6.0.3

Table Of Contents
firewalls
access for management agents 174
access for services 174
floppy disks 221
folders, privileges 262
forged transmissions 232, 233
G
generating CSRs 80, 85, 89
generating certificate requests 93, 102, 104
generating STS signing certificate, vCenter
Server appliance 47
generating STS signing certificate on
Windows 48
genselfcacert 92
global permissions, assign 145
global privileges 262
groups
add members 57
adding 57
local 57
searching 144
guest operating systems
copy and paste 224
disabling logging 226
enabling copy and paste 223
limiting variable information size 225
H
hardening the vCenter Server Host OS 211
hardware devices 221
HGFS File Transfers 223
host name, configuring 190
host profiles, privileges 266, 269
host upgrades and certificates 162
host configuration with scripts 154
host management privileges, user 189
host security
authorized keys 159
CIM tools 216
disabling MOB 159
logging 206
managed object browser 159
performance data 252
resource management 220
unsigned VIBs 186
using templates 219
virtual machine console 220
virtual disk shrinking 218
host-to-host firewall ports 230
hosts
CIM privileges 263
configuration privileges 263
inventory privileges 264
local operations privileges 265
thumbprints 213
vSphere replication privileges 266
HTTPS PUT, uploading certificates and
keys 170, 201
Hypervisor security 11
I
identity provider 45
identity source
adding to vCenter Single Sign-On 31
editing for vCenter Single Sign-On 34
identity sources for vCenter Single Sign-On 29
idle session timeout 203, 204
image profile privileges 257
Image Builder security 186
informational messages, limiting 217
interediate CA, vSphere Web Client 78
intermediate CA, Certificate Manager 85
Internet Protocol Security (IPsec) 239
inventory service, privileges 267
IP addresses, adding allowed 174
IPsec, See Internet Protocol Security (IPsec)
iSCSI
authentication 250
protecting transmitted data 251
QLogic iSCSI adapters 250
securing ports 251
security 250
isolation
standard switches 14
virtual networking layer 14
VLANs 14
J
join domain 193
K
keys
authorized 200, 201
SSH 200, 201
uploading 170, 200, 201
L
Linux-based clients, restricting use with vCenter
Server 212
load balancer 62
lockdown mode
behavior 182
catastrophic vCenter Server failure 185
DCUI access 185
DCUI.Access 185
Index
VMware, Inc. 289