Monday, April 21, 2014

Horizon Workspace 1.8.1 and Heartbleed patch

This day and age marks a great new release bound to get techies everywhere a mouth watering treat (no not that one). VMware released a patch for Horizon Workspace bringing the software to version 1.8.1!

Among numerous enhancements and fixes, this patch also includes an update to OpenSSL 1.0.1g which resolves the widespread vulnerability known as the Heartbleed Bug. You can check out the list of fixes in the Release Notes


Alongside this patch, you can apply a Heartbleed-only patch to your vApp if desired. If you're running Horizon Workspace 1.0, you must upgrade to at least version 1.5 to apply the Heartbleed fix manually. Likewise you can apply the Heartbleed fix to Workspace 1.8.0, but if you're taking the time to patch it, you might as well update to 1.8.1. See more info about that patch here: kb.vmware.com/kb/2076551


Applying the Heartbleed-Only fix (updating OpenSSL)


Applying the Heartbleed-only patch from the above KB, you should copy the RPM to somewhere on the Gateway-va (/tmp for example). I like to use WinSCP for copying files to and from my appliances. Then run the RPM and you will see it stop nginx and apply the patch:




You can always check the status of nginx afterward by running /etc/rc.d/nginx status

 

Per the KB, after running the OpenSSL fix you'll want to regenerate your SSL Certs. The steps are slightly different if you terminate SSL at the gateway-va vs a Load Balancer, so be sure to refer to the article.

 

You can find more details on the Heartbleed vulnerability here: www.vmware.com/security/advisories/VMSA-2014-0004.html

 

 

Updating Workspace 1.8.0 to 1.8.1
Be sure to check out the Release Notes


1. Take a snapshot of each appliance and the external DB VM
2. Login to the Configurator as root
3. Run /usr/local/horizon/lib/menu/updatemgr.hzn check and ensure you see the 1.8.1 update, then run /usr/local/horizon/lib/menu/updatemgr.hzn update
4.  Reboot the vApp.
NOTE: If you didn't apply the Heartbleed-specific patch above prior to updating to 1.8.1, then you must generate new SSL Certs and apply them to your gateway-va. See the post-installation steps outlined in kb.vmware.com/kb/2076551

<Screenshots coming soon>


Don't forget to also upgrade your Workspace Clients to 1.8.1!

If you have further queries or concerns about how Heartbleed could affect your Horizon View environment, take a gander at kb.vmware.com/kb/2076796  along with the VMware Security Advisories page.
Share:

Friday, April 18, 2014

Horizon Workspace 1.8.1 Client Update & Heartbleed bug

Last night VMware quietly released a patched Windows and OSX Client for Horizon Workspace 1.5 and 1.8 bringing the client to version 1.8.1. This client release includes an updated OpenSSL 1.0.1g. Alongside the release is a KB with the remediation steps for the Client regarding the pesky CVE-2014-0160 vulnerability.

You can continue to track the VMware advisory for this vulnerability here: http://www.vmware.com/security/advisories/VMSA-2014-0004.html

Get the downloads from the VMware Product Page.
Share:

Wednesday, April 9, 2014

Horizon 6 Announced



If you weren't able to attend the live webcast of the Horizon 6 announcement this morning, keep an eye on Twitter's @vmwarehorizon account for a link to watch it later.

Horizon 6 is the latest big news from VMware and is all the buzz for EUC land. There are a number of new features and capabilities that make this a very exciting release. Check out VMware's CTO announcement of it here: http://cto.vmware.com/introducing-horizon-6/?sf24825866=1

Sumit Dhawan, VP and GM of Desktop Products at VMware, frontlined the event and claimed Horizon 6 as an "Innovation Packed Release."

Horizon 6 will come in 3 flavors of licensing:

  1. View Standard - Simple, powerful VDI with great user experience
  2. Horizon Advanced - Cost-effective delivery of desktops and apps through a unified workspace
  3. Horizon Enterprise - Desktops and apps delivered with cloud automation and management
You can find more info in the Horizon 6 FAQ
Share:

Friday, March 14, 2014

Offline upgrades available for Horizon Workspace 1.8

Whether you're running Horizon Workspace 1.5 as a POC, or you restricted it to have internal access by design, admins who deployed Workspace without internet access can rejoice knowing that version 1.8 introduces a method for performing an "offline" upgrade. This option was not previously available when upgrading from 1.0 to 1.5.

