SlideShare a Scribd company logo
vCenter – SSL Automation Tool
ESXi Host – OpenSSL
SRM – OpenSSL
vBrownbag – Michael Russell
@kerryspring2
kerryspring2@eircom.net
Resources #1
 #vBrownBag US View SSL Certs with Shane Williford
 http://professionalvmware.com/2012/12/vbrownbag-us-view-ssl-certs-with-
shane-williford-coolsportoo/
 #vBrownBag Follow-up How I learned to love the CSR with Jim Millard
 http://professionalvmware.com/2013/05/vbrownbag-follow-up-how-i-learned-
to-love-the-csr-with-jim-millard-millardjk/
 vSphere 5.1 Hardening Guide - Official Release
 http://communities.vmware.com/docs/DOC-22981
 Windows OpenSSL distribution (ver 0.9.8)
 http://slproweb.com/products/Win32OpenSSL.html
 How to use trusted certificates with VMware vCenter Site Recovery Manager
 http://communities.vmware.com/docs/DOC-11411
Resources #2
 vCenter Certificate Automation Tool Download
 https://my.vmware.com/group/vmware/get-download?downloadGroup=SSL-TOOL-101
 Generating certificates for use with the VMware SSL Certificate Automation Tool
 http://kb.vmware.com/kb/2044696
 Deploying and using the SSL Certificate Automation Tool (& Known Issues)
 http://kb.vmware.com/kb/2041600
 Process for Replacing SSL Certificates - vSphere 5 (7 Parts) - Julian Wood
 http://www.wooditwork.com/2011/11/30/vsphere-5-certificates-1-installing-a-root-
certificate-authority-3/
 vCenter 5.1 U1 installation including SSL replacement (15 Parts) - Derek Seaman
 http://www.derekseaman.com/2012/09/vmware-vcenter-51-installation-part-1.html
SSL Automation Tool Notes
 Microsoft Certificate Server SHA-1 vs SHA2-256
 Duplicate Template – Windows Server 2003 Enterprise
 Windows Server 2003 CA Server must be Enterprise Edition
 Deploy Root Certificate to Servers with vCenter components
 Generate chain.pem files from root64.cer & rui.crt
 Add Extensions: Allow Encryption of User Data (vCenter/ESXi)
/Client Authentication (SRM)
 OpenSSL v 0.9.8 – Copy OpenSSL DLLs to binaries (/bin) dir
 Certificate Tool vs vSphere Upgrades
http://kb.vmware.com/kb/2048202
 SSO user is admin@system-domain
 vCenter Database Password = ?
 Update Manager installation – Register FQDN, not IP Address
ESXi Hosts – SSL Notes
 ESXi Host HA Issues: http://kb.vmware.com/kb/2006210
 perl HostReconnect.pl --server <ip address> --username
administrator@lab.local
 vMA permit Winscp:
http://communities.vmware.com/message/2020784
sudo vi /etc/host.allow
add the following line;
sshd: ALL: ALLOW
then save the file :WQ!
 OpenSSL Commands to generate CSR:
 openssl req -new -nodes -out rui.csr -keyout rui.key -config
openssl.cfg
 Drop rui.crt & rui.key into /etc/vmware/ssl
ESXi Hosts – OpenSSL.cfg
 default_bits = 2048 (Change from 1024)
 default_keyfile = rui.key (Change from privkey.pem)
 req_extensions = v3_req (Remove # at start of line)
 countryName_default = IE (Update to your Country Code)
 stateOrProvinceName_default = Leinster (Update)
 localityName_default = Dublin (Add & Update)
 0.organizationName_default = Lab (Update to your Company Name)
 organizationalUnitName_default = IT (Update & Remove # at start of line)
 [ v3_req]
 subjectAltName = @alt_names (Add this under “keyUsage =“ line)
 [alt_names]
 DNS.1 = iedubdc2esx01.lab.local (Use FQDN here)
 DNS.2 = iedubdc2esx01 (Use Shorter Netbios Name here)
SRM – OpenSSL.cfg
 OpenSSL Command to export certificate file for SRM:
 openssl pkcs12 -export -in rui.crt -inkey rui.key -name rui -
passout pass:testpassword -out rui.p12
 OpenSSL.cfg changes:
 [ v3_req]
 extendedKeyUsage = serverAuth, clientAuth (Add under
“keyUsage =“ entry)
 [alt_names]
 DNS.1 = iedubdc2vc01.lab.local (Use FQDN of SRM Server
here)
 DNS.2 = iedubdc2esx01 (Delete this line)

More Related Content

What's hot (20)

PDF
Oracle obiee-11-installation-guide 11.1.1.6.0
Aadiseshu Immadisetty
 
PPTX
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Dhruv Sharma
 
PDF
Webmin configuration in Linux
Thamizharasan P
 
PPTX
Docker
Jo Ee Liew
 
PPTX
Guidlines sitecore9 installation
PRADEEP GUPTA
 
PPTX
WebSockets On Fire
Jef Claes
 
PPTX
WordPress security for everyone
Vladimír Smitka
 
PDF
How HTTP/2 will change the web as we know it
Nils De Moor
 
PPS
Squid
Chirag Gupta
 
PPT
Top 12 php frameworks 2016
ValueCoders
 
PPTX
Mike MacCana - Deploying your JS app in 2018
OdessaJS Conf
 
PDF
Clouldera Implementation Guide for Production Deployments
Ahmed Mekawy
 
PDF
Make WordPress Fly With Virtual Server Hosting - WordCamp Sydney 2014
Vlad Lasky
 
PPTX
Enhancing Mobile User Experience with WebSocket
Mauricio "Maltron" Leal
 
PDF
SOA with C, C++, PHP and more
WSO2
 
PDF
Percona University - ProxySQL para MySQL
Marcelo Altmann
 
KEY
Mobile Activesync Russian Roulette - Kiwicon 09
deathflu
 
PPTX
DB Floripa - ProxySQL para MySQL
Marcelo Altmann
 
PDF
EvasionTechniques
Candan BOLUKBAS
 
PDF
WebSockets: The Current State of the Most Valuable HTML5 API for Java Developers
Viktor Gamov
 
Oracle obiee-11-installation-guide 11.1.1.6.0
Aadiseshu Immadisetty
 
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Dhruv Sharma
 
Webmin configuration in Linux
Thamizharasan P
 
Docker
Jo Ee Liew
 
Guidlines sitecore9 installation
PRADEEP GUPTA
 
WebSockets On Fire
Jef Claes
 
WordPress security for everyone
Vladimír Smitka
 
How HTTP/2 will change the web as we know it
Nils De Moor
 
Top 12 php frameworks 2016
ValueCoders
 
Mike MacCana - Deploying your JS app in 2018
OdessaJS Conf
 
Clouldera Implementation Guide for Production Deployments
Ahmed Mekawy
 
Make WordPress Fly With Virtual Server Hosting - WordCamp Sydney 2014
Vlad Lasky
 
Enhancing Mobile User Experience with WebSocket
Mauricio "Maltron" Leal
 
SOA with C, C++, PHP and more
WSO2
 
Percona University - ProxySQL para MySQL
Marcelo Altmann
 
Mobile Activesync Russian Roulette - Kiwicon 09
deathflu
 
DB Floripa - ProxySQL para MySQL
Marcelo Altmann
 
EvasionTechniques
Candan BOLUKBAS
 
WebSockets: The Current State of the Most Valuable HTML5 API for Java Developers
Viktor Gamov
 

Viewers also liked (19)

