<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VMtoday &#187; security</title>
	<atom:link href="http://vmtoday.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://vmtoday.com</link>
	<description>VMware News, Views, &#38; How-To&#039;s from Josh Townsend</description>
	<lastBuildDate>Tue, 06 Jul 2010 17:21:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Virtualization Bookmarks for August 28th</title>
		<link>http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=virtualization-bookmarks-for-august-28th</link>
		<comments>http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 14:13:21 +0000</pubDate>
		<dc:creator>Joshua Townsend</dc:creator>
				<category><![CDATA[General IT]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[bookmarks]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[client]]></category>
		<category><![CDATA[comparison]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[disk]]></category>
		<category><![CDATA[hippa]]></category>
		<category><![CDATA[iscsi]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[manager]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[powershell]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[SAN]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vcenter]]></category>
		<category><![CDATA[vdi]]></category>
		<category><![CDATA[vmsight]]></category>
		<category><![CDATA[vmtoday]]></category>
		<category><![CDATA[vsphere]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows7]]></category>

		<guid isPermaLink="false">http://vmtoday.com/?p=161</guid>
		<description><![CDATA[Here are some bookmarks for resources that I have recently referenced: vCenter 4 and ESX 4 Now Use 10 Year Default SSL Certificate &#124; VM /ETC &#8211; Rich Brambly has some guidance on installing a new SSL certificate on vCenter, with very useful links in his post to official VMware documentation and KB&#8217;s on the [...]


Related posts:<ol><li><a href='http://vmtoday.com/2010/07/emc-virtual-storage-integrator-update/' rel='bookmark' title='Permanent Link: EMC Virtual Storage Integrator Update'>EMC Virtual Storage Integrator Update</a> <small>I upgraded my in-house VMware vSphere environment to 4.0 Update...</small></li>
<li><a href='http://vmtoday.com/2010/05/free-san-monitor-for-ds3300-md3000i-and-others/' rel='bookmark' title='Permanent Link: Free SAN Monitor for DS3300, MD3000i and others'>Free SAN Monitor for DS3300, MD3000i and others</a> <small>One of my most popular posts to date had been...</small></li>
<li><a href='http://vmtoday.com/2009/09/vcenter-database-stats-rollup-troubleshooting/' rel='bookmark' title='Permanent Link: vCenter Database Stats Rollup Troubleshooting'>vCenter Database Stats Rollup Troubleshooting</a> <small>VMware vCenter collects performance statistics, tasks and events for historical...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Here are some bookmarks for resources that I have recently referenced:</p>
<ul>
<li><a href="http://vmetc.com/2009/08/14/vcenter-4-now-has-10-year-default-ssl-certificate/">vCenter 4 and ESX 4 Now Use 10 Year Default SSL Certificate | VM /ETC</a> &#8211; Rich Brambly has some guidance on installing a new SSL certificate on vCenter, with very useful links in his post to official VMware documentation and KB&#8217;s on the subject.</li>
<li><a href="http://www.virtuallifestyle.nl/2009/05/vmware-vsphere-client-on-microsoft-windows-7/">VMware vSphere Client on Microsoft Windows 7! | Virtual Lifestyle</a> &#8211; Heiko Verlande has found a way to run the VMware vSphere Client on Windows 7.</li>
<li><a href="http://www.virtu-al.net/2009/08/18/powercli-daily-report-v2/">Virtu-Al » PowerCLI: Daily Report V2</a> &#8211; Version two of a handy PowerShell based VMware Environment Daily Report from VMware vExpert and PowerShell guru Alan Renouf
<ul>What’s new/Bug Fixes<br />
* Active VMs count<br />
* Inactive VMs count<br />
* DRS Migrations count and list<br />
* Correct NTP Server check for each host<br />
* VMs stored on local datastores<br />
* NTP Service check for each host<br />
* vmkernel warning messages for each host<br />
* VM CPU ready over x%</ul>
</li>
<li><a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=1003468">VMware Self-Service- VMware Update Manager Plug-In fails to install</a> -Troubleshooting steps for vCenter Plug-in install problems.</li>
<li><a href="http://www.vmware.com/resources/techresources/1027">Using VMware VDI and vmSight for Stronger and Sustainable HIPAA and PCI Compliance</a> &#8211; Virtualization brings new options for protecting sensitive data by moving it from the desktop into the datacenter.</li>