The process includes setting up a local web server and using the updatelocal.hzn checkurl command against the web server.

When going through the upgrade guide, you may be wondering where you actually get the mentioned updaterepo.zip files. It's not clearly stated, however, you will need to contact VMware GSS Support in order to obtain those update bits.

http://pubs.vmware.com/horizon-workspace-18/topic/com.vmware.ICbase/PDF/horizon-workspace-18-upgrade.pdf
Share:

Wednesday, March 12, 2014

Horizon Workspace 1.8 is out!


As you may have heard, Horizon Workspace 1.8 became GA yesterday. This release hasn't been publicized too much but is a major improvement over the 1.5 release with many bug fixes. Some of the major changes include:
  • Citrix-based Application integration. From the Horizon Workspace User Portal, users can launch Citrix-based applications via XenApp 5.0, 6.0, and 6.5 using single sign-on. Note: Citrix Receiver must be installed on the client.
  • VMware ThinApp package delivery to Windows desktops. Horizon Workspace provides delivery of ThinApp 5.0 packages with 32-bit/64-bit applications to all Windows devices. HTTP delivery is supported to non-domain member endpoints on Windows devices.
  • Microsoft Office 365. Single sign-on from Workspace to Microsoft Office 365, SharePoint, and Outlook 365 web applications. Browser based and native email clients are supported.
  • Horizon Workspace User Portal and App Center. The User Portal has been enhanced to make application resource management easier. The App Center provides users with self-service category filtering, which shows the latest applications added.
  • Web application links. IT administrators can now create Web application links that do not require user authentication, allowing administrators to create static Web links.
  • Enterprise enhancements, including the following.
  • Support for multi-forest Active Directory deployments. You can integrate Horizon Workspace with multiple Active Directory (AD) forests.
  • Application access policy. IT administrators can apply access policies and select different authentication methods based on application type.
  • Support for enterprise branding of Horizon Workspace.
  • VMware Switch enhancements, including the following.
  • Support for Android 4.2 (JellyBean) as the workspace operating system.
  • Support for Android tablets.
  • Enhanced Horizon Mail 1.7x.

You can find the release notes here: http://hrzn.ws/1qwmOVe
And all other documentation here: http://hrzn.ws/1fqnNgO


Remember to join our Horizon Workspace Google+ page to share tips, tricks, and help build the Workspace community!
Share:

Thursday, March 6, 2014

What's compatible with Horizon View 5.3?

I'll bet you didn't know this existed!

Have you been wondering what's compatible with Horizon View 5.3 only to find documentation on VMware's website for View 5.2? There's a reason for that...

Horizon View 5.3 was originally supposed to be Horizon View 5.2.1 and was changed to 5.3 last minute. Hence, all the latest available documentation is still on 5.2 because it wasn't supposed to change. That being said, we still feel in the dark when it comes to compatibility with our shiny new 5.3 View Environment.

There's a KB for that...  =)

Compatibility Matrix for Horizon View Components During an Upgrade to Horizon View 5.3: http://kb.vmware.com/kb/2069327

Furthermore, the best solution for checking vSphere component compatibility is the VMware Product Interoperability Matrix. Definitely worth bookmarking!

http://partnerweb.vmware.com/comp_guide2/sim/interop_matrix.php?
Share:

Wednesday, February 26, 2014

Introducing the Horizon View Configuration Tool

Ever wished you could just deploy an OVA to setup your new View environment? Now you can! Thanks to Marilyn Basanta - a Solutions Management Engineer at VMware!


The Horizon View Configuration Tool automates Horizon View 5.3 installation and deployment. It removes the complexities and manual steps required for setting up a basic Horizon View deployment.

Features


The vCT ships as a virtual appliance with all the required VMware components to set up your Horizon View environment. After providing a Windows Server 2008 R2 SP1 ISO, an ESX host (not managed by vCenter), a few parameters, and licenses, the tool will provision your environment dynamically and automatically. The vCT deploys the following components:


  • Virtual machine with Active Directory Domain Controller configured (or you may integrate with the existing DC in your environment)

  • Virtual machine with Horizon View Connection Server installed

  • Virtual machine with Horizon View Composer installed

  • vCenter Server Appliance virtual machine deployed and configured


** Note this is a Tech Preview and is NOT going to be supported by VMware Global Support Services. 

 



 
Share: