Thursday, August 6, 2015

SRM 6 NIGHTMARE!!!

***************************
Update 2

This case is now closed. Only advice that I can give at this point is be VERY careful when you are updating the Certificates in the MOB. If you do it wrong, you will be rebuilding your environment.

The below notes do work for fixing the MOB just make sure you know exactly what your syntax is supposed to be and know which Certificates you are replacing...


Back to the drawing board for me.....


*****SIGH*****


$#@%^&*&%$##^%^&!!!


***************************
UPDATE!!!

After going through all of this again (time has finally permitted me to get a back to this). I have finally got MOST of this working. I say most because I reset my PSC and vCenter Certs to the same thing and now I have to call support to see if I can change this! *Yes, I am an idiot* I will update again as I get this last part figured out.


VMware has updated KB2121701 so many times over the last couple of months that they must really be sick of that page.

The ROOT of the problem is the certificates that are associated with the PSC and the vCenter servers. If they get changed, for some reason VMware does not change them properly in the MOB *or where ever the info is stored* and it then falls on you the Admin to be clever enough to know this is the issue......


If you follow the instructions (very carefully I might add) it gives you instructions how to view what the current certificate that the MOB has listed for your PSCs and your vCenters , how to download a copy of those Certs to get a Thumbprint, how to download your current Certificates, and finally how to use the ls_update_certs.py * which you have to install a new one from the KB article* script to modify what is in the MOB pages. Below is the example from the article of the scripts you will run. I want to point out if you have multiple PSCs and vCenters you will need to do this for ALL of them! You also have to run this from the PSC server.



%VMWARE_PYTHON_BIN%" ls_update_certs.py --url https://psc.vmware.com/lookupservice/sdk --fingerprint 13:1E:60:93:E4:E6:59:31:55:EB:74:51:67:2A:99:F8:3F:04:83:88 --certfile c:\certificates\new_machine.crt --user Administrator@vsphere.local --password Password


You would need to do the above for:

1.) Your Production PSC *get the thumbprint for the old cert and download the new cert to a central location*
2.) Your Production vCenter *get the thumbprint for the old cert and download the new cert to a central location*
3.) Your DR PSC *get the thumbprint for the old cert and download the new cert to a central location*
4.) Your DR vCenter *get the thumbprint for the old cert and download the new cert to a central location*

I don't know how to make KB 2121701 easier to read but there has to be a way....it is a wealth of knowledge but....it is not easy to obtain that knowledge! 


****************************


I am trying to love VMware vSphere 6 and Site Recovery Manager 6 (SRM). I am trying to show my confidence in VMware. It's not working though.....and I know, I broke the cardinal rule of IT “never adopt early.”

VMware has been my favorite technology for a long time! I drank the Kool-aide and in my mind there is not another company that is doing the kinds of things that they are. Let's face it though....nobody is perfect.

I have now had a case open with them since June 8th about Site Recovery Manager 6 and vCenter 6, about 2 months. I have talked to some great techs there at VMware, but to me I am beginning to sense that there is a lot of confusion among their ranks about the new products. I have had techs tell me that I had to have the same certificate for both the protected and recovery site in order for things to work, and yet their install and configure manual clearly says different. I have had technicians that did not know what the VMCA is and what the function of it was, going as far as to tell me that I needed to do individual certs for each of my vCenter servers, Platform Services Controller (PSC) servers and my ESXi servers. I still have not gotten a good answer as to if SRM and the VMCA work together or if they will sometime in the future. Heck, the first month of my case was spent calling and begging their support team to call me back, it wasn’t until my VP called and started screaming that I started getting any serious traction on the case.

The frustrating part? I have done a bog standard install of SRM. I have setup my environment with VMware’s best practices. I have even gone so far as to ask the technicians to verify the install.

The PSCs are External. The vCenter Servers and the SRM servers are stand-alone VM servers.  I made my VMCAs into a subordinate Certificate Authorities to my in-house Certificate Authority so that all of my clients would trust the sites and we would not have issues.




