Thursday, April 30, 2015

VMware releases vSphere security patches

Calling all non-vSphere 5.5 users. Check out today's new VMware releases which address JRE security vulnerabilities, as well as SKIP-TLS, FREAK, and POODLE.

More details in the release notes linked below.

VMware vCenter Server 5.0 U3d
VMware vCenter Server 5.1 U3a
VMware vSphere VUM 5.0 U3d
VMware vSphere VUM 5.1 U3a
VMware vCenter Orchestrator 5.1.3.1
VMware vCloud Networking and Security 5.5.4.1
Share:

Monday, April 27, 2015

Freeing my iPad of Social Media is the best thing I've done

Whether you're an Apple fan boy, or a die hard Android enthusiest, we can all agree tablets are great. I've recently come to realize, however, how much more I can enjoy my iPad when I exclude certain distractions from it. Namely, social media. 

Twitter, Facebook, Instagram - our digitial social lives are calling out for our attention ALL the time. I've come to realize the benefit of not only finding a time and place for social media, but also a platform for it.

Like most, my phone is with me pretty much wherever I go. And this is what I generally use for things like Twitter and Instagram (I ditched Facebook months ago - yet another hugely gratifying decision, but is a story for another day). My iPad is also with me quite often, but I tend to use it for different things.

For instance, though my iPad and iPhone are capable of the same applications, I much, much prefer to use my iPad for reading a book, checking out a comic book, or catching up on saved blog posts. There's something to be said about having that screen real estate for reading. It was far too often though that these activities would get distracted by social notifications. Not only notifications, but it's more peaceful reading a book now knowing I'm not subconciously looking for that next great quote to tweet, or that new blog post that should get shared.

I can enjoy a good news article or book way more now than before when I knew my social media was just around the corner.

Sure there are plenty of other ways to get distracted. Maybe you're more prone to spend hours on YouTube, or browse all the latest podcasts (who are you?). On the other hand, there's a good chance you have more self control than I. But the fact of the matter is, I can enjoy a good news article or book way more now than before when I knew my social media was just around the corner. I've even gone to disable the majority of notifications on my iPad to simmer down distractions.

Differentiating what my iPhone and iPad are used for has greatly improved my enjoyment of each device. Maybe you're different and you enjoy having all the same apps on your phone and your tablet. More power to you!

As silly as a post this is, it's something that has dramatically increased my productivity and media consumption enjoyment. Try it out. You'll probably be glad you did!
Share:

Thursday, April 2, 2015

Fast Lane Support for VMware's Premier Services customers

The latest version of the My VMware mobile application now allows VMware Premier Services customers to open up a Severity 1 SR and get connected to support in minutes. This new feature is called "Fast Lane Support" and is now live!






Check it out on iTunes: https://itunes.apple.com/us/app/my-vmware/id512689552?mt=8

Check it out on Google: https://play.google.com/store/apps/details?id=com.vmware.myvmware&hl=en
Share:

Thursday, March 12, 2015

VMware New Releases including vSphere 6.0 and Horizon View 6.1

Today was a busy day for VMware! In the midst of all the noise and chatter, it's easy to get overwhelmed with all the new information. Below is a compiled list of useful KB articles for vSphere 6.0, including upgrade and installation documents, as well as other new product release notes not to be overlooked. Enjoy!


vSphere Prereqs
=============
Important Information before upgrading to vSphere 6.0 (2110293)
Update sequence for vSphere 6.0 and its compatible VMware products (2109760)
List of recommended topologies for vSphere 6.0.x (2108548)

vCenter Installation
=====================
Installing vCenter Server 6.0 best practices (2107948)
Installing VMware vCenter Server 6.0 with an embedded Platform Services Controller on a Windows machine (2108799)
Installing VMware vCenter Server 6.0 with an external Platform Services Controller on a Windows machine (2108802)
Uninstalling vCenter Server 6.0.x resets the embedded VMware Postgres database (2108547)

vCenter Upgrade
================
Upgrading to vCenter Server 6.0 best practices (2109772)
Upgrading to vCenter Server 6.0 without migrating SQL database to vPostgres (2109321)
Upgrading to VMware vCenter Server 6.0 with an embedded Platform Services Controller from vCenter Server 5.5 installed using the simple install method (2109559)
Upgrading VMware vCenter Single Sign-on 5.5 to a VMware vCenter Server 6.0 Platform Services Controller 6.0 (2109560)
Upgrading VMware vCenter Server 5.5 to vCenter Server 6.0 with an external Platrfom Services Controller (2109562)