<li><a href="http://blogs.technet.com/cotw/archive/2009/03/18/analyzing-storage-performance.aspx">Counter of the Week : Analyzing Storage Performance</a> &#8211; The purpose of this article is to provide prescriptive guidance on how to troubleshoot logical and physical disk response times in regards to Windows performance analysis. Start with the following performance counters to analyze disk response&#8230;</li>
<li><a href="http://www.networkworld.com/reviews/2008/072808-test-iscsi-sans.html">NetApp, Compellent, HP, Dell top the field in 12-product test &#8211; Network World</a> &#8211; A terabyte isn&#8217;t what it used to be. Disks are slower than you think. And a Gigabit Ethernet is plenty of bandwidth for many storage applications.</li>
</ul>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Virtualization+Bookmarks+for+August+28th+-+http://bit.ly/bRMfIh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;title=Virtualization+Bookmarks+for+August+28th" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;title=Virtualization+Bookmarks+for+August+28th" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;title=Virtualization+Bookmarks+for+August+28th" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Virtualization%20Bookmarks%20for%20August%2028th%22&amp;body=Link: http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Here%20are%20some%20bookmarks%20for%20resources%20that%20I%20have%20recently%20referenced%3A%0D%0A%0D%0A%09vCenter%204%20and%20ESX%204%20Now%20Use%2010%20Year%20Default%20SSL%20Certificate%20%7C%20VM%20%2FETC%20-%20Rich%20Brambly%20has%20some%20guidance%20on%20installing%20a%20new%20SSL%20certificate%20on%20vCenter%2C%20with%20very%20useful%20links%20in%20his%20post%20to%20official%20VMware%20documentation%20and%20KB" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-printfriendly">
			<a href="http://www.printfriendly.com/print?url=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/" rel="nofollow" class="external" title="Send this page to Print Friendly">Send this page to Print Friendly</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;title=Virtualization+Bookmarks+for+August+28th" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;title=Virtualization+Bookmarks+for+August+28th&amp;srcUrl=http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/&amp;srcTitle=Virtualization+Bookmarks+for+August+28th&amp;snippet=Here%20are%20some%20bookmarks%20for%20resources%20that%20I%20have%20recently%20referenced%3A%0D%0A%0D%0A%09vCenter%204%20and%20ESX%204%20Now%20Use%2010%20Year%20Default%20SSL%20Certificate%20%7C%20VM%20%2FETC%20-%20Rich%20Brambly%20has%20some%20guidance%20on%20installing%20a%20new%20SSL%20certificate%20on%20vCenter%2C%20with%20very%20useful%20links%20in%20his%20post%20to%20official%20VMware%20documentation%20and%20KB" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>



<p>Related posts:<ol><li><a href='http://vmtoday.com/2010/07/emc-virtual-storage-integrator-update/' rel='bookmark' title='Permanent Link: EMC Virtual Storage Integrator Update'>EMC Virtual Storage Integrator Update</a> <small>I upgraded my in-house VMware vSphere environment to 4.0 Update...</small></li>
<li><a href='http://vmtoday.com/2010/05/free-san-monitor-for-ds3300-md3000i-and-others/' rel='bookmark' title='Permanent Link: Free SAN Monitor for DS3300, MD3000i and others'>Free SAN Monitor for DS3300, MD3000i and others</a> <small>One of my most popular posts to date had been...</small></li>
<li><a href='http://vmtoday.com/2009/09/vcenter-database-stats-rollup-troubleshooting/' rel='bookmark' title='Permanent Link: vCenter Database Stats Rollup Troubleshooting'>vCenter Database Stats Rollup Troubleshooting</a> <small>VMware vCenter collects performance statistics, tasks and events for historical...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://vmtoday.com/2009/08/virtualization-bookmarks-for-august-28th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Your Virtual Infrastructure</title>
		<link>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=securing-your-virtual-infrastructure</link>
		<comments>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 21:03:38 +0000</pubDate>
		<dc:creator>Joshua Townsend</dc:creator>
				<category><![CDATA[General IT]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VMware How To]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtual]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://vmtoday.com/?p=45</guid>
		<description><![CDATA[Between budget cuts and New Year&#8217;s resolutions, improving your security posture is probably near the top of your to-do list.  Much has been made of security concerns in a virtual environment, but it is always good to re-visit your configurations and make sure they are still on par with recommended best practices.  I began re-reviewing [...]


