6.0.3

Table Of Contents
securing vCenter Server Appliance 213
security
best practices 247
certification 17
DMZ in single host 236, 237
host 156
iSCSI storage 250
permissions 141
standard switch ports 232
vCenter Server 13
virtual machines with VLANs 234
virtual networking layer 14
virtualization layer 11
VLAN hopping 235
VMware policy 17
security policies
available 241
creating 241
listing 241
removing 242
security profile 173, 179
security token service (STS), vCenter Single
Sign-On 50
security and PCI devices 199
security associations
adding 239
available 239
listing 239
removing 240
security policy 232
security recommendations 180, 243
Security Token Service 20, 22, 47
services
stopping 92
syslogd 207
sessions, privileges 270
shares limits, host security 220
Single Sign-On
about 25
benefits 20
disabling users 55
editing users 56
effect on vCenter Server installation and
upgrades 22
login fails because user account is locked 62
Lookup Service Error 60
policies 51
troubleshooting 60
unable to log in using Active Directory
domain 61
upgrades 23
Single Sign-On identity source, deleting 35
Single Sign-On solution users 58
smart card authentication
configuring 196
disable 197
enable 197
fallback 198
in lockdown mode 198
SMS API privileges 270
SNMP 242
solution user sso handshake 20
solution users 58
solution user certificates 91, 97
spanning 243
SSH
ESXi Shell 200
security settings 200
SSH keys 199
SSL
enable over NFC 214
enabling and disabling 65
encryption and certificates 65
SSL certificate 51
SSO, See Single Sign On See Single Sign-On
SSO HA 62
SSO passwords 16
SSPI 35
standard switch ports, security 232
standard switch security 235
standard switches
and iSCSI 251
forged transmissions 232
MAC address changes 232
promiscuous mode 232
storage, securing with VLANs and virtual
switches 235
Storage Monitoring Service API privileges 270
storage views, privileges 270
storage security best practices 250
stp 231
strict lockdown mode 180
STS, See security token service (STS)
STS (Security Token Service) 22
STS signing certificate
vCenter Server appliance 47
vCenter Server on Windows 48
subordinate certificate 106
Subordinate CA, Certificate Manager 85
switch 231
synchronize ESXi clocks on vSphere
network 247
synchronizing clocks on the vSphere
network 247
syslog 207
vSphere Security
292 VMware, Inc.