ESXi Installation
==================
Best practices to install or upgrade to VMware ESXi 6.0 (2109712)
Methods of installing ESXi 6.0 (2109708)

ESXi Upgrade
==============
Methods for upgrading to ESXi 6.0 (2109711)

Maintenance
============
Recovering from a failed upgrade of vCenter Server 5.1 or 5.5 to 6.0 (2108938)
Back up and restore the embedded PostgreSQL database (2091961)
How to backup and restore vCenter Server 6.0 external deployment models (2110294)

Release Notes
============
VMware vCenter Server 6.0

VMware vCenter Server Appliance 6.0

VMware vSphere ESXi 6.0

VMware vRealize Operations for Horizon 6.1.0

VMware vRealize Automation 6.2.1

VMware vRealize Orchestrator 6.0.1

vRealize Business Advanced\Enterprise 8.2.1

vRealize Business Standard 6.1.0

vRealize Code Stream 1.1.0

vRealize Infrastructure Navigator 5.8.4

vRealize Operations Manager 5.8.5

VMware vCloud Networking and Security 5.5.4

VMware vCenter Site Recovery Manager 6.0

VMware Virtual SAN 6.0

VMware vSphere Data Protection 6.0

VMware vSphere Replication 6.0

vCenter Host Gateway 6.0

VMware Integrated OpenStack v1.0

VMware Update Manager 6.0

vSphere Update Manager PowerCLI 6.0

VMware View 6.1

VMware Horizon Client for Windows 3.3

VMware Workspace Portal 2.1.1

VMware App Volumes 2.6
Share:

Monday, February 9, 2015

Workspace Portal, Access Policies, and Kerberos authentication

You've decided it's time to expand your Workspace Portal deployment from internal-only, to also allow external access. You've setup your Load Balancer, gotten your certificates in place, and now you're tasked with configuring internal and external authentication methods.

This post covers the configuration needed for Kerberos on internal connections, while allowing username/password authentication from external connections.

Access Policies


First, let's setup your access policies. Access Policies allow you to specify criteria that users must meet in order to access Workspace Portal. We're going to configure the Default Access Policy Set to include two policies: internal and external

For our internal connections, we're going to utilize Kerberos. Configuring Kerberos isn't covered in this post, so ensure you have it working first. Here are some helpful posts for setting it up:

Configuring Kerberos for Workspace
Kerberos SSO in Workspace 1.8 (basic config flow still applies to Workspace Portal 2.1)

For our external connections, we'll let our users utilize their Active Directory synced username and passwords for authentication. Ensure your Directory Sync rules from the Connector Service Admin page include all desired AD groups and that they're synced regularly.

First: ensure you've created both an internal and an external Network Range:

  1. Log into the Workspace Admin Portal > Settings > Network Ranges

  2. Click + Network Range to add our internal range. Configure this to the appropriate subnets used in your LAN.

  3. We'll use the default ALL RANGES entry for our external connections


Then, from the Policies tab, we'll edit the default_access_policy_set to correspond to these network ranges.

  1. Click + Access Policy and name it internal. Set it to use a Minimum Authentication Score of 1. 

  2. Then select the default 'web policy' which corresponds to our external network range. We'll set this to a Minimum Authentication Score of 2 as seen below:


NOTE: Be sure to re-arrange the policies so that internal is on top, and 'web policy' is on bottom and click Save.


Authentication method



Now, head to Settings > Authentiation Methods and order the options as seen here. Be sure to click each entry to edit the Authentication Score to match the below screenshot. Once again, order is important.



Notice that Kerberos is on top, with an authentication score of 1.



Set Kerberos as the Default Method



Password will be set to an authentication score of 2.


At this point, you should be able to verify that your user portal loads from both internal and external locations, as well as verify that your internal users aren't prompted for their credentials.


Troubleshooting



Scenario 1:

When launching Workspace Portal externally, the page times out and doesn't load, but internally it launches.


Scenario 2:

When launching Workspace Portal externally, the page loads, but internally, users are prompted for username and password (Kerberos fails to login the user)


   - In either case, verify the order of your Access Policies have Kerberos on top, password on bottom. Also verify that the scores are set appropriately, per the screenshots

Share:

Monday, January 26, 2015

Workspace Portal Administrative Consoles

Workspace Portal has had a few facelifts over the years. Some remember the Horizon Workspace 1.x days of the multi-vm vApp where 5 different VMs were responsible for 5 different services. One difficulty resulting from this architecture was different VMs, with different URLs, that had different settings. This vApp then went down to 4 VMs with Workspace Portal 2.0, and now all necessary services are handled in a single-vm vApp with Workspace Portal 2.1, simplifying deployment and configuration.