PPTX
Photography best work december
jojoycexxx
 
DOC
Media development diary word
jojoycexxx
 
PPTX
Themes 17418838
Erin Holloway
 
PDF
Web economy, start up nel 2013.
Livia Bosi
 
PPTX
Plan
jojoycexxx
 
PPTX
Main task and intial ideas media
jojoycexxx
 
PPTX
Television sponsorship
jojoycexxx
 
PPTX
Best work photog
jojoycexxx
 
PPTX
Presentation1bestwork
jojoycexxx
 
PPTX
Textual analysis powerpoint media
jojoycexxx
 
PPTX
Themes
Erin Holloway
 
PPTX
Tv advert powerpoint
jojoycexxx
 
PDF
L’efficacia e la diffusione degli strumenti 2.0 nella piccola e media impresa...
Livia Bosi
 
PPTX
Introduction to spelling strategies- 17418838
Erin Holloway
 
PPTX
History of television advertisments
jojoycexxx
 
PPTX
Codal analysis
jojoycexxx
 
PDF
Web Runners - Imprese 2.0
Livia Bosi
 
PDF
Webbing Rank Cities
Livia Bosi
 
PPTX
Projectproposal1
jojoycexxx
 
Photography best work december
jojoycexxx
 
Media development diary word
jojoycexxx
 
Themes 17418838
Erin Holloway
 
Web economy, start up nel 2013.
Livia Bosi
 
Main task and intial ideas media
jojoycexxx
 
Television sponsorship
jojoycexxx
 
Best work photog
jojoycexxx
 
Presentation1bestwork
jojoycexxx
 
Textual analysis powerpoint media
jojoycexxx
 
Tv advert powerpoint
jojoycexxx
 
L’efficacia e la diffusione degli strumenti 2.0 nella piccola e media impresa...
Livia Bosi
 
Introduction to spelling strategies- 17418838
Erin Holloway
 
History of television advertisments
jojoycexxx
 
Codal analysis
jojoycexxx
 
Web Runners - Imprese 2.0
Livia Bosi
 
Webbing Rank Cities
Livia Bosi
 
Projectproposal1
jojoycexxx
 
Ad

Similar to Ssl slides (20)

PPTX
SSL deep dive vCenter Server 5.5
fbuechsel
 
PPTX
VMworld 2015: VMware vSphere Certificate Management for Mere Mortals
VMworld
 
PDF
OSCM 2024 | Ignite: Monitoring and maintaining self-signed certificates is da...
NETWAYS
 
PDF
vsphere-esxi-vcenter-sesecurity-guide.pdf
hokismen
 
PDF
320.1-Cryptography
behrad eslamifar
 
PPTX
2016.11.03 ncwivmug super meeting - v sphere 6 upgrade
Paul Woodward Jr
 
PDF
SSL Certificates and Operations
Nisheed KM
 
PPTX
VMworld 2015: Managing vSphere 6 Deployments and Upgrades
VMworld
 
DOCX
Vmware Training in Bangalore | Certification
apponix123
 
DOCX
V mware course contents copy
Rakesh Puppala
 
PPTX
2016.07.20 indy vmug usercon - vsphere 6 upgrade
Paul Woodward Jr
 
DOCX
Vmware training course
FuturePoint Technologies
 
PPT
How to configure esx to pass an audit
Concentrated Technology
 
PPTX
Vmware Data Center Virtualization ESXI and vCenter
A. Shamel
 
PDF
Web server hardware and software
Saquib Suhail
 
PPTX
London VMUG - Upgrade vSphere 5.5 to 6.5
Dean Lewis
 
PDF
vsphere5.5 to 6.5
Srinivasa Rao Kotamraju
 
PDF
June OpenNTF Webinar - Domino V12 Certification Manager
Howard Greenberg
 
PDF
VMworld 2013: vSphere Upgrade Series Part 1: vCenter Server
VMworld
 
PDF
VMworld 2013: vCenter Deep Dive
VMworld
 
SSL deep dive vCenter Server 5.5
fbuechsel
 
VMworld 2015: VMware vSphere Certificate Management for Mere Mortals
VMworld
 
OSCM 2024 | Ignite: Monitoring and maintaining self-signed certificates is da...
NETWAYS
 
