Latest Entries »

Wednesday, June 29, 2011

ESXi Active Directory Integration

Worked with a customer today to setup AD authentication providers for ESXi access. Every time he tried to login into the server using his AD credentials he received an error stating his username or password invalid. At first I just thought he couldn't type, but after the third and fifth try I figured there had to be something wrong.

I popped into the Authentication Providers and everything looked good. The server was configured to use Active Directory and I confirmed in ADUC that the computer account had been created.

ESX Authentication Services
I then popped into the DNS and Routing section to ensure the domain and DNS was setup properly. It looked something like this.
ESX DNS and Routing - No Domain
You will notice in the figure above that the Domain setting is empty. The admin guide states that this needs be configured in order for the host to join the domain (http://pubs.vmware.com/vsphere-esxi-4-1-installable/server_config/t_configure_directory_service.html ). A quick jump into the properties to update the domain field (you will need to remove the server from the domain before changing this) and it was populated. 
ESX DNS and Routing - With a Domain
Sorry about the graphic (had to remove the names to protect the innocent?), but if you look closely you will see there are now a few letters in the Domain field. 

Ok, so we fixed the settings to make it compliant with the admin guide settings and then we opened the vSphere and client, punched in the host name, clicked the box (should have done this the first time) to pass the session credentials to the host and......

Unknown username or bad password!

What gives? The host is configured correctly and successfully joined the domain. I took a look at how he was logged in and noticed that the Windows 2000 domain name was different than the FQDN for the domain (ie: domain\username and the FQDN was domain.somewhere.com). On a whim I said, try this, domain.somewhere.com\username, and bada-bing, we were in. So, it seems linux is linux and doesn't know about the NetBIOS name, go figure, and the FQDN that is used in host DNS and Routing settings needs be used to successfully pass the credentials through. The nice little check box for passing credentials is out, but at least you can login with your AD account. Of course you will really hate your really.long.domain.that.normally.is.just.one.word. Have fun!

BTW, you can add a host to any Organization Unit in your domain by specifying "domain.com/ou name/another ou" (without the quotes) as the Domain in the Domain Settings section of the Directory Services Configuration dialog box.


Saturday, March 5, 2011

Drinking and Laughing

I have seen and heard a lot of Christians talking about alcohol, crude movies (even some that non-christians have avoided for crudeness), and talking coarsely about sex and drinking. I know for myself I often laugh, and or enjoy something, that if I later think more about I realize I probably should not have indulged. As a Christian I don't want to lead a brother or sister into sin, nor do I want to sin. My goal should be to glorify God and to lead others to him through my example.

Let me start by saying, I have an occasional drink and enjoy movies. The scripture tells us that Jesus turned water into wine, and of course the last supper has him drinking the cup and passing it to the disciples. The culture of his time would also dictate that one would just drink wine at a meal. so, if wine is unholy, then there is no way Jesus could have had it to drink, he is perfectly holy, so a drink in this case would mean he sinned against himself and his father's commands to be holy.

Now, take food for example. I like food, I need food. Jesus ate food. Food however, can be (key word, can) sinful if it is abused. In this example, over eating food to the point of excess, gluttony, is a sin. 

Paul tells us that all things are permissible, but not all things are good for us. Food, wine, beer, movies, all permissible, but not all good for us (1 Corinthians 10:23).  The point of the entire chapter of 1 Cor 10 is to do all things to the glory of God, whether that is eating or drinking, the reason you do those things ought to be so that God may be glorified.

Paul begins the chapter with some stern warnings to the people of Corinth (1 Cor 10:5). He is warning them that if they depart from God, God in his perfect justice and holiness will punish them with death. He reminds them that this is no new thing, but that God has always throughout history punished those who do evil, and especially those who do evil while claiming to be God's people. See the Old Testament if you need more convincing.

Is a movie bad? In and of itself, not necessarily (although many are). But what is the movie leading you to do? Maybe you are a strong person and not easily influenced. While that is good, the scripture is clear that bad company corrupts good morals. So if we go regularly to the company of immoral movies, whether at home or the theatre, we will in one way or another be influenced and brought into the things that are portrayed. If that is drunkenness, harlotry,  gambling, murder, etc and we enjoy the movie, we are in some way partaking of the sin.

