Showing posts with label VCAP-DCA. Show all posts
Showing posts with label VCAP-DCA. Show all posts

Wednesday, November 14, 2012

Ultimate VCAP5-DCD / VCAP5-DCA preparation Links

I have read so many blogs out there discussing and preparing you for VCAP5-DCD. For VCAP5-DCA I did not make any preparation except doing some tasks in my home lab as I have appeared for the BETA exam and passed it.

These blogs are no doubt not to be under rated or such for those who are getting ready as they add more value of course. Now this is not some kind of judgement about which blog is good/bad but actually the nature of content which brought me to a position where I can just suggest to read them/go through while preparing for the exams. So don't go and compare one to another. All the information available through blog posts by our community members are equally important and valuable in their own stance. To add to that this is not some kind of competition where there is a winner or the 1st rank will be given, but simply the Quality of the Content which matters.

But to me one blog just came on the surface while I was looking at the content for VCAP5-DCD




This blog site is maintained by our 3 Engineers of VMware, Jarrett, Joe and Karim. I have personally work with them on numerous occasions and the stuff they have put on the blog is top notch. They have blended the information from everywhere possible to make the flow lot smoother while you are reading. The best thing is to have the links ready for further reading if one needs to dig deeper in a subject. They have also written for VCAP5-DCA so you can check that out too.

Recently @ForbesGuthrie passed his VCAP5-DCD and he mentioned in his Tweet that he used this blog for the preparation. So this is one of the use cases I would say :-) while recommending this site.


 
Now I have not meet him yet but know him as he was one of the writers of VMware vSphere Design 4 book which help you preparing for VCAP-DCD Version 4. Now most of the content you can definitely use for Version 5 as well as far as the design methodologies and principles are concerned.

One day I was researching for some specific issue and then found about the www.thefoglite.com. This is another Top recommendation for VCAP5-DCA by Ethan Rowe (@rowe_ethan)




Now at the same time I don't want to miss a chance to give the credits to @JoshCoen (Blogpost) and @jaslanger (Blogpost) for their respective contributions for VCAP5-DCA.

Hopefully this will help you in preparing for both VCAPs along with other resources out there which may includes various blog sites, videos, online sessions etc. etc.

My 2c.

Good Luck to all going for VCDX  !!!!!



Tuesday, November 13, 2012

VMware Training and Credits

Here is the summary where you can associate the VMware Training and how many training credits that course has.

Its easy to interpret the credits into the training you can attend for the courses offered by VMware Education as of today.



If you have any question and you can visit the Education and Certification site.

http://mylearn.vmware.com/portals/www/

Enjoy learning.

Sunday, July 8, 2012

All Free Courses offered by VMware Education !!

Now a days lot of companies have their various certifications in the market to compete others in the same area and VMware also has few new certifications released recently which includes VCAP5-DCD, VCP5-DT etc. for the Datacenter and Desktop streams.

Few others are in BETA stages such as VCAP5-DCA and VCP-IaaS right now and will become publicly available in future. The BETA Period is over by now for both exams so whomsoever willing to appear have to wait till it generally available.

The following list includes almost all the courses offered Free of Cost (self-paced) by VMware and the areas starts from vSphere Fundamentals, View, vShiled, vCenter Operations Manager, vCenter Chargeback, Site Recovery Manager, Virtualizing Tier 1 Databases such as SQL and Oracle and not limited to that but also included courses for the TC Server, GemFire, Groovy Grails, SpringSource, Hyperic (Companies acquired by VMware) etc. etc.

I have tried finding all the Free courses offered by VMware Education and if you find any course for which there is a cost involved then pleaes leave the feedback so that I can update the list accordingly.

These courses are very good for the person who never knew what vMware vSphere is or what ESX/ESXi server is. These courses are covering the starter level areas covering desktop products such as Workstation, Fusion, Lab manager, vSphere upto all at the advanced level areas such as vShiled, Tier 1 Database virtualization, View Design, Business Continuity and Disaster Recovery etc. etc.

These courses are worth if one is preparing for any entry level certification like VCP to an advanced certification such as VCAP-DCD or VCAP-DCA for various tracks such as vSphere, View or IaaS (new upcoming first vCloud Certification).


vSphere 5.x and 4.1, SRM, DR/BC,Chargeback, Capacity IQ, AppSpeed,

• VMware vSphere What's New in 5.1

http://mylearn.vmware.com/mgrReg/courses.cfm?ui=www_edu&a=det&id_course=149391


• VMware vSphere Fundamentals 4.1

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=22153

• VMware vSphere: What's New in vSphere 4

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=15448

• VMware vSphere: Resource Management Fundamentals

http://mylearn.vmware.com/register.cfm?course=122604&ui=www_edu

• VMware vSphere: Security Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=29803