vsphere-esxi-vcenter-sesecurity-guide.pdf
hokismen
 
320.1-Cryptography
behrad eslamifar
 
2016.11.03 ncwivmug super meeting - v sphere 6 upgrade
Paul Woodward Jr
 
SSL Certificates and Operations
Nisheed KM
 
VMworld 2015: Managing vSphere 6 Deployments and Upgrades
VMworld
 
Vmware Training in Bangalore | Certification
apponix123
 
V mware course contents copy
Rakesh Puppala
 
2016.07.20 indy vmug usercon - vsphere 6 upgrade
Paul Woodward Jr
 
Vmware training course
FuturePoint Technologies
 
How to configure esx to pass an audit
Concentrated Technology
 
Vmware Data Center Virtualization ESXI and vCenter
A. Shamel
 
Web server hardware and software
Saquib Suhail
 
London VMUG - Upgrade vSphere 5.5 to 6.5
Dean Lewis
 
vsphere5.5 to 6.5
Srinivasa Rao Kotamraju
 
June OpenNTF Webinar - Domino V12 Certification Manager
Howard Greenberg
 
VMworld 2013: vSphere Upgrade Series Part 1: vCenter Server
VMworld
 
VMworld 2013: vCenter Deep Dive
VMworld
 
Ad

Recently uploaded (20)

PDF
Human-centred design in online workplace learning and relationship to engagem...
Tracy Tang
 
PDF
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
PDF
Empowering Cloud Providers with Apache CloudStack and Stackbill
ShapeBlue
 
PDF
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
PDF
Apache CloudStack 201: Let's Design & Build an IaaS Cloud
ShapeBlue
 
PDF
TrustArc Webinar - Data Privacy Trends 2025: Mid-Year Insights & Program Stra...
TrustArc
 
PDF
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
PPTX
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
PDF
CloudStack GPU Integration - Rohit Yadav
ShapeBlue
 
PDF
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
PPTX
Top Managed Service Providers in Los Angeles
Captain IT
 
PDF
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
PPTX
Darren Mills The Migration Modernization Balancing Act: Navigating Risks and...
AWS Chicago
 
PPTX
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
PPTX
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
PDF
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
PPT
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
PDF
Predicting the unpredictable: re-engineering recommendation algorithms for fr...
Speck&Tech
 
PDF
Persuasive AI: risks and opportunities in the age of digital debate
Speck&Tech
 
Human-centred design in online workplace learning and relationship to engagem...
Tracy Tang
 
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
Empowering Cloud Providers with Apache CloudStack and Stackbill
ShapeBlue
 
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
Apache CloudStack 201: Let's Design & Build an IaaS Cloud
ShapeBlue
 
TrustArc Webinar - Data Privacy Trends 2025: Mid-Year Insights & Program Stra...
TrustArc
 
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
CloudStack GPU Integration - Rohit Yadav
ShapeBlue
 
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
Top Managed Service Providers in Los Angeles
Captain IT
 
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
Darren Mills The Migration Modernization Balancing Act: Navigating Risks and...
AWS Chicago
 
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
Predicting the unpredictable: re-engineering recommendation algorithms for fr...
Speck&Tech
 
