User`s guide

During the installation process, you must specify certificates for the Collector and for the Enterprise. You
can have Installation Manager generate the certificates for you, or you can use your existing certificates. If
you plan to use your own certificates, familiarize yourself with the certificate names so that you can select
those certificates from your certificate store during installation.
A Collector certificate must meet certain criteria to be valid:
n
The Collector certificate must be located in the local machine personal certificate store.
n
The Collector certificate must be valid for Server Authentication. If any Enhanced Key Usage extension
or property is present, it must include the Server Authentication OID 1.3.6.1.5.5.7.3.1. If the Key Usage
extension is present, it must include DIGITAL_SIGNATURE.
n
The Collector certificate must not be expired.
NOTE If you provide your own certificates, refer to the Transport Layer Security (TLS) Implementation for
VCM White Paper on the VMware Web site.
Identify Default Network Authority Account
The Installation Manager requires that you specify the default network authority account during the
installation process. VCM uses the default network authority account to collect data from Windows Agent
machines. The default network authority account, which is often the system administrator’s account, must
be set up in the local administrators group on each machine prior to installation and needs administrator
rights on the Agent machines.
NOTE You can change the network authority account later in VCM at Administration > Settings >
Network Authority.
1. Right-click Computer and select Manage to open Server Manager.
2. Expand Configuration, expand Local Users and Groups and click Groups.
3. Double-click Administrators and verify that the network authority account is listed as a member of the
Administrators group.
If the user or administrator’s group is not listed, add the user or group to the list. Also ensure that the
user has Windows administrator rights issued by the network administrator.
Identify VMware Application Services Account
The VMware Application Services Account must be a domain user. Because this account will have full
administrative authority to the CSI_DOMAIN database, you should never use it as a VCM login or for any
other purpose.
1. Right-click Computer and select Manage to open Server Manager.
2. Expand Configuration, expand Local Users and Groups and click Groups.
3. Double-click Administrators and verify that the application services account is listed as a member of
the Administrators group.
If the user or administrator’s group is not listed, add the user or group to the list. Also ensure that the
user has Windows administrator rights issued by the network administrator.
Software and Operating System Requirements for Collector Machines
VMware, Inc. 37