jueves, 25 de septiembre de 2014

VMware: Administración de Usuarios, Grupos y Roles en vSphere 5.5

Since Single Sign-On was completely rebuilt from the ground up in vSphere 5.5  I was in a bit of a struggle while configuring roles and permissions for users accessing VMware vCenter.


With Single Sign-On (from here simply referred as SSO) redesign in vSphere 5.5 VMware introduced a new common domain named vsphere.local.
Users authentication is now managed by SSO server and not by vCenter itself. This is because VMware is looking to provide a common authentication platform across all its services. SSO now lets users authenticate into vCenter, vCD and vCO. New products, like vCOps, will probably authenticate users against SSO in their future releases.

So, here's how to create users, groups and manage permissions in vSphere 5.5.

First login to vSphere 5.5 Web Client which, by default, is accessible from this URL:

https://<your_vCenter_Server_IP_or_FQDN>:9443/vsphere-client


Login into vCenter with following credentials:

User: Administrator@vsphere.local
Password: vmware


NOTE: This is the default password for VMware vCenter Server Appliance. If you deployed vCenter as standalone installation you were prompted to choose for a password during installation process.


Go to Roles -> Single Sign-On -> Users and Groups. Click the green New User button to add new users.


Ensure that vsphere.local is set in Domain picker. This is because our users will not be local users but will be authenticated against SSO server.

Now let's create a Group. Move to Groups tab and click New Group button.


Then to add user(s) to this group select the newly created group, click Add Member icon, select user(s), click Add, then Ok.


Finally we need to assign our user(s) or group(s) permissions within our specific product. In this case we assign permissions within vCenter. Permissions are assigned product-wide and not domain-wide this is because a certain user or group could for example retain administrative permissions in vCenter and read-only permissions in vCD.

Go to your vCenter, click Manage -> Permission tab, add button


Click Add, select VSPHERE.LOCAL in Domain picker, choose your group, or user if want to grant permission only to single user and not to entire group, then click Add -> Ok.


Select role for user/group then click Ok.


You can now login with new user's credentials to verify correct permission grant.


Since in this example TestUser is member of TestGroup which has Read-Only permission assigned we can access vCenter and its object but cannot manage/interact with them as expected.


Permissions can be customized to properly fit your specifications. This can be done by accessing Roles -> Access Control -> Roles.

There are two different groups of roles: system roles, which cannot be modified, and sample rolesthat can be edited.

If you need to create a custom role best practices suggest you to clone an existing one and edit the cloned one.

That's all!!

Fuente: 
http://hostilecoding.blogspot.com/2013/11/vmware-users-groups-and-roles.html
http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-72BFF98C-C530-4C50-BF31-B5779D2A4BBB.html

jueves, 18 de septiembre de 2014

Windows 2000 en VmWare vSphere con VmWare tools

Para instalar un windows 2000 en VmWare vSphere hay que primero descargar el paquete e instalarlo:
http://www.microsoft.com/en-us/download/details.aspx?id=20806

Debido a que si no esta instalado no se podra instalar vmware tools.
http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2007120

Para instalar vmware tools hay que seguir los siguientes pasos:

Procedure
  1. Select the menu command to mount the VMware Tools virtual disc on the guest operating system.

    vSphere Client – Inventory > Virtual Machine > Guest > Install/Upgrade VMware ToolsvSphere Web Client – All Actions icon > Configuration > Install/Upgrade VMware Tools
  2. If you are using vCenter Server and are performing an upgrade or reinstallation, in the Install/Upgrade VMware Tools dialog, selectInteractive Tools Installation or Interactive Tools Upgrade and click OK.

    The process starts by mounting the VMware Tools virtual disc on the guest operating system.
  3. If you are installing VMware Tools for the first time, click OK in the Install VMware Tools information screen.