Here is what the Bible says regarding drinking wine or in this case watching a movie or talking coarsely:

Ephesians 5:1-21
1Be imitators of God, therefore, as dearly loved children 2and live a life of love, just as Christ loved us and gave himself up for us as a fragrant offering and sacrifice to God.
 3But among you there must not be even a hint of sexual immorality, or of any kind of impurity, or of greed, because these are improper for God's holy people. 4Nor should there be obscenity, foolish talk or coarse joking, which are out of place, but rather thanksgiving. 5For of this you can be sure: No immoral, impure or greedy person—such a man is an idolater—has any inheritance in the kingdom of Christ and of God.[a] 6Let no one deceive you with empty words, for because of such things God's wrath comes on those who are disobedient. 7Therefore do not be partners with them.
 8For you were once darkness, but now you are light in the Lord. Live as children of light 9(for the fruit of the light consists in all goodness, righteousness and truth) 10and find out what pleases the Lord. 11Have nothing to do with the fruitless deeds of darkness, but rather expose them. 12For it is shameful even to mention what the disobedient do in secret. 13But everything exposed by the light becomes visible, 14for it is light that makes everything visible. This is why it is said:
   "Wake up, O sleeper,
      rise from the dead,
   and Christ will shine on you."
 15Be very careful, then, how you live—not as unwise but as wise, 16making the most of every opportunity, because the days are evil. 17Therefore do not be foolish, but understand what the Lord's will is. 18Do not get drunk on wine, which leads to debauchery. Instead, be filled with the Spirit. 19Speak to one another with psalms, hymns and spiritual songs. Sing and make music in your heart to the Lord, 20always giving thanks to God the Father for everything, in the name of our Lord Jesus Christ.
 21Submit to one another out of reverence for Christ.


As Christians we are commanded to be as holy as God. That doesn't mean we always will be, but that is why Jesus died for us. That said, the command still stands and we must obey it. If we willfully disobey, then we deserve nothing but God's wrath. He is merciful, and gives freely to all who hear his voice and turn from their sins. But as Jesus said to many of those he healed. Go and sin no more.

Please prayerfully consider what is being said by the apostle in this passage. Ask God to show you the motives of your heart. Ask him to drive out any sinful desires, and to give you a heart of flesh that beats for him.  There is a way that seems right to a man, but the end of it is death. Be filled with the spirit.

With prayers, and concern for your soul, your friend,

Rocky

Monday, January 31, 2011

EMC VAII



EMC Array Integration

There are a number of free, yes free, tools available from EMC to assist with managing ESX host's shared storage. All of the tools are available on powerlink.emc.com. These vSphere plugins allow you to create and configure LUNs from end-to-end on an EMC array. The Virtual Storage Integrator (VSI) tools come in the following flavors:


File NameDescription
EMC_VSI_for_VMware_vSphere_Unified_Storage_Management.zip Used for storage management functions, such as creating a LUN that is presented to all hosts.
emc-vsi-pm-4.0.0-vmware-vsphere-WINDOWS-x86.zipUsed for Path Management of vSphere ESX hosts. This allows you to set the default path policy for all ESX hosts.
emc-vsi-spm-4.0.0-vmware-vsphere-WINDOWS-x86.zipUsed for Storage Pool management. This allows integration with the new CX4, VNX and Celerra storage pools.
emc-vsi-sv-4.0.0-vmware-vsphere-WINDOWS-x86.zipUsed for gaining visibility into the storage components behind a VM and/or ESX host. This allows you to easily see what storage resources are being used to support the VM.


There is an order of installation that should be followed to workaround a known issue with the MSI installer package.

Install in this order:


  1. NavisphereCLI

  2. emc-vsi-sv-4.0.0-vmware-vsphere-WINDOWS-x86.zip
  3. emc-vsi-spm-4.0.0-vmware-vsphere-WINDOWS-x86.zip
  4. emc-vsi-pm-4.0.0-vmware-vsphere-WINDOWS-x86.zip
  5. VSI Unified Storage Management Plug-in 4.0.0.45
What are the Multipathing Policies in ESX 4.x? Check out http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1011340 for more info.