Install VCSA 6.7

How to Install VCSA 6.7 (VMware vCenter Server Appliance)

In this article I will show you how to install VCSA 6.7 (VMware vCenter Server Appliance).

To start, you need an installation kit of vCenter Server Appliance 6.7. For this article, I will use the VCSA 6.7 Update 1 version – VMware-VCSA-all-6.7.0-10244745.iso (the latest available at the time I wrote this article).

Note: If you look for VCSA upgrade instructions, check this article: How to Upgrade vCenter Server Appliance from 6.5 to 6.7 – Stage 1.

Install VCSA 6.7 (VMware vCenter Server Appliance) – Stage 1

To launch the installer I will use a Windows virtual machine (alternatively you can use a Mac or a Linux system). Unzip the archive and navigate to VMware-VCSA-all-6.7.0-10244745\vcsa-ui-installer\win32 folder. Launch installer.exe and begin to install VCSA 6.7.

Install VCSA 6.7 - installer.exe

Read More

VMUG Romania October Meeting Report

Better late than never, so here it is the report for VMUG Romania latest meeting. On 16th October, 35 guests attended the last VMUG Romania meeting of the year. We held our meeting in the beautiful offices of our sponsor, Veeam. This meeting we added a new feature to our meeting: at the request of few remote colleagues, we streamed live on Facebook almost all the presentations. This allowed me to embed the videos into this article, so double win! We received cool feedback, so for next sessions we will have some sort of live streaming for sure.

I had the honor to present in the first slot of the meeting. As this year is the first year when Romania has not only one, but 2 vExperts, I thought this is a good opportunity to spread the word about vExpert program into the community. I talked about vExpert program, about the benefits of joining it and I showed the audience my path to vExpert. You can watch below my presentation in Romanian.

Read More

VCP6.5-DCV Delta Exam

VCP6.5-DCV Delta Exam Experience

Not so long ago I started to receive reminders from VMware Training Services about the expiration of my VCP6-DCV certification. With so many changes around, I patiently waited for the last reminder, one month to go. Read on for my journey with  VCP6.5-DCV Delta exam.

You generally have 3 ways to renew your certification:

  • Upgrade to VCAP
  • Update with the latest VCP exam (VCP6.5-DCV in my case)
  • Certify in a different technology track (for example VCP7-CMA)

Read More

VMSA-2018-0024

VMSA-2018-0024 – AirWatch Console Vulnerability

VMware has released a new security advisory VMSA-2018-0024: VMware Workspace ONE Unified Endpoint Management Console (AirWatch Console) update resolves SAML authentication bypass vulnerability.

This advisory documents the remediation of one critical issue: VMware Workspace ONE Unified Endpoint Management Console (AirWatch Console) contains a SAML authentication bypass vulnerability which can be leveraged during device enrollment. This vulnerability may allow for a malicious actor to impersonate an authorized SAML session if certificate-based authentication is enabled. If certificate-based authentication is not enabled the outcome of exploitation is limited to an information disclosure (Important Severity).

The Common Vulnerabilities and Exposures project has assigned the identifier CVE-2018-6979 to VMSA-2018-0019 issue.

VMSA-2018-0024 – Affected Products and Resolutions

AirWatch Console 9.7.x – update to version 9.7.0.3 or above
AirWatch Console 9.6.x – update to version 9.6.0.7 or above
AirWatch Console 9.5.x – update to version 9.5.0.16 or above
AirWatch Console 9.4.x – update to version 9.4.0.22 or above
AirWatch Console 9.3.x – update to version 9.3.0.25 or above
AirWatch Console 9.2.x – update to version 9.2.3.27 or above
AirWatch Console 9.1.x – update to version 9.1.5.6 or above

As per VMware KB, if patching your environment is not feasible in a timely manner, you can take mitigation steps by disabling SAML authentication for enrollment located under System > Enterprise Integration > Directory Services.

You can check reports on other VMware vulnerabilities in my page dedicated to Security Advisories.

VMUG Romania

VMUG Romania October Meeting

At VMUG Romania we have a busy October: on 2nd October we take part to VMware vForum Romania with a presentation booth, then on 16th October we will host our autumn meeting in a new venue, AFI Park 5, Bucharest.

If you don’t know what you can expect from such a meeting, you can read my report for the February VMUG meeting.