• VMware vSphere: Data Protection and Recovery Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=29800

• VMware vCenter AppSpeed Fundamentals

http://mylearn.vmware.com//mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=15816

• VMware vCenter CapacityIQ Fundamentals

http://mylearn.vmware.com//mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=18269

• VMware vCenter Lab Manager 4.0 Fundamentals

http://mylearn.vmware.com//mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=15589

• VMware vCenter Chargeback Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=15658

• VMware vCenter Chargeback Fundamentals [v1.6]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=24215

• VMware vCenter Operations Manager Fundamentals [v5.x]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=31413

• VMware vCenter Configuration Manager Fundamentals [v5.x]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=30255

• Site Recovery Manager (SRM) Fundamentals

http://mylearn.vmware.com//mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=20252

Business Continuity and Disaster Recovery Design 5.1 Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=133207

• VMware vSphere: Transition to ESXi Essentials [V4.1]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=96341


Virtualizing SQL and Oracle Databases and Sharepoint

Virtualizing Microsoft SharePoint with VMware [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=132810

Virtualizing Microsoft SQL Server with VMware

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=135400

Virtualizing Oracle Database with VMware [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=134761


vCloud, vShield, vCenter Chargeback, Configuration Manager

VMware vCloud Director Fundamentals [V1.5]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=134582


Introduction to the VMware Security Solution Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=31788

VMware vShield Fundamentals [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=133169

VMware vShield App Fundamentals [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=31784

VMware vShield Data Security Fundamentals [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=133175

VMware vShield Edge Fundamentals [V5.X] 

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=31786

VMware vShield Endpoint Fundamentals [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=133181

VCP-IaaS signup sheet

https://docs.google.com/spreadsheet/viewform?formkey=dGdQQkFJQVNwM0pTdWZpbzVjbFphb2c6MQ


VMware View and vCenter vCOPS

What's New in Vmware view v4.5

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=21103

View Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=27841

View Fundamentals [V5.0]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=134581

ThinApp Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=19218

VMware vCenter Operations Manager Fundamentals [V5.X]

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=det&id_course=132265



Desktop Products - Workstation and Fusion

• VMware Workstation 7: Fundamentals

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=17725

• VMware Workstation 7: Advanced

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=18921

• VMware Fusion 3

http://mylearn.vmware.com/mgrreg/courses.cfm?ui=www_edu&a=one&id_subject=17857


SpringSource has their own certifications as follows about which you can find out more information by visiting http://www.springsource.com/training.


1) Springsource Certified Spring Professional
2) Springsource Certified Spring WebApplication Developer
3) Springsource Certified Spring Enterprise Integration Specialist


TC, Gemfire, vFabric, SpringSource, Groovy Grails,

vFabric GemFire Essentials  [114441]

http://mylearn.vmware.com/register.cfm?course=114441&ui=www_edu

vFabric TC Server Essentials  [114442]

http://mylearn.vmware.com/register.cfm?course=114442&ui=www_edu

vFabric Hyperic Essentials  [99416]

http://mylearn.vmware.com/register.cfm?course=99416&ui=www_edu

Developing Aspects with AOP

http://www.springsource.com/training/free-online-training-developing-aspects-a
Key learning points:
- Introduction to AOP
- What problem does AOP solve
- The Spring AOP approach
- Defining pointcuts
- Implementing advice


OSGi and Modular Applications

http://www.springsource.com/training/freeonline/osgi
Key learning points:
  • Learn about the basics of OSGi and how it provides a modular, dynamic environment for your applications
  • Learn how Spring Dynamic Modules allows to you to apply the familiar Spring programming model to your OSGi-based applications
  • Learn how the SpringSource dm Server enables you to build Enterprise Java applications that can benefit from OSGi’s features on the server-side
  • Learn about OSGi and Spring-DM best practices
  • Learn about options and best practices for applying modularization to your own applications
  • Metaprogramming Techniques With Groovy
  • Metaprogramming Hooks
  • ExpandoMetaClass
  • Intercept, Cache and Invoke

Core Spring

http://www.springsource.com/training/class?classID=136220
Course Objectives covers
  • Use the Spring Framework to develop Java applications
  • Use dependency injection to set up and configure applications
  • Test Spring-based applications
  • Set up Spring configuration using XML, annotations, and Java configuration
  • Use Hibernate and JDBC with Spring to access relational databases
  • Use Spring support for transactions
  • Use aspect-oriented programming (AOP) to add behavior to objects
  • Develop a basic Web application with Spring MVC
  • Use Spring Security to secure Web applications
  • Use Spring with RMI, HttpInvoker, and JMS for remote communication
  • Add management with the JMX API