    If autorun is enabled for the CD-ROM drive in the guest operating system, the VMware Tools installation wizard appears.
  4. If autorun is not enabled, to manually launch the wizard, click Start > Run,type D:\setup.exe, where D: is your first virtual CD-ROM drive, and click OK.
  5. Follow the on-screen instructions. To install nondefault components, select the Custom setup.
  6. If the New Hardware wizard appears, go through the wizard and accept the defaults.
  7. When prompted, reboot the virtual machine.
After the installation completes, the VMware Tools label on the Summary tab in vCenter Server changes to OK.

Prerequisites
  • Power on the virtual machine.
  • Verify that the guest operating system is running.
  • For vSphere virtual machines, to determine whether you have the latest version of VMware Tools, in the vSphere Client inventory, select the virtual machine and click the Summary tab.
  • If the guest operating system is a Windows NT, Windows 2000, Windows XP, Windows Server 2003, Windows Vista, or Windows 7 operating system, log in as an administrator. Any user can install VMware Tools in a Windows 95, Windows 98, or Windows Me guest operating system.

Fuente:
http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2007120
http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2004754

martes, 26 de agosto de 2014

Install Apache2, PHP5 And MySQL Support On CentOS 6.5 (LAMP)

Version 1.0
Authors: Till Brehm <t [dot] brehm [at] howtoforge [dot] com>, Falko Timme <ft [at] falkotimme [dot] com>
 Follow Howtoforge on Twitter
Last edited 04/03/2014
There is a new version of this tutorial available for CentOS 7.
LAMP is short for Linux, Apache, MySQL, PHP. This tutorial shows how you can install an Apache2 webserver on a CentOS 6.4 server with PHP5 support (mod_php) and MySQL support.
I do not issue any guarantee that this will work for you!

1 Preliminary Note

In this tutorial I use the hostname server1.example.com with the IP address 192.168.0.100. These settings might differ for you, so you have to replace them where appropriate.

2 Installing MySQL 5

To install MySQL, we do this:
yum -y install mysql mysql-server
Then we create the system startup links for MySQL (so that MySQL starts automatically whenever the system boots) and start the MySQL server:
chkconfig --levels 235 mysqld on
/etc/init.d/mysqld start
Set passwords for the MySQL root account:
mysql_secure_installation
[root@server1 ~]# mysql_secure_installation
NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MySQL
SERVERS IN PRODUCTION USE! PLEASE READ EACH STEP CAREFULLY!
In order to log into MySQL to secure it, we'll need the current
password for the root user. If you've just installed MySQL, and
you haven't set the root password yet, the password will be blank,
so you should just press enter here.
Enter current password for root (enter for none):
OK, successfully used password, moving on...
Setting the root password ensures that nobody can log into the MySQL
root user without the proper authorisation.
Set root password? [Y/n] <-- ENTER
New password: <-- yourrootsqlpassword
Re-enter new password: <-- yourrootsqlpassword
Password updated successfully!
Reloading privilege tables..
... Success!
By default, a MySQL installation has an anonymous user, allowing anyone
to log into MySQL without having to have a user account created for
them. This is intended only for testing, and to make the installation
go a bit smoother. You should remove them before moving into a
production environment.
Remove anonymous users? [Y/n] <-- ENTER
... Success!
Normally, root should only be allowed to connect from 'localhost'. This
ensures that someone cannot guess at the root password from the network.
Disallow root login remotely? [Y/n] <-- ENTER
... Success!
By default, MySQL comes with a database named 'test' that anyone can
access. This is also intended only for testing, and should be removed
before moving into a production environment.
Remove test database and access to it? [Y/n] <-- ENTER
- Dropping test database...
... Success!
- Removing privileges on test database...
... Success!
Reloading the privilege tables will ensure that all changes made so far
will take effect immediately.
Reload privilege tables now? [Y/n] <-- ENTER
... Success!
Cleaning up...

All done! If you've completed all of the above steps, your MySQL
installation should now be secure.
Thanks for using MySQL!

3 Installing Apache2

Apache2 is available as a CentOS package, therefore we can install it like this:
yum -y install httpd
Now configure your system to start Apache at boot time...
chkconfig --levels 235 httpd on
... and start Apache:
/etc/init.d/httpd start
Now direct your browser to http://192.168.0.100, and you should see the Apache2 placeholder page:
Click to enlarge
Apache's default document root is /var/www/html on CentOS, and the configuration file is /etc/httpd/conf/httpd.conf. Additional configurations are stored in the /etc/httpd/conf.d/ directory.

