VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION Manuale Utente Pagina 1

Navigare online o scaricare Manuale Utente per Software VMware VCM 5.3 - TRANSPORT LAYER SECURITY IMPLEMENTATION. vCenter Configuration Manager Transport Layer Security Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa

Sommario

Pagina 1 - Implementation

vCenter Configuration ManagerTransport Layer SecurityImplementationVMware VCM 5.3WHITE PAPER

Pagina 2 - Table of Contents

TLS Implementation for VCMTECHNICAL WHITE PAPER / 10The Collector CertificateThe Collector Certificate is issued by the Enterprise Certificate, and mu

Pagina 3

TECHNICAL WHITE PAPER / 11lMust be usable for client authenticationlMust be issued by any Collector Certificate issued by the Enterprise Certificate,

Pagina 4 - Introduction to TLS

TLS Implementation for VCMTECHNICAL WHITE PAPER / 12Creating and Installing Certificates for CollectorsCertificates can either be generated during VCM

Pagina 5 - Expiration and Revocation

TLS Implementation for VCMTECHNICAL WHITE PAPER / 13Changing CertificatesCertificates always have an expiration date, after which they are no longer v

Pagina 6 - Certificate Storage

TECHNICAL WHITE PAPER / 14After VCM installation, if you decide that you want to use different certificates than the ones that you either generatedor

Pagina 7 - How VCM Uses Certificates

TLS Implementation for VCMTECHNICAL WHITE PAPER / 15Delivering Initial Certificates to AgentsVCM Agents use Enterprise Certificates to validate Collec

Pagina 8

TLS Implementation for VCMTECHNICAL WHITE PAPER / 16Installing the Agent from a Disk (Windows only)The VCM installation image/DVD does not contain cus

Pagina 9

TECHNICAL WHITE PAPER / 17UNIX/Linux or Mac OS XEach UNIX/Linux or Mac OS X installation package is targeted for one or more supported platforms. To i

Pagina 10 - Agent Certificates

TLS Implementation for VCMTECHNICAL WHITE PAPER / 188. Select the certificate to be exported. Right-click, and then select All Tasks | Export.9. The C

Pagina 11 - TLS Machine Security Level

TECHNICAL WHITE PAPER / 199. The File to Import dialog box appears. Select the file to import. Either format is acceptable: *.pfx or *.cer. The*.pem f

Pagina 12 - TLS Implementation for VCM

TECHNICAL WHITE PAPER / 2Table of ContentsIntroduction to TLS 4Server Authentication 4Mutual Authentication 4Certificates and Public Key Infrastructur

Pagina 13 - Changing Certificates

TLS Implementation for VCMTECHNICAL WHITE PAPER / 20Appendix A: Creating Certificates for TLS UsingMakecertVCM is designed to run in TLS mode with two

Pagina 14

TLS Implementation for VCMTECHNICAL WHITE PAPER / 211. Use the following command to create the CM Enterprise Certificate:makecert -pe -n "<ent

Pagina 15 - Upgrades

TECHNICAL WHITE PAPER / 22Example:makecert -pe -n "CN=CM Collector Certificate BBBBBBBB-BBBB-BBBB-BBBB-BBBBBBBBBBBB" -sky exchange -sv "

Pagina 16 - UNIX/Linux or Mac OS X

TLS Implementation for VCMTECHNICAL WHITE PAPER / 23Import the Certificates on the Collector MachinesPerform the following procedure on the new Collec

Pagina 17 - Certificate Transport

TECHNICAL WHITE PAPER / 24-h 2 Max height of certificate chains. A value of 2 for the Enterprise allowsit to sign a Collector certificate capable of s

Pagina 18

TLS Implementation for VCMTECHNICAL WHITE PAPER / 25-pe Make the private key exportable.-r Self sign the certificate.-sk <collector_key_name>Nam

Pagina 19

TLS Implementation for VCMTECHNICAL WHITE PAPER / 26Appendix B: Updating the Collector CertificateThumbprint in the VCM Collector Database1. Within MM

Pagina 20 - Makecert

TLS Implementation for VCMTECHNICAL WHITE PAPER / 27Appendix C: Managing the VCM UNIX AgentCertificate StoreThe VCM UNIX Agent certificate store is a

Pagina 21

TLS Implementation for VCMTECHNICAL WHITE PAPER / 28CSI_ManageCertificateStore Options[root@localhost tmp]# CSI_ManageCertificateStore -?Usage: /opt/C

Pagina 22

TECHNICAL WHITE PAPER / 29-u Update certificate in the certificate storeCommon uses:Insert a new certificate into the certificate store:/opt/CMAgent/C

Pagina 23 - MakeCert Options

TECHNICAL WHITE PAPER / 3Certificate Expiration 17Certificate Transport 17Exporting Certificates (Windows Only) 17Importing Certificates (Windows Only

Pagina 24

TLS Implementation for VCMTECHNICAL WHITE PAPER / 30/opt/CMAgent/CFC/3.0/bin/CSI_ManageCertificateStore -e -g fingerprintExport existing certificates

Pagina 25

TECHNICAL WHITE PAPER / 31Subject : O = CSI-SE, OU = VMware vCenter Configuration Manager, title = VCMCertificate 7529006C-222F-4EBF-A7E7-F6AB15DB626F

Pagina 26

TLS Implementation for VCMTECHNICAL WHITE PAPER / 32Subject : O =VMware, Inc., OU = VMware vCenter Configuration Manager, title = VCMCertificate 75290

Pagina 27 - Certificate Store

TECHNICAL WHITE PAPER / 33Subject : O = QAT, OU = VMware vCenter Configuration Manager, title = VCMCertificate 7529006C-222F-4EBF-A7E7-F6AB15DB626F, C

Pagina 28

VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.comCopyright © 2010 VMware, Inc. All rights rese

Pagina 29

TLS Implementation for VCMTECHNICAL WHITE PAPER / 4Introduction to TLSTransport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL),

Pagina 30

TLS Implementation for VCMTECHNICAL WHITE PAPER / 5Certificates and Public Key InfrastructureA Public Key Infrastructure, or PKI, is a management syst

Pagina 31

TLS Implementation for VCMTECHNICAL WHITE PAPER / 6Note VCM supports certificate expiration. However, it does not support revocation lists. Certificat

Pagina 32

TECHNICAL WHITE PAPER / 7How VCM Uses CertificatesThere are three types of certificates that enable HTTP collector-agent communications in VCM:lEnterp

Pagina 33

TLS Implementation for VCMTECHNICAL WHITE PAPER / 8Figure 2: Shared Collector-Agent RelationshipAs the diagram above illustrates, an Agent may communi

Pagina 34

TECHNICAL WHITE PAPER / 9Figure 3: Trust Chain in a Shared Collector-Agent RelationshipIn addition, for Mutual Authentication in a shared Collector-Ag

Commenti su questo manuale

Nessun commento