Related posts:<ol><li><a href='http://vmtoday.com/2009/07/virtual-infrastructure-client-opens-off-screen/' rel='bookmark' title='Permanent Link: Virtual Infrastructure Client Opens Off Screen'>Virtual Infrastructure Client Opens Off Screen</a> <small>A user reported an issue with one of the VM&#8217;s...</small></li>
<li><a href='http://vmtoday.com/2009/11/upgrading-virtual-hardware-in-a-vmware-virtual-machine-may-cause-disks-to-go-offline/' rel='bookmark' title='Permanent Link: Upgrading Virtual Hardware in a VMware Virtual Machine May Cause Disks to go Offline'>Upgrading Virtual Hardware in a VMware Virtual Machine May Cause Disks to go Offline</a> <small>I recently posted an article on how specific actions during...</small></li>
<li><a href='http://vmtoday.com/2008/11/microsoft-offline-virtual-machine-servicing-tool-v2-released/' rel='bookmark' title='Permanent Link: Microsoft Offline Virtual Machine Servicing Tool v2 Released'>Microsoft Offline Virtual Machine Servicing Tool v2 Released</a> <small>The Microsoft Offline Virtual Machine Servicing Tool v2 could be...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Between budget cuts and New Year&#8217;s resolutions, improving your security posture is probably near the top of your to-do list.  Much has been made of security concerns in a virtual environment, but it is always good to re-visit your configurations and make sure they are still on par with recommended best practices.  I began re-reviewing VI security best practices after reading at post by Bob Plankers at <a title="The Lone SysAdmin: Why Would You Want a Second Superuser" href="http://lonesysadmin.net/2008/12/23/why-would-you-want-a-second-superuser/" target="_blank">The Lone SysAdmin</a> (Bob has been on my reading list for years &#8211; he has a great style and always brings fresh insights) on why you would want a second super-user account on your ESX servers.</p>
<p>We certainly all have our own opinions and operations procedures when it comes to configuring and hardening our environments, but I decided to take a look at what the experts had to say on this particular subject and other basic build and hardening recommendations.  Here is what I found:</p>
<p><a title="VMware Security Resources" href="http://www.vmware.com/technology/security/resources.html" target="_blank">VMware Security Resources</a></p>
<p><a title="VMware Security Utilities" href="http://www.vmware.com/technology/security/utilities.html" target="_blank">VMware Security Utilities</a></p>
<p><a title="VMware Security Hardening Whitepaper" href="http://www.vmware.com/files/pdf/vi35_security_hardening_wp.pdf" target="_blank">VI3.5 Security Hardening Whitepaper</a></p>
<p><a title="DISA STIG" href="http://iase.disa.mil/stigs/stig/esx_server_stig_v1r1_final.pdf" target="_blank">Defense Informaion Systems Agency (DISA) ESX Server Security Technical Implementation Guide</a></p>
<p><a title="DISA ESX Server Checklist" href="http://iase.disa.mil/stigs/checklist/esx_server_checklist_v1_r1-2_03sep2008pdf.zip" target="_blank">DISA ESX Server Checklist</a></p>
<p>As a side note, DISA publishes many STIG&#8217;s at <a title="DISA STIG Library" href="http://iase.disa.mil/stigs/" target="_blank">http://iase.disa.mil/stigs/</a>.  Your tax dollars paid for these, so you might as well check them out.</p>
<p><a title="NSA ESX Configuration Guide" href="http://www.nsa.gov/snac/support/I733-009R-2008.pdf" target="_blank">NSA VMware ESX  Server 3 Configuration Guide</a></p>
<p>There are also numerous tips and scripts for locking down your virtual infrastructure in the VMware Community Forums (Start here: <a title="ESX_SRRSecure - Script to allow ESX to pass a DISA Security Readiness Review" href="http://communities.vmware.com/message/941372" target="_blank">http://communities.vmware.com/message/941372</a>).</p>
