server with SSL
Secure IIS Web Server with SSL EventTracker v7.x Publication Date: Sep 30, 2014 EventTracker 8815 Centre Park Drive Columbia MD 21045 www.eventtracker.com Abstract The purpose of this document is to help
Getting Started with ESXi Embedded
ESXi 4.1 Embedded vcenter Server 4.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent
DEPLOYMENT GUIDE Version 1.1. Deploying F5 with Oracle Application Server 10g
DEPLOYMENT GUIDE Version 1.1 Deploying F5 with Oracle Application Server 10g Table of Contents Table of Contents Introducing the F5 and Oracle 10g configuration Prerequisites and configuration notes...1-1
IIS, FTP Server and Windows
IIS, FTP Server and Windows The Objective: To setup, configure and test FTP server. Requirement: Any version of the Windows 2000 Server. FTP Windows s component. Internet Information Services, IIS. Steps:
SC-T35/SC-T45/SC-T46/SC-T47 ViewSonic Device Manager User Guide
SC-T35/SC-T45/SC-T46/SC-T47 ViewSonic Device Manager User Guide Copyright and Trademark Statements 2014 ViewSonic Computer Corp. All rights reserved. This document contains proprietary information that
Migrating to vcloud Automation Center 6.1
Migrating to vcloud Automation Center 6.1 vcloud Automation Center 6.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
WhatsUp Gold v16.1 Installation and Configuration Guide
WhatsUp Gold v16.1 Installation and Configuration Guide Contents Installing and Configuring Ipswitch WhatsUp Gold v16.1 using WhatsUp Setup Installing WhatsUp Gold using WhatsUp Setup... 1 Security guidelines
Configuring Single Sign-on from the VMware Identity Manager Service to Dropbox
Configuring Single Sign-on from the VMware Identity Manager Service to Dropbox VMware Identity Manager SEPTEMBER 2015 V1 Configuring Single Sign-On from VMware Identity Manager to Dropbox Table of Contents
VMware Identity Manager Administration
VMware Identity Manager Administration VMware Identity Manager 2.4 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
1. If there is a temporary SSL certificate in your /ServerRoot/ssl/certs/ directory, move or delete it. 2. Run the following command:
C2Net Stronghold Cisco Adaptive Security Appliance (ASA) 5500 Cobalt RaQ4/XTR F5 BIG IP (version 9) F5 BIG IP (pre-version 9) F5 FirePass VPS HSphere Web Server IBM HTTP Server Java-based web server (generic)
VMware vcenter Operations Manager for Horizon Supplement
VMware vcenter Operations Manager for Horizon Supplement vcenter Operations Manager for Horizon 1.7 This document supports the version of each product listed and supports all subsequent versions until
Sophos Mobile Control Installation guide. Product version: 3
Sophos Mobile Control Installation guide Product version: 3 Document date: January 2013 Contents 1 Introduction...3 2 The Sophos Mobile Control server...4 3 Set up Sophos Mobile Control...16 4 External
vsphere Upgrade vsphere 6.0 EN-001721-03
vsphere 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of this document,
Replacing VirtualCenter Server Certificates VMware Infrastructure 3
Technical Note Replacing VirtualCenter Server Certificates VMware Infrastructure 3 This technical note provides information about replacing the default certificates supplied with VirtualCenter Server hosts.
StarWind Virtual SAN Installation and Configuration of Hyper-Converged 2 Nodes with Hyper-V Cluster
#1 HyperConverged Appliance for SMB and ROBO StarWind Virtual SAN Installation and Configuration of Hyper-Converged 2 Nodes with MARCH 2015 TECHNICAL PAPER Trademarks StarWind, StarWind Software and the
DEPLOYMENT GUIDE Version 2.1. Deploying F5 with Microsoft SharePoint 2010
DEPLOYMENT GUIDE Version 2.1 Deploying F5 with Microsoft SharePoint 2010 Table of Contents Table of Contents Introducing the F5 Deployment Guide for Microsoft SharePoint 2010 Prerequisites and configuration
WHITE PAPER Citrix Secure Gateway Startup Guide
WHITE PAPER Citrix Secure Gateway Startup Guide www.citrix.com Contents Introduction... 2 What you will need... 2 Preparing the environment for Secure Gateway... 2 Installing a CA using Windows Server
VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.4.1
VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.4.1 This document supports the version of each product listed and supports all subsequent versions
Host Access Management and Security Server
Host Access Management and Security Server Evaluation Guide Host Access Management and Security Server Evaluation Guide 12.2 Copyrights and Notices Copyright 2015 Attachmate Corporation. All rights reserved.
