Quantcast
Channel: VMware Communities : Discussion List - All Communities
Viewing all 178097 articles
Browse latest View live

vCenter 6.7 / VMCA as a Subordinate CA / Incomplete certification path on ESXi 6.7 hosts; but ESXi 6.5 hosts work OK.

$
0
0

VCSA with Embedded PSC v6.7 (Build 9451876)

VMCA configured as Subordinate CA to a Windows 2012 R2 Enterprise Root CA. (SHA256 Hash / 2048 bit Key)

VMCA replaces the SSL certificate on a ESXi v6.5 (Build 5969303) host and the 'certification path' is complete. All works as expected, no browser errors.

VMCA replaces the SSL certificate on a ESXi v6.7 (Build 8169922) host and the 'certification path' is incomplete. Still get the standard browser errors. The root CA and VMCA certificates are NOT in the path, only the ESXi host certificate!

 

ESXi v6.5 Host - Complete Certification Path.
Good SSL Certificate- ESXi 6.5 Host.png

A dump of the SSL connection using the TestSSLServer utility (GitHub - pornin/TestSSLServer ) shown below.

 

Connection: mc-esxi-v-204.momusconsulting.com:443

SNI: mc-esxi-v-204.momusconsulting.com

  TLSv1.0:

     server selection: uses client preferences

     3-- (key:  RSA) RSA_WITH_AES_128_CBC_SHA

     3-- (key: RSA)  RSA_WITH_AES_256_CBC_SHA

     3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA

  TLSv1.1: idem

  TLSv1.2:

     server selection: enforce server preferences

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_GCM_SHA384

     3f- (key: RSA) ECDHE_RSA_WITH_AES_128_GCM_SHA256

     3-- (key: RSA)  RSA_WITH_AES_256_GCM_SHA384

     3-- (key: RSA)  RSA_WITH_AES_128_GCM_SHA256

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA384

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA

     3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA256

     3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA

     3-- (key: RSA)  RSA_WITH_AES_256_CBC_SHA256

     3-- (key: RSA)  RSA_WITH_AES_256_CBC_SHA

     3-- (key: RSA)  RSA_WITH_AES_128_CBC_SHA256

     3-- (key: RSA)  RSA_WITH_AES_128_CBC_SHA

=========================================

+++++ SSLv3/TLS: 1 certificate chain(s)

+++ chain: length=3

names match:        yes

includes root:      yes

signature hash(es): SHA-256

+ certificate order: 0

thumprint:  A18830247B90395EE003D706CE3AEB3CDA96BC6D

serial:     E032A1675443F48D

subject: EMAILADDRESS=admin@momusconsulting.com,CN=mc-esxi-v-204.momusconsulting.com,OU=Momus Labs,O=Momus Consulting,L=Basingstoke,ST=Basingstoke,C=GB

issuer:     CN=VMCA-mc-vcsa-v-204,OU=Momus Labs,O=Momus Consulting,L=Basingstoke,ST=Hampshire,C=GB

valid from: 2018-10-06 14:22:12 UTC

valid to:   2020-10-05 12:06:47 UTC

key type:   RSA

key size:   2048

sign hash:  SHA-256

server names:

   mc-esxi-v-204.momusconsulting.com

+ certificate order: 1

thumprint:  6313EF9061D1ED748298F0DB7D693F6CC2099046

serial:     5D0000000BA3C47E6295F579B400000000000B

subject:    CN=VMCA-mc-vcsa-v-204,OU=Momus Labs,O=Momus Consulting,L=Basingstoke,ST=Hampshire,C=GB

issuer:     CN=Momus Root CA on mc-addc-v-101,DC=momusconsulting,DC=com

valid from: 2018-10-06 12:06:47 UTC

valid to:   2020-10-05 12:06:47 UTC

key type:   RSA

key size:   2048

sign hash:  SHA-256

+ certificate order: 2

thumprint:  A3BD98D6B6C712A510E11669A84D0571C2D2F0F1

serial:     65F1DEEF09DD1A9A436075662D731F0F

subject:    CN=Momus Root CA on mc-addc-v-101,DC=momusconsulting,DC=com

issuer:     CN=Momus Root CA on mc-addc-v-101,DC=momusconsulting,DC=com

valid from: 2018-10-05 15:11:29 UTC

valid to:   2028-10-05 15:21:28 UTC

key type:   RSA

key size:   2048

sign hash:  SHA-256

(self-issued)

=========================================

Server compression support: no

Server sends a random system time.