The configuration, however, done through Workspace's administrative links can still be a bit daunting to the new administrator.

Workspace Portal has 3 primary locations used to customize and configure the appliance. These 3 locations, or "Quick Links" can be accessed from https://:8443



Set it and forget it.

The first link is the Appliance Configurator. I like to think of this link as the "Set it and forget it" link. When you configure the settings from this page, you won't need to access the page very often anymore - things like your FQDN and your database connection. Clicking on this link, you'll notice it prompts for your Admin password you initially setup upon first connecting to Workspace, which brings us to the Configurator Admin page

NOTE: you can also access this page directly by navigating to https://:8443/cfg/setup



The most important settings configured from this page are the Database, SSL Cert, and FQDN. The optional settings are for setting up a syslog server, changing admin/ssh account passwords, and generating support log bundles. If you're ever opening up a support request with VMware Support, be sure to include a log bundle collected from this location.

Connecting services to Workspace Portal.

Next we'll look at the Connector Services Admin link. Think of this as where we'll "connect" Workspace to other services in your environment, whether it's your existing Active Directory users and groups, Horizon View desktops and hosted apps, SaaS applications, and the authentication methods for said services.

NOTE: you can also access thsi page directly by navigating to https://:8443/hc/admin/about



Finally you have the Workspace Admin Portal. Think of this as where you refine the end-results of your working instance. From here, you can access a tab called Settings which has some misceallaneous settings - things from obtaining SAML Metadata for your SaaS service providers, to tweaking your Authentication Methods for your synced internal and external users.



Related Documentation:
Introduction to Workspace for Administrators
Share:

Wednesday, January 7, 2015

Running the VMware Horizon View Client 3.2 in Ubuntu (and Ubuntu derivatives)

Have you ever felt like a Linux user in a Windows VDI world? You're not alone!

Any Linux fans that are familiar with the world of VDI know that the VMware View Client for Linux has appeared stuck at version 2.2 for what seems like forever. Then in December of 2014, we were given a lovely gift: the Horizon Client for Linux version 3.2.

In your excitement you download the client, open up your terminal, run the installer and launch the new release only to find your system has missing requirements. In the Users Guide for the 3.2 client, you'll find a laundry list of system requirements and pre-requisites. The trickiest of all being the OpenSSL requirements (not to mention 64-bit systems aren't supported).

This post will walk you through getting past the system requirements and getting the 3.2 Client up and running on your Ubuntu (or similar) system.

In this article, I will be installing the client on Linux Mint 17.1 x64, but please be aware that VMware will not support the Horizon View Client outside of the system requirements outlined in the Users Guide.


  1. Download the .bundle from VMware here

  2. Run the installer by typing  sudo sh ./file_name


  3. This should launch the GUI installer. Accept the EULA


  4. Configure your desired settings and verify the installation was successful



Hooray! You should be done right? Well most likely you may run into issues once you click that Scan button. You'll find that you pretty much bombed your mid-term:



Not to worry though, this is very simple to fix!

Now for my purposes, the only lib files I care about are libcrypto.so and libssl.so. I won't be using USB redirection or RTAV. What we need to do is create symbolic links between the 1.0.0 versions that I have installed, with the 1.0.1 naming that the Horizon Client wants to use. Let's start by finding where our current files live

  1. Use the find command to locate your libcrypto and libssl files

    sudo find / -iname libssl*

  2. Once you have the full paths of the files, create your symbolic links using

    sudo ln -s source_file destination_file


  3. Now re-run your Scan test - you should find the appropriate files are now back on track to walk at graduation!



And congratulations are in order! You should now have a functioning 3.2 Horizon Client. You may see a dialog that reads:


VMware Horizon Client requires openssl-1.0.1i or above. But 1.0.1f seems to be installed on your system. This discrepancy could result in unexpected problems or even security leaks. Contact your administrator for more information.

Since you're using your system's openssl lib files, any system updates that affect these files shouldn't break compatibility - however if openssl gets updated later on, you'll likely need to update your symlinks to reflect the updated lib versions.




Now go get some work done!

Share: