Version 1.5 June 2015 AT&T Synaptic Compute as a Service SM Instruction Guide to AT&T Operating System Usage 2015 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property
Notice Copyright 2015 AT&T Intellectual Property. All rights reserved. AT&T, the AT&T logo and all other AT&T marks contained herein are trademarks of AT&T Intellectual Property and/or AT&T affiliated companies. All other marks contained herein are the property of their respective owners. This document is not an offer, commitment, representation or warranty by AT&T and is subject to change. The information contained in this document should not be duplicated, transmitted, or disclosed, in whole or in part without the expressed written consent of AT&T. Information in this document is subject to change without notice. AT&T assumes no responsibility for any errors or omissions in this document. Use of this document and the information is pursuant to the terms and conditions of your service agreement with AT&T. Windows is a trademark of the Microsoft group of companies. Red Hat Enterprise Linux is a trademark of Red Hat, Inc.
Contents 1.0 Overview... 4 2.0 Creating New Virtual Machines... 5 3.0 Configuration Information... 11 4.0 Accessing the Patching and Activation Servers... 12 5.0 Instructions For Updating unmanaged Windows VM(s) With AT&T- Provided Licensing (aka Migration)... 12 6.0 Instructions For Updating unmanaged Red Hat VM(s) With AT&T-Provided Software Subscription Keys (aka Migration)... 13 7.0 Frequently Asked Questions... 15
1.0 Overview As part of our licensing agreements with Microsoft and Red Hat, AT&T must provide all licensing for Windows 2008 and 2012 operating system instances on AT&T Synaptic Compute as a Service SM as well as all software subscription services (aka enterprise support option) for Red Hat Enterprise Linux (RHEL) Release 5.0 and newer operating system instances on AT&T Compute as a Service. Effective November 1, 2013 customers will be billed for the use of these operating systems as described in the AT&T Cloud Solutions Service Guide found at http://serviceguidenew.att.com (under Data AT&T Cloud Solutions ) and on the AT&T Cloud Solutions Portal at http://synaptic.att.com. This guide is designed to help you configure your virtual machines (VMs) with the appropriate Windows Key Management Server (KMS) and Red Hat Update Infrastructure ( RHUI) server information. The RHUI server manages updates to RHEL servers. Windows Server Update Service (WSUS) servers will manage patching of Windows VMs. Here is an at-a-glance view of the possible VM creation scenarios and how to handle updating these VMs with the required information: Virtual Machine (VM) Activation Scenarios VM Type User Action Required Patching Provided By Patching Servers Used New Managed VM- Windows/Red Hat None AT&T AT&T WSUS and AT&T RHUI servers New Managed VM from Clone of Managed VM - Windows/Red Hat None AT&T AT&T WSUS and AT&T RHUI servers New unmanaged VM from AT&T Template Windows None Customer Microsoft Public WSUS (www.microsoft.com) New unmanaged VM from AT&T Template Red Hat New unmanaged VM from Clone of AT&T Template Windows New unmanaged VM from Clone of AT&T Template Red Hat New unmanaged VM from a non- AT&T template or clone Windows New unmanaged VM from a non- AT&T template or clone Red Hat New unmanaged Virtual Machines (VMs) via the vcloud Director None Customer AT&T RHUI Servers None Customer Microsoft Public WSUS None Customer AT&T RHUI Servers - Update the KMS server IP address configuration to point to the AT&T KMS server - Insert AT&T License key * - Install the RHUI entitlement rpm appropriate for your location and OS version ** - Update the KMS server IP address Customer Customer Customer Microsoft Public WSUS AT&T RHUI Servers Microsoft Public WSUS
console or APIs- Windows New unmanaged Virtual Machines (VMs) via the vcloud Director console or APIs- Red Hat configuration to point to the AT&T KMS server - Insert AT&T License key * Update the RHUI configuration file to point to the IP address of the AT&T RHUI server Customer AT&T RHUI Servers * License key information is located in Section 3 of this document, Section C -Configuration Information ** The information is provided in Section 6 of this document 2.1 Creating New Virtual Machines This section provides detailed steps on how to configure your VMs with the required licensing and patching information. If you are creating your VMs from AT&T-provided templates, these templates will be pre-configured with the appropriate Windows KMS and / or RedHat RHUI server information for your VM. NOTE: IP addresses for AT&T Windows Key Management Servers (KMS) and Red Hat Update Infrastructure ( RHUI) servers are unique to each physical AT&T data center. You can verify the physical data center location of your VMs via the AT&T Cloud Solutions Portal as shown here: Also note that the steps may vary, depending on how you access your Virtual Data Center (VDC). If you use the default Internet option for connecting to your VDC(s), follow the Internet-connected VDC steps. If you have added