Persuasive AI: risks and opportunities in the age of digital debate
Speck&Tech
 

Ssl slides

  • 1. vCenter – SSL Automation Tool ESXi Host – OpenSSL SRM – OpenSSL vBrownbag – Michael Russell @kerryspring2 [email protected]
  • 2. Resources #1  #vBrownBag US View SSL Certs with Shane Williford  http://professionalvmware.com/2012/12/vbrownbag-us-view-ssl-certs-with- shane-williford-coolsportoo/  #vBrownBag Follow-up How I learned to love the CSR with Jim Millard  http://professionalvmware.com/2013/05/vbrownbag-follow-up-how-i-learned- to-love-the-csr-with-jim-millard-millardjk/  vSphere 5.1 Hardening Guide - Official Release  http://communities.vmware.com/docs/DOC-22981  Windows OpenSSL distribution (ver 0.9.8)  http://slproweb.com/products/Win32OpenSSL.html  How to use trusted certificates with VMware vCenter Site Recovery Manager  http://communities.vmware.com/docs/DOC-11411
  • 3. Resources #2  vCenter Certificate Automation Tool Download  https://my.vmware.com/group/vmware/get-download?downloadGroup=SSL-TOOL-101  Generating certificates for use with the VMware SSL Certificate Automation Tool  http://kb.vmware.com/kb/2044696  Deploying and using the SSL Certificate Automation Tool (& Known Issues)  http://kb.vmware.com/kb/2041600  Process for Replacing SSL Certificates - vSphere 5 (7 Parts) - Julian Wood  http://www.wooditwork.com/2011/11/30/vsphere-5-certificates-1-installing-a-root- certificate-authority-3/  vCenter 5.1 U1 installation including SSL replacement (15 Parts) - Derek Seaman  http://www.derekseaman.com/2012/09/vmware-vcenter-51-installation-part-1.html
  • 4. SSL Automation Tool Notes  Microsoft Certificate Server SHA-1 vs SHA2-256  Duplicate Template – Windows Server 2003 Enterprise  Windows Server 2003 CA Server must be Enterprise Edition  Deploy Root Certificate to Servers with vCenter components  Generate chain.pem files from root64.cer & rui.crt  Add Extensions: Allow Encryption of User Data (vCenter/ESXi) /Client Authentication (SRM)  OpenSSL v 0.9.8 – Copy OpenSSL DLLs to binaries (/bin) dir  Certificate Tool vs vSphere Upgrades http://kb.vmware.com/kb/2048202  SSO user is admin@system-domain  vCenter Database Password = ?  Update Manager installation – Register FQDN, not IP Address
  • 5. ESXi Hosts – SSL Notes  ESXi Host HA Issues: http://kb.vmware.com/kb/2006210  perl HostReconnect.pl --server <ip address> --username [email protected]  vMA permit Winscp: http://communities.vmware.com/message/2020784 sudo vi /etc/host.allow add the following line; sshd: ALL: ALLOW then save the file :WQ!  OpenSSL Commands to generate CSR:  openssl req -new -nodes -out rui.csr -keyout rui.key -config openssl.cfg  Drop rui.crt & rui.key into /etc/vmware/ssl
  • 6. ESXi Hosts – OpenSSL.cfg  default_bits = 2048 (Change from 1024)  default_keyfile = rui.key (Change from privkey.pem)  req_extensions = v3_req (Remove # at start of line)  countryName_default = IE (Update to your Country Code)  stateOrProvinceName_default = Leinster (Update)  localityName_default = Dublin (Add & Update)  0.organizationName_default = Lab (Update to your Company Name)  organizationalUnitName_default = IT (Update & Remove # at start of line)  [ v3_req]  subjectAltName = @alt_names (Add this under “keyUsage =“ line)  [alt_names]  DNS.1 = iedubdc2esx01.lab.local (Use FQDN here)  DNS.2 = iedubdc2esx01 (Use Shorter Netbios Name here)
  • 7. SRM – OpenSSL.cfg  OpenSSL Command to export certificate file for SRM:  openssl pkcs12 -export -in rui.crt -inkey rui.key -name rui - passout pass:testpassword -out rui.p12  OpenSSL.cfg changes:  [ v3_req]  extendedKeyUsage = serverAuth, clientAuth (Add under “keyUsage =“ entry)  [alt_names]  DNS.1 = iedubdc2vc01.lab.local (Use FQDN of SRM Server here)  DNS.2 = iedubdc2esx01 (Delete this line)