2017 archive

vSphere 6.5 VM and vSAN Encryption FAQ now available

I’m really pleased to announce the availability of the vSphere 6.5 VM and vSAN Encryption FAQ! This FAQ is built upon over a year of questions that have come in to me on both VM and vSAN Encryption. We’ve reached critical mass and now it’s time to share!

Continue reading

Key Manager Concepts and Topology Basics for VM and vSAN Encryption

At VMworld 2017 VM and vSAN Encryption and security of vSphere in general became VERY popular topics. And in those discussions the topic of Key Managers came up and specifically “How many key managers should I have?” was a recurring question.

Continue reading

Using the vCenter Login Banner for RSA SecurID support

In vSphere 6.0 Update 2 we added the capability to use RSA SecurID for two-factor authentication (2FA) in to the web client (only). I wrote about that in a two part blog series. Part 1 and Part 2

I recently got an email from a customer asking me about the implementation of the RSA SecurID Agent in vSphere and that prompted this blog.

The initial inquiry was around SecurID PIN resets and the customer asked: “It seems like vSphere doesn’t support PIN resets. How can I help my folks who are logging in to vCenter if their PIN is expired?”

In this blog I’ll show you how editing the Login Banner can help you get your users to the right page to reset their RSA SecurID PIN.

Continue reading