Secure renegotiation support: yes

Encrypt-then-MAC support (RFC 7366): no

SSLv2 ClientHello format (for SSLv3+): yes

Minimum EC size (no extension):   256

Minimum EC size (with extension): 256

ECDH parameter reuse:  no

Supported curves (size and name) ('*' = selected by server):

  * 256 secp256r1 (P-256)

=========================================

  WARN[CS006]: Server supports cipher suites with no forward secrecy.

 

 

ESXi v6.7 Host - Incomplete Certification Path.
Bad SSL Certificate - ESXi 6.7 Host.png

Again, a dump of the SSL connection is shown below.

 

Connection: mc-esxi-v-205.momusconsulting.com:443

SNI: mc-esxi-v-205.momusconsulting.com

  TLSv1.2:

     server selection: enforce server preferences

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_GCM_SHA384

     3f- (key: RSA) ECDHE_RSA_WITH_AES_128_GCM_SHA256

     3-- (key: RSA)  RSA_WITH_AES_256_GCM_SHA384

     3-- (key: RSA)  RSA_WITH_AES_128_GCM_SHA256

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA384

     3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA

     3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA256

     3f- (key: RSA)  ECDHE_RSA_WITH_AES_128_CBC_SHA

     3-- (key: RSA)  RSA_WITH_AES_256_CBC_SHA256

     3-- (key: RSA)  RSA_WITH_AES_256_CBC_SHA

     3-- (key: RSA)  RSA_WITH_AES_128_CBC_SHA256

     3-- (key: RSA)  RSA_WITH_AES_128_CBC_SHA

=========================================

+++++ SSLv3/TLS: 1 certificate chain(s)

+++ chain: length=1

names match:        yes

includes root:      no

signature hash(es): SHA-256

+ certificate order: 0

thumprint:  9CB7BEC3BD58491A36069B182093F22BE9813042

serial:     FD682ECC9662D00C

subject: EMAILADDRESS=admin@momusconsulting.com,CN=mc-esxi-v-205.momusconsulting.com,OU=Momus Labs,O=Momus Consulting,L=Basingstoke,ST=Basingstoke,C=GB

issuer:     CN=VMCA-mc-vcsa-v-204,OU=Momus Labs,O=Momus Consulting,L=Basingstoke,ST=Hampshire,C=GB

valid from: 2018-10-06 14:44:04 UTC

valid to:   2020-10-05 12:06:47 UTC

key type:   RSA

key size:   2048

sign hash:  SHA-256

server names:

   mc-esxi-v-205.momusconsulting.com

=========================================

Server compression support: no

Server sends a random system time.

Secure renegotiation support: yes

Encrypt-then-MAC support (RFC 7366): no

SSLv2 ClientHello format (for SSLv3+): yes

Minimum EC size (no extension):   256

Minimum EC size (with extension): 256

ECDH parameter reuse:  no

Supported curves (size and name) ('*' = selected by server):

  * 256 secp256r1 (P-256)

=========================================

  WARN[CS006]: Server supports cipher suites with no forward secrecy.

 

Any ideas?

 

Thanks

M


VCSA log full issue

$
0
0

We are using ESXI 6.0 with VCSA installed. Almost every three month, we unable to startup vcenter services due to the disk space full especially on this file /var/log/audit/audit.log. Normally I have to manually SSH to the server and delete this file before the disk full but I am unable to predict when the file is going to fully occupied the disk.

 

1. Is there a way to prevent this file from growing or fully occupied the disk space like retention policy?

2. Will upgrade to 6.5/6.7 prevent this kind of issue happen again?

3. Will increasing the hdd space able to solve this issue?

 

Thanks

Fusionで”Boot Camp.vmdkを開くことができません”と出て来ます。対処方法を知りたいです。

$
0
0

Fusion 11 で下記の様なメッセージが出て使用できません。

元々Fusion 8で出ていて 11にUPすると改善するするかと思ったのですが

状況は変わっていません。

 

対応方法等をご存知の方が

いれば教えて下さい。

 

--出力メッセージ---

ファイル「/Users/ユーザ名/Library/Application Support/VMware Fusion/Virtual Machines/Boot Camp/Boot Camp.vmwarevm/Boot Camp.vmdk」を開くことができません:

--

 

現在の使用Mac環境

macOS High Sierra

 

--

Boot Camp.vmdk

壊れたのか?

消えたのか?