AT&T Compute as a Service to your AT&T MPLS VPN network OR if your company currently has a collocated server presence in an AT&T Data Center and are connecting to your VDC via a data center cross-connect, then follow the AT&T MPLS VPN and Cross-Connected VDC steps. 1. Creating New Managed Virtual Machines (VMs) All Managed VMs that are part of AT&T Managed vapp option include the IP addresses for AT&T KMS and RHUI servers. In addition, AT&T will provide the patching of all VMs that are part of AT&T Managed vapp option. a. Internet-Connected VDCs Managed VMs created from an AT&T VM template from the public library are already configured with the appropriate licensing and patching information. No configuration is required by the Customer. All operating system patching is performed by AT&T. b. AT&T MPLS VPN-Connected and Cross-Connected VDCs Managed VMs created from an AT&T VM template from the public library are already configured with the appropriate licensing and patching information. No configuration is required by the Customer. All operating system patching is performed by AT&T. 2. Creating a new Virtual Machine from a clone of a Managed Virtual Machine All clones of Managed VMs that are part of AT&T Managed vapp option already include the IP addresses for AT&T KMS and RHUI servers. In addition, AT&T will provide the patching of all VMs that are part of AT&T Managed vapp option. A managed VM can only be cloned into a Managed vapp. a. Internet-Connected VDCs Clones of managed VMs are created from AT&T VM templates from the public library that are already configured with the appropriate licensing and patching information. No configuration is required by the Customer. All operating system patching is performed by AT&T. b. AT&T MPLS VPN-Connected and Cross-Connected VDCs Clones of managed VMs are created from AT&T VM templates from the public library are already configured with the appropriate licensing and patching information. No configuration is required by the Customer. All operating system patching is performed by AT&T. 3. Creating New unmanaged Virtual Machines (VMs) from an AT&T template All unmanaged Windows and Red Hat VMs created from an AT&T-provided template will include all the necessary information required to access AT&T KMS and RHUI servers. Creating a VM from an AT&T template on the AT&T Cloud Solutions Portal is shown below:
a. Internet-Connected VDCs Unmanaged VMs created from an AT&T VM template from the public library are already configured with the appropriate licensing and patching information. No VM configuration is required by the customer. However, all operating system patching must be performed by customer. By default, your (customer) firewall allows all outbound connections. Therefore, access to the AT&T KMS and RHUI servers is supported. Should you wish to reconfigure your firewall, be careful to not block your access to the following ports: o Port 1688 o Port 443 o Port 80 b. AT&T MPLS VPN-Connected and Cross-Connected VDCs Unmanaged VMs created from an AT&T VM template from the public library are already configured with the appropriate licensing and patching information. AT&T will automatically create a Virtual IP address ( VIP ) for access to the KMS and RHUI servers when your VDC is initially activated. o NOTE: AT&T will be using one of your designated IP addresses to create this VIP. Customers who access their service via AT&T MPLS VPN or cross-connect and create their virtual machines (VMs) via vcloud Director (VCD) or an API can determine their specific VIP by reviewing the VM details of a previously-created VM via the AT&T
Cloud Solutions Portal. The VIP details can be accessed via the VM details page on the AT&T Cloud Solutions Portal. No VM configuration is required by the Customer. However, all operating system patching is performed by the Customer. 4. Creating New unmanaged Virtual Machines (VMs) from a Clone of an AT&T template All unmanaged Windows and Red Hat VMs created from a clone of an AT&T-provided template will include all the necessary information required to access AT&T KMS and RHUI servers, if you have not changed such configurations since the VM was initially activated. Cloning a VM from an AT&T template on the AT&T Cloud Solutions Portal is shown here: NOTE: If you clone or copy a VM created from an AT&T template, the new image will also contain the necessary information to support licensing and patching of your new server / VM. 5. Creating New unmanaged Virtual Machines (VMs) from a non-at&t template or a cloned VM When you create or clone a VM from a private (non-at&t) VM or template, you will need to update those VMs with the appropriate IP addresses to support connectivity to AT&T KMS and RHUI servers and the AT&T key for Windows software activation. When you click Create VM from a private (non-at&t) template OR you select the Clone VM action on a private VM template from the AT&T Cloud Solutions Portal, a Pop Up window will appear, explaining: You are creating VMs from a private template. Per the AT&T terms of use you need to use the following IP addresses to configure your VMs: Microsoft Windows VMs: xxx.xxx.xxx.xxx for license activation
Red Hat Linux VMs: yyy.yyy.yyy.yyy for RHUI patching configuration Please refer to the AT&T Cloud Solutions Portal Knowledge Center for detailed instructions. The link to the AT&T Cloud Solutions Portal Knowledge Center is: https://www.synaptic.att.com/clouduser/html/knowledgecenter/knowledgecenter.htm The pop-up will be populated with the appropriate Microsoft or Red Hat server IP address for the physical location where your VM is operating. (East Coast, West Coast, South Central, Netherlands, United Kingdom). Instructions are as follows: a. Internet-Connected VDCs Unmanaged VMs created from a non-at&t VM template (i.e. private image) OR from a clone of a private (Non-AT&T) image are NOT configured with the appropriate licensing and patching information. Configuration is required by the customer (unless cloning a VM which already has this configuration) to insert the correct IP address of the AT&T KMS or RHUI server from Table 3.1 below. Windows VMs need to be updated with the AT&T generic license activation code from Table 3.2 below as well. All operating system patching is performed by customer. Your firewall, by default, allows all outbound connections. Therefore, connectivity to the AT&T KMS and RHUI servers is supported. Should you wish to reconfigure your firewall, be careful to not block your access to the following ports: o Port 1688 o Port 443 o Port 80
b. AT&T MPLS VPN-Connected VDCs and Cross-Connected VDCs Unmanaged VMs created from a non-at&t VM template (i.e. private image) OR from a clone of a private (Non-AT&T) image are NOT configured with the appropriate licensing and patching information AT&T will automatically create a Virtual IP address ( VIP ) for access to the KMS and RHUI servers when your VDC is initially activated. o NOTE: AT&T will be using one of your designated IP addresses to create this VIP. Customers who access their service via AT&T MPLS VPN or cross-connect and create their virtual machines (VMs) via vcloud Director (VCD) or an API can determine their specific VIP by reviewing the VM details of a previously-created VM via the AT&T Cloud Solutions Portal. The VIP details can be accessed via the VM details page on the AT&T Cloud Solutions Portal. Configuration is required by the customer to insert the correct IP address of the AT&T KMS or RHUI server from Table 3.1 below. Windows VMs need to be updated with an AT&T generic activation code from Table 3.2 below as well. All operating system patching is performed by customer. 6. Creating New unmanaged Virtual Machines (VMs) via the vcloud Director console or via Application Programming Interfaces (APIs) All unmanaged Windows and Red Hat VMs created outside of the AT&T Cloud Solutions Portal will NOT have the required information to access AT&T KMS and RHUI servers. VMs created via vcloud Director and/or APIs will need to be configured with the appropriate AT&T KMS and/or RHUI IP addresses for the AT&T Data Center where each VM is deployed. a. Internet-Connected VDCs Unmanaged VMs created via vcloud Director and/or APIs are NOT configured with the appropriate licensing and patching information. Configuration is required by the Customer to insert the correct IP address of the AT&T KMS or RHUI server from Table 3.1 below. Windows VMs need to be updated with an AT&T generic activation code from Table 3.2 below as well. All operating system patching is performed by customer. Your firewall, by default, allows all outbound connections. Therefore, connectivity to the AT&T KMS and RHUI servers is supported. Should you wish to reconfigure your firewall, be careful to not block your access to the following ports: o Port 1688 o Port 443 o Port 80 b. AT&T MPLS VPN-Connected VDCs and Cross-Connected VDCs Unmanaged VMs created via vcloud Director and/or APIs are NOT configured with the appropriate licensing and patching information.