Agenda

Cornel Popescu  (Veeam) – Improve data protection with Veeam CDP for vSphere and Availability Orchestrator
Community session – Victor Homocea – vSAN in real life
Community session – Constatin Ghioc – All about vExpert
Community session – Razvan Ionescu – PowerCLI and bulding custom vSphere images
Cristian Radu (VMware) – VMware, what’s new

In the end we will host a raffle, be sure to be there to claim your prize 🙂

Location

AFI Park 5, 9th Floor
Veeam Software, Timisoara Avenue 4A
Bucharest, Romania, 061344

Participation is free. Registration is mandatory.

VMUG Romania meeting from 16 October 2018 is sponsored by Veeam.

VMware vForum Romania 2018

VMware vForum Romania 2018

VMware announced 2018 edition of their 1 full-day conference in Romania, vForum. On 2nd October, Crown Plaza Hotel from Bucharest will host the biggest annual event of VMware Romania.

“VMware vFORUM 2018 is a full day of innovation to accelerate your digital transformation through a software-defined approach to business and IT. We show you how you can improve business agility by modernizing data centers and integrating public clouds, and create exceptional experiences by empowering a secure digital workspace. Get ready for industry-leading insights, keynotes, breakout sessions and customer case studies on the trends that matter most to your business and to IT.” – VMware vForum official site

This year the event has a long list of sponsors: Dell, Fortinet, HPE, Veeam, AWS, Check Point, Eta-2U, Kapsch, Novatech, and TechData.

Read More

VMSA-2018-0003

VMSA-2018-0019 – VMware Horizon Vulnerability

VMware has released a new security advisory VMSA-2018-0019: Horizon 6, 7, and Horizon Client for Windows updates address an out-of-bounds read vulnerability.

This advisory documents the remediation of one important issue: Horizon 6, 7, and Horizon Client for Windows contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client are installed.

The vulnerability doesn’t apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.

The Common Vulnerabilities and Exposures project has assigned the identifier CVE-2018-6970 to VMSA-2018-0019 issue.

VMSA-2018-0019 – Affected Products and Resolutions

Horizon version 7.x running on Windows – update to version 7.5.1 (release date 19 July 2018, for more details check the Release Notes)

Horizon version 6.x running on Windows – update to version 6.2.7 (release date 7 August 2018, for more details check the Release Notes)

Horizon Client for Windows version 4.x and earlier – update to version 4.8.1 (release date 7 August 2018, for more details check the Release Notes)

The vulnerability doesn’t apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.

You can check reports on other VMware vulnerabilities in my page dedicated to Security Advisories.

How to Upgrade vCenter Server Appliance from 6.5 to 6.7

How to Upgrade vCenter Server Appliance from 6.5 to 6.7 – Stage 2

In a previous article (How to Upgrade vCenter Server Appliance from 6.5 to 6.7 – Stage 1) I walked through the first phase of the upgrade process for vCSA 6.7 (embedded deployment) – Deploy the OVA File of the new vCenter Server Appliance with an embedded Platform Services Controller. In this article I will cover phase 2 of the vCenter upgrade – transfer the data and setup the newly deployed vCenter Server Appliance.

Upgrade vCenter Server Appliance from 6.5 to 6.7 – Stage 2

In the last step of the phase 1, I was presented with the following screen:

Upgrade vCenter Server Appliance from 6.5 to 6.7 - Deploy VCSA Completed

Read More

How to Upgrade vCenter Server Appliance from 6.5 to 6.7

How to Upgrade vCenter Server Appliance from 6.5 to 6.7 – Stage 1

In this article I will show you how to upgrade vCenter Server Appliance running 6.5 to the target version of 6.7. I will upgrade an embedded deployment (as per vCenter Server and Platform Services Controller Deployment Types: all services bundled with the Platform Services Controller are deployed together with the vCenter Server services on the same virtual machine or physical server).

The upgrade procedure consists in two steps:

  1. Stage 1 – Deploy the OVA File of the new vCenter Server Appliance with an embedded Platform Services Controller
  2. Stage 2 – transfer the data and setup the newly deployed vCenter Server Appliance

In this article I will cover Stage 1 (deployment of a new vCSA 6.7). In a later article I will cover Stage 2 (data migration from the old 6.5 vCSA to the new 6.7 vCSA).

Read More

VMSA-2018-0003

VMSA-2018-0014 – VMware Horizon Client Privilege Escalation Vulnerability

VMware has released a new security advisory: : VMware Horizon Client update addresses a privilege escalation vulnerability.

This advisory documents the remediation of one important issue: VMware Horizon Client contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.

The Common Vulnerabilities and Exposures project has assigned the identifier CVE-2018-6964 to VMSA-2018-0014 issue.

All 4.x and prior versions of Horizon Client are affected by this vulnerability. VMware recommends update to version 4.8.0 (released 29 May 2018).

Read More