思って見たのですが

存在は確認して

タイムスタンプは2014年の日付けでした。

中は未確認。

--

Windows Failover Cluster Manager

$
0
0

hi,

 

Can you use windows failover cluster manager with esxi hosts. If I connect my 8 Esxi hosts to the "AD DC" then try add them to the windows failover cluster manager does it work?

is there any particular configuration that needs to be set up. Im guessing the user accounts need to be all exactly the same.

 

 

matt

Remove VMs from load balancer pools workflow does not give the expected result

$
0
0

Hello,

 

I am using the vRo plugin for NSX and I managed to use successfully, the workflow "Add VMs to existing load balancer pools" but the workflow "Add VMs to existing load balancer pools" does not seem to work. I don't know what to put as format for the following inputs : "poolid" and "poolmembers".

I tried pultiple formats, each time the workflow ends successfullty but the members are still there in the pool.

The workflow does not have debug logs and the function used in the workflow do not return any output. So it is hard to troubleshoot this.

The documentation of the plugin does not state the format either : Remove VMs and Load Balancer Pools

I am using the following products versions :

vRO : 7.3.1

NSX : 6.4.0

NSX plugin : 1.1

 

Any help on how to solve or troubleshoot this would be appreciated.

Thanks.

The system cannot find the file specified. VMware `12.5

$
0
0

Hello team,

 

I'm having issues opening a vm in my vmware workstation  12.5.  When try to open a vritual machine that I backed up, I get the following error message:

 

Unable to open file "C:\Users\mrf\Google Drive\oscp\vm\OffsecVM-2017.2-20171023\OffsecVM-2017.2-hdd-000011.vmdk":

 

The system cannot find the file specified.

 

Then when I try to open a different Virtual Disk from the following:

 

 

 

I get the error message:

 

I can't open any disks in this virtual machine nor can I revert snapshots.

 

When I try to revert it, I get the following message:

 

 

 

The issue started happening after I moved the folder to a different location. I know that I copied everything from the old folder to the new destination. Now, I'm trying to open it from the new location, I get the above messages.

 

It looks like I'm missing vmdk files, but should I be able to use those snapshots to revert the machines ?

 

I have been having this issue for over a month and its been really fursttrating trying to fix it. I did a lot of research online but can't seem to figure it out.

 

P.S.  for some magic reason this worked today for 15 minutes. I powered on the machine and it worked. Then, while I was shocked and trying to backup the machine, the machine crashed and got the following:

 

 

 

 

I can see the disks are very large and I feel like the data is there. total size 85GB. 'm hoping that I didnt lose the vm.

 

 

 

I have attached the log file.

 

 

Any help would be appreciated

.vmdk file issue

$
0
0

Can I ask you for your help with VMware Fusion vmdk file issue. I can't start the virtual machine

Unable to open file "/Volumes/OLD/Windows 7En/Windows 7.vmdk":

The system cannot find the file specified

but Windows 7.vmdk file is exist in this folder

 

I think I need to recreate this file , but how

 

Снимок экрана 2018-10-27 в 19.23.00.png

 

Снимок экрана 2018-10-27 в 19.23.25.png

Identity sources and SSO

$
0
0

Hi

How many domain can use as identity sources for SSO ?


vSphere DRS & vMotion

$
0
0

Hi,

 

I cant seem to find anything detailing these two features?

 

1) vSphere DRS

2) vMotion

 

can you use them together in a cluster, what's the difference with vMotion to "HA" ive tried to set up HA but it never seems to work and connect to the master host I end up with 10s of errors about storage and networking cards and all sorts. so ended up just using DRS and vMotion.

 

 

Matt

Update Manager completely gone after updating vCenter 6.7 to 6.7-update01

$
0
0

All,

 

Weird thing happening.

 

I do an upgrade from 6.7 and all seems well, except the fact that there is no trace of the Update Manager tool after vCenter restarts.

 

In an attempt to solve this I did:

  • Re-register the Update Manager with  /usr/lib/vmware-updatemgr/bin/updatemgr-utility.py register_vc
  • Resetting the database using /usr/lib/vmware-updatemgr/bin/updatemgr-utility.py reset-db and cleaning out the patchstore folder
  • Restarted vCenter

 

None of it helps. Rolling back, Update Manager re-appears without an issue and works fine.

 

So, after investigating a little more, I discovered one weird thing. After rolling back to 6.7.0-9433931 and checking that everything works fine, I go to the VCSA using SSH.