Connection Broker Managing User Connections to Workstations, Blades, VDI, and More. Quick Start with Microsoft Hyper-V
Connection Broker Managing User Connections to Workstations, Blades, VDI, and More Quick Start with Microsoft Hyper-V Version 8.1 October 21, 2015 Contacting Leostream Leostream Corporation http://www.leostream.com
DEPLOYMENT GUIDE CONFIGURING THE BIG-IP LTM SYSTEM WITH FIREPASS CONTROLLERS FOR LOAD BALANCING AND SSL OFFLOAD
DEPLOYMENT GUIDE CONFIGURING THE BIG-IP LTM SYSTEM WITH FIREPASS CONTROLLERS FOR LOAD BALANCING AND SSL OFFLOAD Configuring the BIG-IP LTM system for use with FirePass controllers Welcome to the Configuring
Obtaining SSL Certificates for VMware Horizon View Servers
Obtaining SSL Certificates for VMware Horizon View Servers View 5.2 View Composer 5.2 This document supports the version of each product listed and supports all subsequent versions until the document is
http://www.trendmicro.com/download
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files,
vcenter Configuration Manager Backup and Disaster Recovery Guide VCM 5.3
vcenter Configuration Manager Backup and Disaster Recovery Guide VCM 5.3 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by
vcenter Chargeback User s Guide
vcenter Chargeback 1.6 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions
Virtual Appliance Setup Guide
Virtual Appliance Setup Guide 2015 Bomgar Corporation. All rights reserved worldwide. BOMGAR and the BOMGAR logo are trademarks of Bomgar Corporation; other trademarks shown are the property of their respective
DEPLOYMENT GUIDE Version 1.2. Deploying F5 with Oracle E-Business Suite 12
DEPLOYMENT GUIDE Version 1.2 Deploying F5 with Oracle E-Business Suite 12 Table of Contents Table of Contents Introducing the BIG-IP LTM Oracle E-Business Suite 12 configuration Prerequisites and configuration
Copyright 2012 Trend Micro Incorporated. All rights reserved.
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files,
RoomWizard Synchronization Software Manual Installation Instructions
2 RoomWizard Synchronization Software Manual Installation Instructions Table of Contents Exchange Server Configuration... 4 RoomWizard Synchronization Software Installation and Configuration... 5 System
DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014
DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014 Contents Overview... 2 System requirements:... 2 Before installing... 3 Download and installation... 3 Configure DESLock+ Enterprise Server...
Deploying EMC Documentum WDK Applications with IBM WebSEAL as a Reverse Proxy
Deploying EMC Documentum WDK Applications with IBM WebSEAL as a Reverse Proxy Applied Technology Abstract This white paper serves as a detailed solutions guide for installing and configuring IBM WebSEAL
Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.
This chapter provides information about the Security Assertion Markup Language (SAML) Single Sign-On feature, which allows administrative users to access certain Cisco Unified Communications Manager and
http://docs.trendmicro.com/en-us/smb/hosted-email-security.aspx
Trend Micro Incorporated reserves the right to make changes to this document and to the product described herein without notice. Before installing and using the product, review the readme files, release
Director and Certificate Authority Issuance
VMware vcloud Director and Certificate Authority Issuance Leveraging QuoVadis Certificate Authority with VMware vcloud Director TECHNICAL WHITE PAPER OCTOBER 2012 Table of Contents Introduction.... 3 Process
Foglight. Foglight for Virtualization, Free Edition 6.5.2. Installation and Configuration Guide
Foglight Foglight for Virtualization, Free Edition 6.5.2 Installation and Configuration Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright.
Configuring a single-tenant BIG-IP Virtual Edition in the Cloud
Deployment Guide Document Version: 1.0 What s inside: 2 Configuration example 4 Securing the isession deployment 6 Downloading and importing the new iapp 6 Configuring the BIG- IP systems using the Cloud
How To Create An Easybelle History Database On A Microsoft Powerbook 2.5.2 (Windows)
Introduction EASYLABEL 6 has several new features for saving the history of label formats. This history can include information about when label formats were edited and printed. In order to save this history,
DameWare Server. Administrator Guide
DameWare Server Administrator Guide About DameWare Contact Information Team Contact Information Sales 1.866.270.1449 General Support Technical Support Customer Service User Forums http://www.dameware.com/customers.aspx
Integrating WebSphere Portal V8.0 with Business Process Manager V8.0
2012 Integrating WebSphere Portal V8.0 with Business Process Manager V8.0 WebSphere Portal & BPM Services [Page 2 of 51] CONTENTS CONTENTS... 2 1. DOCUMENT INFORMATION... 4 1.1 1.2 2. INTRODUCTION... 5
Configuring Single Sign-on from the VMware Identity Manager Service to WebEx
Configuring Single Sign-on from the VMware Identity Manager Service to WebEx VMware Identity Manager SEPTEMBER 2015 V 2 Configuring Single Sign-On from VMware Identity Manager to WebEx Table of Contents
vsphere Replication for Disaster Recovery to Cloud
vsphere Replication for Disaster Recovery to Cloud vsphere Replication 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
How To Integrate An Ipm With Airwatch With Big Ip On A Server With A Network (F5) On A Network With A Pb (Fiv) On An Ip Server On A Cloud (Fv) On Your Computer Or Ip
F5 Networks, Inc. F5 Recommended Practices for BIG-IP and AirWatch MDM Integration Contents Introduction 4 Purpose 5 Requirements 6 Prerequisites 6 AirWatch 6 F5 BIG-IP 6 Network Topology 7 Big-IP Configuration
Appendix E. Captioning Manager system requirements. Installing the Captioning Manager
Appendix E Installing and configuring the Captioning Manager The Mediasite Captioning Manager, a separately sold EX Server add-on, allows users to submit and monitor captioning requests through Automatic