Enterprise Integration with Spring Training

http://www.springsource.com/training/class?classID=136215

You will learn:
  • How to design and implement asynchronous, event-driven, message-oriented systems with Spring JMS
  • How to use Spring Integration to implement Hohpe and Woolf's Enterprise Integration Patterns
  • How to cut through hype and understand 'buzzword' topics including SOA, ESB, and REST from first principles
  • How to design for concurrency using the latest from Spring and java.util.concurrent
  • How to optimize performance across integration boundaries
Rich Web Applications with Spring Training

http://www.springsource.com/training/class?classID=136217
You will learn:
  • Learn to create professional Ajax user interfaces with Spring JavaScript
  • Learn to design and implement stateful application transactions with Spring Web Flow 2
  • Learn to secure web applications effectively with Spring Security 2
  • Learn to get the most out of Ajax toolkits such as the Dojo Toolkit in your application
  • Learn to integrate JSF into your application with Spring Faces

I hope you will find these courses useful for your own study purpose and also to educate a person who is new to VMware virtualization. If you see any other courses which is not in the list above then please notify me or leave a feedback on the post and I will update the post.


For all the certification requirements and other necessary courses required for the ceritfications do visit the certification site http://mylearn.vmware.com/portals/certification/ and the training site http://mylearn.vmware.com/mgrreg/index.cfm?ui=www_edu&redirect=off.


Good luck and enjoy the ride of VMware Virtualization !!

Monday, June 11, 2012

VCDX Path - for both vSphere versions

Hi,

I was thinking to do this while back but could not get time to do it but today I just put some raw information in a form of Flow chart for both VCDX versions based on vSphere 4 and vSphere 5




This will help people determining and planning for their defenses at either SF or Barcelona.

Please watch this space with updates shortly.

Thanks for your time.

Saturday, May 26, 2012

Securing ESXi Host with Certificates - Obj 7.1 Part 1



I am covering here how to secure ESXi host. This include dealing with certificates (both default and CA assigned) and also some guidelines on what are the minimum steps you need to take to secure the VMware environment and make it a trusted one.


Generate New Certificates for ESXi

You typically generate new certificates only if you change the host name or accidentally delete the certificate. Under certain circumstances, you might be required to force the host to generate new certificates.

1          Log in to the ESXi Shell and acquire root privileges.

2          In the directory /etc/vmware/ssl, back up any existing certificates by renaming them
using the following commands.

        mv rui.crt orig.rui.crt
        mv rui.key orig.rui.key

Note:   If you are regenerating certificates because you have deleted them, this step is
unnecessary.

3          Run the command /sbin/generate-certificates to generate new certificates.

4          Restart the host after you install the new certificate.
Alternatively, you can put the host into maintenance mode, install the new certificate, and then use the Direct Console User Interface (DCUI) to restart the management agents.

5          Confirm that the host successfully generated new certificates by using the following command and comparing the time stamps of the new certificate files with orig.rui.crt and orig.rui.key.
           
        ls –la

Replace a Default Host Certificate with a CA-Signed Certificate

The ESXi host uses automatically generated certificates that are created as part of the installation process. These certificates are unique and make it possible to begin using the server, but they are not verifiable and they are not signed by a trusted, well-known certificate authority (CA).

Using default certificates might not comply with the security policy of your organization. If you require a certificate from a trusted certificate authority, you can replace the default certificate.

Note:   If the host has Verify Certificates enabled, replacing the default certificate might cause vCenter Server to stop managing the host. If the new certificate is not verifiable by vCenter Server, you must reconnect the host using the vSphere Client.

ESXi supports only X.509 certificates to encrypt session information sent over SSL connections between server and client components.

Note    For information about replacing default certificates on a vCenter Server system, see the vSphere Examples and Scenarios documentation.

Prerequisites

All file transfers and other communications occur over a secure HTTPS session. The user used to authenticate the session must have the privilege Host.Config.AdvancedConfig on the host. For more information on ESXi privileges, see About Users, Groups, Permissions, and Roles.

Procedure

1 Log in to the ESXi Shell and acquire root privileges.

2 In the directory /etc/vmware/ssl, rename the existing certificates using the following commands.

               mv rui.crt orig.rui.crt
               mv rui.key orig.rui.key


3 Copy the new certificate and key to /etc/vmware/ssl.

4 Rename the new certificate and key to rui.crt and rui.key.

5 Restart the host after you install the new certificate.

Alternatively, you can put the host into maintenance mode, install the new certificate, and then use the Direct Console User Interface (DCUI) to restart the management agents.

Encryption and Security Certificates for ESXi and vCenter Server

ESXi and vCenter Server support standard X.509 version 3 (X.509v3) certificates to encrypt session information sent over Secure Socket Layer (SSL) protocol connections between components. If SSL is enabled, data is private, protected, and cannot be modified in transit without detection.

All network traffic is encrypted as long as the following conditions are true:
              
You did not change the Web proxy service to allow unencrypted traffic for the port.

Your firewall is configured for medium or high security.

Certificate checking is enabled by default and SSL certificates are used to encrypt network traffic. However, ESXi and vCenter Server use automatically generated certificates that are created as part of the installation process and stored on the server system. These certificates are unique and make it possible to begin using the server, but they are not verifiable and are not signed by a trusted-well-known certificate authority (CA). These default certificates are vulnerable to possible man-in-the-middle attacks.

To receive the full benefit of certificate checking, particularly if you intend to use encrypted remote connections externally, install new certificates that are signed by a valid internal certificate authority or purchase a certificate from a trusted security authority. Replacing vCenter Server certificates is described in the vSphere Examples and Scenarios documentation.

Note:      If the self-signed certificate is used, clients receive a warning about the certificate. To address this issue, install a certificate that is signed by a recognized certificate authority. If CA-signed certificates are not installed, all communication between vCenter Server and vSphere Clients is encrypted using a self-signed certificate. These certificates do not provide the authentication security you might need in a production environment.

The certificate consists of two files: the certificate itself (rui.crt) and the private-key file (rui.key).
Default Location of ESXi and vCenter Server Certificate Files

Server                                                   Location____________________________________

ESXi 5.0                                               /etc/vmware/ssl/

vCenter Server (Windows 2008)           C:\Program Data\VMware\VMware VirtualCenter\SSL

vCenter Server (Windows 2003)           C:\Documents and Settings\All Users\Application
                                                             Data\VMware\VMware VirtualCenter\SSL


General Security Recommendations

To protect the host against unauthorized intrusion and misuse, VMware imposes constraints on several parameters, settings, and activities. You can loosen the constraints to meet your configuration needs, but if you do so, make sure that you are working in a trusted environment and have taken enough other security measures to protect the network as a whole and the devices connected to the host.

Consider the following recommendations when evaluating host security and administration.

             Limit user access.

To improve security, restrict user access to the management interface and enforce access security policies like setting up password restrictions.

The ESXi Shell has privileged access to certain parts of the host. Therefore, provide only trusted users with ESXi Shell login access.

Also, strive to run only the essential processes, services, and agents such as virus checkers, and virtual machine backups.

            Use the vSphere Client to administer your ESXi hosts.

Whenever possible, use the vSphere Client or a third-party network management tool to administer your ESXi hosts instead of working though the command-line interface as the root user. Using the vSphere Client lets you limit the accounts with access to the ESXi Shell, safely delegate responsibilities, and set up roles that prevent administrators and users from using capabilities they do not need.

             Use only VMware sources to upgrade ESXi components.

The host runs a variety of third-party packages to support management interfaces or tasks that you must perform. VMware does not support upgrading these packages from anything other than a VMware source. If you use a download or patch from another source, you might compromise management interface security or functions. Regularly check third-party vendor sites and the VMware knowledge base for security alerts.

               In addition to implementing the firewall, risks to the hosts are mitigated using other methods.

             ESXi runs only services essential to managing its functions, and the distribution is limited to the features required to run ESXi.

             By default, all ports not specifically required for management access to the host are closed. You must specifically open ports if you need additional services.

             By default, weak ciphers are disabled and all communications from clients are secured by SSL. The exact algorithms used for securing the channel depend on the SSL handshake. Default certificates created on ESXi use SHA-1 with RSA encryption as the signature algorithm.

             The Tomcat Web service, used internally by ESXi to support access by Web clients, has been modified to run only those functions required for administration and monitoring by a Web client. As a result, ESXi is not vulnerable to the Tomcat security issues reported in broader use.

             VMware monitors all security alerts that could affect ESXi security and, if needed, issues a security patch.

             Insecure services such as FTP and Telnet are not installed, and the ports for these services are closed by default. Because more secure services such as SSH and SFTP are easily available, always avoid using these insecure services in favor of their safer alternatives. If you must use insecure services and have implemented sufficient protection for the host, you must explicitly open ports to support them.

Cannot Configure vSphere HA When Using Custom SSL Certificates

After you install custom SSL certificates, attempts to enable vSphere High Availability (HA) fail.

Problem

When you attempt to enable vSphere HA on a host with custom SSL certificates installed, the following error message appears: vSphere HA cannot be configured on this host because its SSL thumbprint has not been verified.

Cause


Solution

1
In the vSphere Client, disconnect the host that has custom SSL certificates installed.
2
Reconnect the host to vCenter Server.
3
Accept the host's SSL certificate.
4
Enable vSphere HA on the host.

For more information on other security related issue, refer the online documentation and search the particular
topic.

There are other areas I could have covered here such as ESXi lock down mode,  authenticalion proxy, 
hardening virtual machines etc. etc. but it will be adding little complexity in the above subjects so may be 
later.