After I stage update 1 ISO using the VCSA console and run software-packages list --staged, this is the output I get:

 

VMware vCenter Server Appliance 6.7.0.14000

Type: vCenter Server with an embedded Platform Services Controller

Last login: Sat Oct 27 16:44:21 2018 from 10.x.y.z
Connected to service

    * List APIs: "help api list"
    * List Plugins: "help pi list"
    * Launch BASH: "shell"

Command> software-packages stage --iso --acceptEulas
[2018-10-27T17:12:40.300] : ISO mounted successfully
[2018-10-27T17:12:41.300] : Evaluating packages to stage...
[2018-10-27T17:12:41.300] : Verifying staging area
[2018-10-27T17:12:41.300] : ISO unmounted successfully
[2018-10-27T17:12:41.300] : Staging process completed successfully
Command>
Command>
Command> software-packages list --staged
[2018-10-27T17:12:54.300] :
        leaf_services: ['vmware-pod']
        thirdPartyInstallation: False
        rebootrequired: True
        buildnumber: 10244745
        productname: VMware vCenter Server Appliance
        summary: Update for VMware vCenter Server Appliance 6.7.0
        version_supported: ['6.7.0.10000', '6.7.0.11000', '6.7.0.12000']
        updateversion: True
        name: VC-6.7.0U1-Appliance-FP
        severity: Critical
        TPP_ISO: False
        category: Bugfix
        eulaAcceptTime: 2018-10-27 17:12:41 CEST
        kb: https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-671-release-notes.html#full_patch
        releasedate: October 16, 2018
        vendor: VMware, Inc.
        version: 6.7.0.20000
        size in MB: 1829
        tags: []
Command>

 

So, it seems this update is not supported on my version, although upgrading itself works without any issue other than Update Manager.

 

I haven't been able to find any article on this issue anywhere just yet, so any help in this regards is very much appreciated.

Open-VMConsoleWindow Authorize Exception

$
0
0

Just noticed that Open-VMConsoleWindow no longer works ? Or did something change that I'm not aware of ? I can run VMRC from vSphere Web Client; also from PowerShell using this approach.

 