4 Installing PHP5

We can install PHP5 and the Apache PHP5 module as follows:
yum -y install php
We must restart Apache afterwards:
/etc/init.d/httpd restart

5 Testing PHP5 / Getting Details About Your PHP5 Installation

The document root of the default web site is /var/www/html. We will now create a small PHP file (info.php) in that directory and call it in a browser. The file will display lots of useful details about our PHP installation, such as the installed PHP version.
vi /var/www/html/info.php
<?php
phpinfo();
?>
Now we call that file in a browser (e.g. http://192.168.0.100/info.php):
Click to enlarge
As you see, PHP5 is working, and it's working through the Apache 2.0 Handler, as shown in the Server API line. If you scroll further down, you will see all modules that are already enabled in PHP5. MySQL is not listed there which means we don't have MySQL support in PHP5 yet.

6 Getting MySQL Support In PHP5

To get MySQL support in PHP, we can install the php-mysql package. It's a good idea to install some other PHP5 modules as well as you might need them for your applications. You can search for available PHP5 modules like this:
yum search php
Pick the ones you need and install them like this:
yum -y install php-mysql
In the next step I will install some common PHP modules that are required by CMS Systems like Wordpress, Joomla and Drupal:
yum -y install php-gd php-imap php-ldap php-odbc php-pear php-xml php-xmlrpc php-mbstring php-mcrypt php-mssql php-snmp php-soap php-tidy curl curl-devel
APC is a free and open PHP opcode cacher for caching and optimizing PHP intermediate code. It's similar to other PHP opcode cachers, such as eAccelerator and Xcache. It is strongly recommended to have one of these installed to speed up your PHP page.
APC can be installed as follows:
yum -y install php-pecl-apc
Now restart Apache2:
/etc/init.d/httpd restart
Now reload http://192.168.0.100/info.php in your browser and scroll down to the modules section again. You should now find lots of new modules there, including the APC module:
Click to enlarge

7 phpMyAdmin

phpMyAdmin is a web interface through which you can manage your MySQL databases.
First we enable the RPMforge repository on our CentOS system as phpMyAdmin is not available in the official CentOS 6.5 repositories:
Import the RPMforge GPG key:
rpm --import http://dag.wieers.com/rpm/packages/RPM-GPG-KEY.dag.txt
On x86_64 systems:
yum -y install http://pkgs.repoforge.org/rpmforge-release/rpmforge-release-0.5.3-1.el6.rf.x86_64.rpm
On i386 systems:
yum -y install http://pkgs.repoforge.org/rpmforge-release/rpmforge-release-0.5.3-1.el6.rf.i686.rpm
phpMyAdmin can now be installed as follows:
yum -y install phpmyadmin
Now we configure phpMyAdmin. We change the Apache configuration so that phpMyAdmin allows connections not just from localhost (by commenting out the <Directory "/usr/share/phpmyadmin"> stanza):
vi /etc/httpd/conf.d/phpmyadmin.conf
#
#  Web application to manage MySQL
#

#<Directory "/usr/share/phpmyadmin">
#  Order Deny,Allow
#  Deny from all
#  Allow from 127.0.0.1
#</Directory>

Alias /phpmyadmin /usr/share/phpmyadmin
Alias /phpMyAdmin /usr/share/phpmyadmin
Alias /mysqladmin /usr/share/phpmyadmin
Next we change the authentication in phpMyAdmin from cookie to http:
vi /usr/share/phpmyadmin/config.inc.php
[...]
/* Authentication type */
$cfg['Servers'][$i]['auth_type'] = 'http';
[...]
Restart Apache:
/etc/init.d/httpd restart
Afterwards, you can access phpMyAdmin under http://192.168.0.100/phpmyadmin/:

Fuente:
http://www.howtoforge.com/apache_php_mysql_on_centos_6.5_lamp