It is exactly as VMware shows it in a standard Two-Site Topology with one vCenter Server instance per Platform Services Controller (PSC).

 














My issue??  Here goes, when I go to Site Recovery>Sites from my production server, I immediately get the below message:





Error: Failed to connect to Lookup Service at HTTPS://DRPSCSERVER.DOMAIN.COM:443/lookupservice/sdk.
Reason:
com.vmware.vim.vmomi.core.exception. CertificateValidationException: Server certificate chain not verified.

Simple right? My certificates on my vCenter must not be trust that PSC chain right? One of the servers must not be have the chain or the certificate for the DR site….but they do. VMware has verified they do. I can go to the DR PSC server from my Production vCenter Server and it shows the site as trusted…

VMware has combed the logs, and “We ain’t found….”












Now, if I try the same exact thing from the DR side what happens you ask? Same exact thing, but the error message says that it certificate chain is not valid for the Production PSC server. Which is really weird….because I can see both vCenter servers on both the Production and DR sites. Oh, and once again I can go to the Production PSC from the vCenter server and it shows the site as well.

Ahh….so it must be the PSCs don’t trust each other…..NOPE. I can go to each of the PSCs and they both trust the other.

Well so that leaves the SRM servers right? One of them must be the culprit. Well, as before …the vCenter servers all look trusted, and so do the PSC servers. The certificates that the SRM servers have are actually from the parent CA. So they are trusted all the way through….

I am bumfuzzeled….

If anyone has any advice on this PLEASE speak up! Once I get a solution I promise I will append it to this entry….




















Thursday, August 28, 2014

Final day!

I am so far behind, it is not even funny, but in my defense it has been a whirlwind couple of days! I was starting to get a little disappointed with what I was seeing this time around at VMWorld. There was something that I thought was missing and I could not put my finger on it. 

Yesterday I found it. CloudVolumes. With what I have been involved with at the office I was looking for something that would improve the user experience with View. This is definitely what I was looking for! You can use a vmdk file that has applications installed to standardize a department build, without having to install it into the base image. Of course that is over simplifying.

There are also other things coming up....Project Meteor , and Project Fargo both looking to make the vdi environment even more. There are so many good things coming! 

The party last night was pretty cool. I was thrilled to be able to be part of the paper airplane toss for charity. This to me was something very positive that VMware is doing and I applaud them for it.

#VMWorld #VMware

Monday, August 25, 2014

End of day report

Lots of info in the sessions today! View 6 sounds to be very promising, with it being configured out of the box to give 30% bandwidth savings right out of the box! 

The log viewer that VMware is offering sounds like a heck of a product too! Being able to pull logs from more than just your ESXi servers; it can pull logs from your SAN, Fiber Switches,Network Switches, Windows machine and much more. It also give you the ability to not only pull those logs, but you can correlate outages that happen and you can filter out everything but error and warnings if you want. Not to mention the fact that you can download filter packs from VMWare to help making diagnostics even easier.

The general session did have some great info, but let's face it, the general sessions are VMWare's time to rah rah about everything that is coming and remind you exactly how many buzz words they know. I don't know about all the other shops out there, but our shop has decided it will keep its infrastructure in-house so that being said I will not feel guilty about not jumping on VMWare's cloud chariot and racing of into the wild blue younder! 

Sunday, August 24, 2014

Shake, Rattle and Roll!!!

Wow! You know VMWORLD is gonna be great when the first thing they do is wake you up with a 3:30am wake up call that can shake down the house!! Naa....I know that VMware had nothing to do with the earthquake.....or did they?! 

Registration is done! Bag has been picked up....now time for some grub! Looking forward to hitting the labs here in a bit. As always VMware has done their best to make sure that the venues look great! The buzz is in the air and everyone is already talking about what tricks VMware has up its sleeve this year. 

Fully rested and looking forward to what the week has in store for me! 


Thursday, July 31, 2014

Unofficial VMworld 2014 Blogger List!!