PS C:\PowerCLI\_> get-vm xxxx | Open-VMConsoleWindow

Open-VMConsoleWindow : A general system error occurred: Authorize Exception

In Zeile:1 Zeichen:23

+ get-vm xxxx | Open-VMConsoleWindow

+               ~~~~~~~~~~~~~~~~~~~~

    + CategoryInfo          : NotSpecified: (:) [Open-VMConsoleWindow], VimException

    + FullyQualifiedErrorId : VMware.Vim.VimException,VMware.VimAutomation.ViCore.Cmdlets.Commands.OpenVMConsoleWindow

 

Some info:

Windows 10 1803

 

PS C:\PowerCLI\_> $PSVersionTable.PSVersion

 

Major  Minor  Build  Revision

-----  -----  -----  --------

5      1      17134  228

 

PS C:\PowerCLI\_> Get-PowerCLIModules

 

Name                                Version

----                                -------

VMware.DeployAutomation             6.7.0.8250345

VMware.ImageBuilder                 6.7.0.8250345

VMware.PowerCLI                     11.0.0.10380590

VMware.Vim                          6.7.0.10334489

VMware.VimAutomation.Cis.Core       11.0.0.10335701

VMware.VimAutomation.Cloud          11.0.0.10379994

VMware.VimAutomation.Common         11.0.0.10334497

VMware.VimAutomation.Core           11.0.0.10336080

VMware.VimAutomation.HA             6.5.4.7567193

VMware.VimAutomation.HorizonView    7.6.0.10230451

VMware.VimAutomation.License        10.0.0.7893904

VMware.VimAutomation.Nsxt           11.0.0.10364044

VMware.VimAutomation.PCloud         10.0.0.7893924

VMware.VimAutomation.Sdk            11.0.0.10334495

VMware.VimAutomation.Security       11.0.0.10380515

VMware.VimAutomation.Srm            10.0.0.7893900

VMware.VimAutomation.Storage        11.0.0.10380343

VMware.VimAutomation.StorageUtility 1.3.0.0

VMware.VimAutomation.Vds            11.0.0.10336077

VMware.VimAutomation.Vmc            11.0.0.10336076

VMware.VimAutomation.vROps          10.0.0.7893921

VMware.VumAutomation                6.5.1.7862888

vmware horizon html access prohibit send ctrl alt delete

$
0
0

Hi!

Is there a way to disable CAD on sidebar when only using HTML access for publishing RDS apps? Only confusing to the users ending up on the RDS server when pressing CAD button.

Fusion 11 upgrade turned Webcam from high flying into molasses ....

$
0
0

WTF! Ouch!

 

So I upgrade on Mojavie to Fusion 11 ... of course the web cam won't even work. So I have to delete them, then I add them and round and round we go (I did do a tools update) until it got going. That happened to be in Fusion 10. However now that it is going, its is so slow while the Mac one is perfect. On my other Mac, Fusion 10, it's perfect. I'm running Ubuntu 16 ... anyone have ideas how I fix it?

email alerts on alternate port

$
0
0

Hi

 

VCSA 6.7

 

I am trying to send email alerts on an alternate port with user authentication... not tls.  It is supported on this smtp server and nothing is blocking... on our network (I use the same settings server from my HP printer to send scanned documents)

 

mail smtp server is set correctly as is the sender address

 

under advanced settings port, sender user email and password are all set.

 

restarted all services, set an alert for power on of a specific VM, alert it is triggered but I never get an email.

 

I must admin I am not up to speed on vcsa log files... is there a log file I can check for more information, and can anyone else confirm if using an alternate port works for them

 

Thanks

Bill

Network Settings greyed out - everything else ok

$
0
0

I have done a upgrade to 10.10 and Fusion 7

 

Everything has been fine, and I created a new custom vmnet, and some VMS - almost had everything working.

 

During the third VM that I made, I realised I needed to change the network so it was in the same vmnet.

Anyway, in the settings for the network its all greyed out - but all other settings for the VM are fine.

 

I figured it was a problem just for this VM, but no, all the VMs have the sam issue!

 

Also when I go to the Fusion preferences, and go to the network tab - all this is greyed out too. The other tabs are ok.

 

It seems as though just the networking element of fusion is broken - all VMs work fine - I just can change VM settings, or add new VMs due to the same issue.

 

Any ideas?

 

Ive tried stopping and starting the services... no luck

the log did reflect that vmnet-bridge is already running.

 

I also wonder if it has anything to do with Cisco Any Connect client that I have - this has carried over from the update from 10.9 to 10.10 - and when I connected to the VPN there was an auto update - though this may not be related at all.

 

Any ideas?

TIA


vmware horizon html access edge browser error

$
0
0

We have published RDS apps on Horizon 7.5.1, and any browser except Edge works. Launching an app on side bar just ends up in a grey page. Using UAG in front. First we encountered problem with Edge on logon page, the credentials parts had the spinning circle. Found out that we needed checkOrigin=false on conn servers. After that we succeded in logging on but now we ends up with a grey page, and this is only on Edge. Any ideas?

Saving PC programs when buying new macbook

$
0
0

I have a number of PC/microsofts programs downloaded but with no installation discs. How do I move those over to a new MacBook?

Failed to activate VSAN on VMkernel

$
0
0

Hi all

 

I'm setting up vSAN in my own lab. I have 2 servers: 1 HP DL380 G7 and one G6. (I know that maybe not all components are on the HCL) but:

 

I was able to activate vSAN Traffic on vmk1 on the G7 server but if I enable it on the G6 server I only get a general system error during the refresh of the vsan configuration. I'm looking at vmkernel log and some vSAN logs, but I didn't get it out what's the problem.

 

ESXi Version is 6.5.

 

If someone has any ideas, let me know.

 

Thank you

 

Update 1:
I'm able to activate all other services like vMotion, management, FT, etc. only vSAN fails.

 

Update 2:

Error Message:

 

Task: Update Vsan

Target: ha-host

Initiator: VC Internal

Result:

Key: haTask--vim.host.VsanSystem.update-158810592

Description: Updates the Virtual SAN configuration for this host

State: Failed  - A general system error occurred:

Централизованное управление нескольими vcentr

$
0
0

Господа, подскажите

Есть 4 vCenter 6.0

есть ли возможность объединить их в один SSO, для единого управления?

что-то нигде не могу найти информацию как это организовать.

p.s. просто подключить все хоты к одно сфере не вариант так как физически инфраструктуры разные и находятся даже в разных городах 

Как увидеть в реальной сеть виртуальную машину

$
0
0

Здравствуйте!

 

Подскажите как настроить vmware так чтобы виртуальную машину можно было видеть в реальной сети?

Viewing all 178097 articles
Browse latest View live


Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>