13.07.2015 Views

Getting Started with vFabric Hyperic v.5.7 - VMware

Getting Started with vFabric Hyperic v.5.7 - VMware

Getting Started with vFabric Hyperic v.5.7 - VMware

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

By default, the <strong>vFabric</strong> <strong>Hyperic</strong> Server and the <strong>vFabric</strong> <strong>Hyperic</strong> Agent do not import untrustedcertificates unless you explicitly respond "yes" to the warning prompt described above. Note,however that both components can be configured to accept untrusted certificates automatically,<strong>with</strong> no warning. For security reasons, this practice is strongly discouraged. Check the values ofagent.setup.acceptUnverifiedCertificate (inAgentHome/conf/agent.properties) and accept.unverified.certificates inServerHome/conf/hq-server.conf.SSL Between a 5.0 Server and Pre-4.6 AgentsTo ensure backwards compatibility <strong>with</strong> pre-4.6 <strong>vFabric</strong> <strong>Hyperic</strong> Agents, the <strong>vFabric</strong> <strong>Hyperic</strong>Server upgrade procedure does not provide a mechanism for configuring the server to access auser-managed keystore.When a newly-upgraded <strong>vFabric</strong> <strong>Hyperic</strong> 4.6.x Server starts up, it generates a self-signed SSLcertificate.When a pre-4.6 <strong>vFabric</strong> <strong>Hyperic</strong> Agent first connects to a newly-upgraded <strong>vFabric</strong> <strong>Hyperic</strong> 4.6.xserver, its self-signed certificate is imported into the server's keystore.SSL and <strong>vFabric</strong> <strong>Hyperic</strong> Product Plugins<strong>vFabric</strong> <strong>Hyperic</strong> plugins that connect to managed products over SSL are updated to supportcertificate verification. To enable management of such products, it may be necessary tomanually import the target server's certificate into the agent keystore if the server's certificate isnot trusted. Affected plugins include:vSphereRabbitMQImport of the managed server's certificate is necessary only if the <strong>vFabric</strong> <strong>Hyperic</strong> Agent cannotverify the certificate. If the agent's keystore contains a CA cert and the managed server'scertificate has been signed by that CA, the agent will be able verify the certificate. Otherwise,you should import the certificate of the signing CA, which is preferable to simply importing themanaged server's certificate. If you are not sure of all of the CAs for signed certificates, youmight consider importing the certificates in your JRE cacert file, which contains certificates for avariety of common CAs.11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!