AT&T will automatically create a Virtual IP address ( VIP ) for access to the KMS and RHUI servers when your VDC is initially activated. O NOTE: AT&T will be using one of your designated IP addresses to create this VIP. Customers who access their service via AT&T MPLS VPN or Cross-Connect and create their virtual machines (VMs) via vcloud Director (VCD) or an API can determine their specific VIP by accessing the VM details of a previously-created VM via the AT&T Cloud Solutions Portal. The VIP details can be accessed via the VM details page on the AT&T Cloud Solutions Portal. Windows VMs need to be updated with an AT&T generic activation code from Table 3.2 below as well. All operating system patching is performed by Customer. 3.0 Configuration Information The table below includes a summary of the IP address and key information required to update unmanaged VMs created from private images and/or private templates: Table 3.1 AT&T Server IP Addresses AT&T Data Center Location Windows KMS Red Hat YUM Red Hat RHUI Server FQDN IP Address Server IP Address East Coast 206.17.19.130 206.17.19.131 cds1.n118402.synaptic.att.com West Coast 63.241.77.122 63.241.77.123 cds1.j118857.synaptic.att.com South Central 199.106.143.130 199.106.143.139 cds1.g218406.synaptic.att.com United Kingdom 32.42.21.121 32.42.21.123 cds1.s218858.synaptic.att.com Netherlands 32.42.45.121 32.42.45.122 cds1.p118855.synaptic.att.com The table below also includes a summary of the AT&T generic Windows keys that need to be used when configuring your VMs. Table 3.2 AT&T Generic Windows Activation Keys AT&T Operating System Version AT&T Generic License Key 2008 Standard Edition TM24T-X9RMF-VWXK6-X8JC9-BFGM2 2008 Enterprise Edition YQGMW-MPWTJ-34KDK-48M3W-X4Q6V 2008 R2 Standard Edition YC6KT-GKW9T-YTKYR-T4X34-R7VHC 2008 R2 Enterprise Edition 489J6-VHDMP-X63PK-3K798-CPX3Y 2012 Standard Edition XC9B7-NBPP2-83J2H-RHMBY-92BT4 2012 Datacenter Edition 48HP8-DN98B-MYWDG-T2DCC-8W83P 2012 Standard Edition Release 2 D2N9P-3P6X9-2R39C-7RTCD-MDVJX 2012 Datacenter Edition Release 2 W3GGN-FT8W3-Y4M27-J84CP-Q3VJ9 NOTE: All other Microsoft Windows operating systems not shown above are not covered by this new licensing policy. 2014 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property.