<p>So back to the question of second super user accounts: It seems that best practices are to create a second user account with sufficient access to the console, granting that user SUDO privledges, and then disabling the default root account.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center">
<ul class="socials">
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Securing+Your+Virtual+Infrastructure+-+http://bit.ly/bb3gDC&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;title=Securing+Your+Virtual+Infrastructure" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;title=Securing+Your+Virtual+Infrastructure" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;title=Securing+Your+Virtual+Infrastructure" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Securing%20Your%20Virtual%20Infrastructure%22&amp;body=Link: http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Between%20budget%20cuts%20and%20New%20Year%27s%20resolutions%2C%20improving%20your%20security%20posture%20is%20probably%20near%20the%20top%20of%20your%20to-do%20list.%C2%A0%20Much%20has%20been%20made%20of%20security%20concerns%20in%20a%20virtual%20environment%2C%20but%20it%20is%20always%20good%20to%20re-visit%20your%20configurations%20and%20make%20sure%20they%20are%20still%20on%20par%20with%20recommended%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-printfriendly">
			<a href="http://www.printfriendly.com/print?url=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/" rel="nofollow" class="external" title="Send this page to Print Friendly">Send this page to Print Friendly</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;title=Securing+Your+Virtual+Infrastructure" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;title=Securing+Your+Virtual+Infrastructure&amp;srcUrl=http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/&amp;srcTitle=Securing+Your+Virtual+Infrastructure&amp;snippet=Between%20budget%20cuts%20and%20New%20Year%27s%20resolutions%2C%20improving%20your%20security%20posture%20is%20probably%20near%20the%20top%20of%20your%20to-do%20list.%C2%A0%20Much%20has%20been%20made%20of%20security%20concerns%20in%20a%20virtual%20environment%2C%20but%20it%20is%20always%20good%20to%20re-visit%20your%20configurations%20and%20make%20sure%20they%20are%20still%20on%20par%20with%20recommended%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>



<p>Related posts:<ol><li><a href='http://vmtoday.com/2009/07/virtual-infrastructure-client-opens-off-screen/' rel='bookmark' title='Permanent Link: Virtual Infrastructure Client Opens Off Screen'>Virtual Infrastructure Client Opens Off Screen</a> <small>A user reported an issue with one of the VM&#8217;s...</small></li>
<li><a href='http://vmtoday.com/2009/11/upgrading-virtual-hardware-in-a-vmware-virtual-machine-may-cause-disks-to-go-offline/' rel='bookmark' title='Permanent Link: Upgrading Virtual Hardware in a VMware Virtual Machine May Cause Disks to go Offline'>Upgrading Virtual Hardware in a VMware Virtual Machine May Cause Disks to go Offline</a> <small>I recently posted an article on how specific actions during...</small></li>
<li><a href='http://vmtoday.com/2008/11/microsoft-offline-virtual-machine-servicing-tool-v2-released/' rel='bookmark' title='Permanent Link: Microsoft Offline Virtual Machine Servicing Tool v2 Released'>Microsoft Offline Virtual Machine Servicing Tool v2 Released</a> <small>The Microsoft Offline Virtual Machine Servicing Tool v2 could be...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://vmtoday.com/2009/01/securing-your-virtual-infrastructure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
