8.0

Table Of Contents
2 Set up the following virtual machines on the management cluster.
Infrastructure Component Description
PXE boot infrastructure TFTP and DHCP servers.
Infrastructure VM Active Directory, DNS, vCenter Server.
vSphere Auto Deploy environment PowerCLI, vSphere Auto Deploy server, vCenter Server. Set up this
environment on a single virtual machine or on three separate virtual machines
in production systems.
The vCenter Server on the infrastructure virtual machine differs from the vCenter Server in the
vSphere Auto Deploy environment.
3 Set up vSphere Auto Deploy to provision other hosts as needed.
Because the components on the management cluster are protected with vSphere HA, high
availability is supported.
vSphere Auto Deploy Security Considerations
When you use vSphere Auto Deploy, pay careful attention to networking security, boot image
security, and potential password exposure through host profiles to protect your environment.
Networking Security
Secure your network just as you secure the network for any other PXE-based deployment
method. vSphere Auto Deploy transfers data over SSL to prevent casual interference and
snooping. However, the authenticity of the client or of the Auto Deploy server is not checked
during a PXE boot.
You can greatly reduce the security risk of Auto Deploy by completely isolating the network where
Auto Deploy is used.
Boot Image and Host Profile Security
The boot image that the vSphere Auto Deploy server downloads to a machine can have the
following components.
n The VIB packages that the image profile consists of are always included in the boot image.
n The host profile and host customization are included in the boot image if Auto Deploy rules are
set up to provision the host with a host profile or host customization.
n The administrator (root) password and user passwords that are included with host profile
and host customization are hashed with SHA-512.
n Any other passwords associated with profiles are in the clear. If you set up Active Directory
by using host profiles, the passwords are not protected.
Use the vSphere Authentication Proxy to avoid exposing the Active Directory passwords. If
you set up Active Directory using host profiles, the passwords are not protected.
n The host's public and private SSL key and certificate are included in the boot image.
VMware ESXi Installation and Setup
VMware, Inc. 196