4.0 Accessing the Patching and Activation Servers Microsoft Windows Managed Microsoft Windows VMs will activate against AT&T-operated KMS servers and will be patched by AT&Tutilizing AT&T-operated WSUS servers located in the applicable AT&T cloud data center. Unmanaged Microsoft Windows VMs will activate against AT&T-operated KMS servers located in the applicable AT&T Cloud datacenter. However, these VMs will connect to Microsoft s public WSUS infrastructure for all patches (www.microsoft.com). Red Hat Managed Red Hat VMs will activate against AT&T-operated RHUI servers and will be patched by AT&T utilizing AT&T- operated RHUI servers located in every Cloud datacenter. Unmanaged Red Hat VMs will also need to access AT&T-operated RHUI servers located in the applicable AT&T data center to activate and to download patches. VMs will need to reach the AT&T servers at the IP addresses in Table 3.1 found above. For more information on configuration details, please see Section 2.0 above. OS Type Patching Server Activation Server Microsoft Windows Managed AT&T WSUS AT&T KMS Microsoft Windows Unmanaged Microsoft WSUS AT&T KMS Linux Managed AT&T RHUI N/A Linux Unmanaged AT&T RHUI N/A 5.1 Instructions For Updating unmanaged Windows VM(s) With AT&T- Provided Licensing (aka Migration) AT&T is providing licensing for all VMs within AT&T Compute as a Service running the following Windows operating systems: Microsoft Windows 2008 Standard and Enterprise Editions Microsoft Windows 2008 R2 Standard and Enterprise Editions Windows Server 2012 Standard Edition Windows Server 2012 Datacenter Edition 2014 AT&T Intellectual Property. All rights reserved. AT&T and the AT&T logo are trademarks of AT&T Intellectual Property.
If you have VMs running any of the above operating systems, please follow the steps provided here to update those VMs with AT&T key management server (KMS) information as soon as possible. 1. Log in to your Windows VM(s) 2. Download the AttActivate.Cmd script. Note that the location of this script varies based on the physical data center where your VMs are running. You may have to add the site as a Trusted Site in order to download file. Physical Data Center East Coast South Central West Coast United Kingdom Netherlands AVPN and Cross Connect Customers Script Location http://206.17.19.131/scripts/ http://199.106.143.139/scripts/ http://63.241.77.123/scripts/ http://32.42.21.123/scripts/ http://32.42.45.122/scripts/ http://<your_vip>/scripts/ 3. Click on "AttActivate.cmd" and click "Run" to run the script. Once it is run, this script will activate your VM with the appropriate AT&T-provided Windows licensing information. 6.1 Instructions For Updating Unmanaged Red Hat VM(s) With AT&T-Provided Software Subscription Keys (aka Migration) The steps below assist in setting up unmanaged Linux VMs to download RHEL patches from the AT&T RHUI infrastructure. The following operating systems are in scope: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 6.5 a. Login to your Linux VM and change directory to /tmp (cd /tmp) b. Download the rpm from the following places based on the location of your VM [East / Ashburn] RHEL 5: wget http://206.17.19.131/files/rhui-client-rhel5-n118402-2.1.3- RHEL 6: wget http://206.17.19.131/files/rhui-client-rhel6-n118402-2.1.3- [Southwest / Webb Chapel] RHEL 5: wget http://199.106.143.139/files/rhui-client-rhel5-g218406-2.1.3- RHEL 6: wget http://199.106.143.139/files/rhui-client-rhel6-g218406-2.1.3- [West / Redwood City] RHEL 5: wget http://63.241.77.123/files/rhui-client-rhel5-j118857-2.1.3- RHEL 6: wget http://63.241.77.123/files/rhui-client-rhel6-j118857-2.1.3- [London] RHEL 5: wget http://32.42.21.123/files/rhui-client-rhel5-s218858-2.1.3- RHEL 6: wget http://32.42.21.123/files/rhui-client-rhel6-s218858-2.1.3- [Amsterdam] RHEL 5: wget http://32.42.45.122/files/rhui-client-rhel5-p118855-2.1.3- RHEL 6: wget http://32.42.45.122/files/rhui-client-rhel6-p118855-2.1.3-