Oh my goodie aunt! I made it onto the Unofficial VMworld 2014 Blogger List!! I am so excited to be able to attend VMworld again this year. The sheer amount of information that is given during this even is mind blowing! This is going to be my third VMworld, and I still can't wait to get there. So from August 23rd through August 28th, I will be giving my opinion about the up and coming technologies from VMware and other market leaders!



As always looking forward to meeting new people and old friends there. Hope to see you all there!

Tuesday, July 8, 2014

Free Microsoft Books!

Had a colleague of mine send me a link to this today. So I figured I would share it with everyone else. Books can be really expensive so anytime I can find one that can be useful and free, I latch onto them!

Eric Ligman publishes a list of Microsoft books and has been doing so for a while now. This might not be new news for some of you but I thought it was great. So give him a follow on Twitter or Facebook or on his Blog, I am sure he would appreciate it!



http://blogs.msdn.com/b/mssmallbiz/archive/2014/07/07/largest-collection-of-free-microsoft-ebooks-ever-including-windows-8-1-windows-8-windows-7-office-2013-office-365-office-2010-sharepoint-2013-dynamics-crm-powershell-exchange-server-lync-2013-system-center-azure-cloud-sql.aspx

Wednesday, July 2, 2014

NetApp, CIFS, vFilers and FTP

I had a moment of sheer stupidity, dealing with vFilers and CIFS on our NetApp. I was trying to setup FTP to our CIFS on a non default vFiler and was getting no where fast. Tech Support for NetApp left a little something to be desired too, as they really could not seem to get what I was trying to do and they failed miserably calling me back with a proper response. I finally figured it out through trial and error, so I hope this helps someone.

The trick to this is to under stand that when you make another vFiler, you have to run all the commands for the vFiler (ftpd commands and cifs commands), under the context of the newly created vFiler and all the files that need to be edited will be edited under the new vFiler as well.

I logged into the NetApp and typed vfiler status then hit enter. This gave me the names of the running vFilers

TESTSAN1> vfiler status                  
vfiler0                                    running
vfiler_test                              running

I then change the context to the "test" vFiler. This is where my and it seems NetApp's Technical support's confusion came in. 


TESTSAN1>vfiler context vfiler_test


the prompt at this point changes to the new vFiler.

vfiler_test@TESTSAN1>                  



At this point you begin to make the changes that you need to enable FTP on your vFiler. I typed options ftpd to get a listing of all the possible configuration settings that could be made to the ftpd service.

vfiler_test@TESTSAN1> options ftpd                

ftpd.3way.enable             off                                
ftpd.anonymous.enable        off                            
ftpd.anonymous.home_dir                                  
ftpd.anonymous.name          anonymous              
ftpd.auth_style              ntlm                                 
ftpd.bypass_traverse_checking off                       
ftpd.dir.override            /vol/TEST_DATAVOL 
ftpd.dir.restriction         off                                  
ftpd.enable                  off                                     
ftpd.locking                 none                                 
ftpd.log.enable              on                                   
ftpd.log.filesize            512k                                
ftpd.log.nfiles              6                                     
ftpd.tcp_window_size         28960                     




I enabled the ftpd service first.

vfiler_test@TESTSAN1> options ftpd.enable on         





I then changed the FTP authentication style. For my environment ntlm is what we needed but you can use unix, ntlm and mixed.

vfiler_test@TESTSAN1> options ftpd.auth_style ntlm         


If you are using ntlm you have to specify the CIFS home directory in the /etc/cifs_homedir.cfg that is located in the etc$ share of the CIFS. In my case the path was \\TEST\etc$ I opened the path by using Windows Explorer and used a text editor to edited this file. Using the examples provided in the file I was able to edit the path in the file and saved the file to the same place in the etc$ share. Once you have specified the CIFS home directory you then run the cifs homedir load.


vfiler_test@TESTSAN1> cifs homedir load        



At this point you can make any other changes that you need such as ftpd.locking or the ftp.dir.override. I was now able to successfully connect to the CIFS and so long as I have proper NTFS permissions I can FTP files to the locations that I need to.