[AVPN Customers] RHEL 5: wget http://<your_vip>/files/<file to download> RHEL 6: wget http://<your_vip>/files/<file to download> where <file to download> is as follows: Table 6.1 Rpm filename and md5sum Physical Data Center File To Download MD5SUM East Coast RHEL 5 rhui-client-rhel5-n118402-2.1.3-223579df6ac9f2d8ca36e9ceb40bd854 RHEL 6 rhui-client-rhel6-n118402-2.1.3- South Central RHEL 5 rhui-client-rhel5-g218406-2.1.3- RHEL 6 rhui-client-rhel6-g218406-2.1.3- West Coast RHEL 5 rhui-client-rhel5-j118857-2.1.3- RHEL 6 rhui-client-rhel6-j118857-2.1.3- United Kingdom RHEL 5 rhui-client-rhel5-s218858-2.1.3- RHEL 6 rhui-client-rhel6-s218858-2.1.3- Netherlands RHEL 5 rhui-client-rhel5-p118855-2.1.3- RHEL 6 rhui-client-rhel6-p118855-2.1.3- dad85c240f12264df3379a4855b516a7 ec7b36e5bb44b8397d18ffaae4412d57 ac10cd65ca1fb58a57bab2e1e5f42031 ca90295ae7738803207acfaaf8a23182 585341c9f78a8f5f99c862b3a8b83688 ade9305a31683419787ef8577a2032bd 14e8a6ae8dba46cf6dc9ff7c736c185f 608509f460762d61cf835c31065a7314 1ab640d3ab5d0e36ae4e5b09dde3d580 c. Verify the md5sum of the downloaded rpm as per Table 6.1 d. Disable any existing AT&T repos in /etc/yum.conf by changing enabled=1 to enabled=0 in /etc/yum.conf for the AT&T repo e. Install the rpm as follows yum --disablerepo=* --nogpgcheck -y localinstall <rpm name> f. [AVPN Customers Only] Configure the /etc/hosts file on your VM by adding the following line <FQDN of the RHUI Server> <Your VIP> NOTE: Please refer to table 3.1 for <FQDN of the RHUI Server>
7.0 Frequently Asked Questions 1. What has changed regarding operating system licensing with AT&T Compute as a Service (CaaS)? As part of our licensing agreements with Microsoft and Red Hat, AT&T now provides all licensing for Windows 2008 and 2012 operating system instances on AT&T Compute as a Service, and it also deploys all software subscription services (aka enterprise support option for Red Hat ) for Red Hat RHEL 5.0 and later operating system instances using AT&T Compute as a Service.Is there a charge for this enhancement? Yes. Effective November 1, 2013, AT&T began accruing billing for usage charges for all supported Windows and Red Hat images. Service will be billed at $.03 per hour per vcpu while VMs are in a running state. You are not charged while a VM is not running (stopped VM). 2. Can I provide my own licenses? No. Customers may not supply their own operating system licenses for Windows 2008, 2012 Server and may not provide their own software subscription services for Red Hat RHEL 5.0 and newer operating systems. H o w e v e r, o t h e r versions and other operating systems are not affected by this policy. 3. Does this apply to virtual machines created from customers private Windows and Red Hat image templates that I have imported? Yes. We are required to provide these services for all Windows Server 2008 and 2012 and Red Hat RHEL 5.0 and newer operating systems even if a customer imports the VM (template) from its own private catalog. 4. Will AT&T perform the patching of AT&T-provided public library images? Yes. AT&T will keep the images of these operating systems in the public library patched and up-to-date, as we do today. 5. Will AT&T provide software updates (patches) for my Windows and Red Hat virtual machines? AT&T will patch Managed VMs only. Patching of unmanaged VMs is your responsibility. For unmanaged Windows VMs, patches will be accessed using public Microsoft WSUS servers (www.microsoft.com). For unmanaged RedHat VMs, patches will be made available via AT&T-provided RHUI servers.