VMware VCM 5.3 - CONFIGURATION MANAGER SECURITY ENVIRONMENT REQUIREMENTS Instrukcja Użytkownika Strona 28

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 32
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 27
vCenter Configuration Manager Security Environment Requirements
TECHNICAL WHITE PAPER / 28
13.0 Proper Decommissioning
Hosts onto which VCM has been installed contain private keys, confidential credentials, and collection results. These
machines must be properly decommissioned before being discarded or used for other purposes.
13.1 An installation of VCM is properly decommissioned before its hardware is repur-
posed or retired
VCM hosts contain confidential data and credentials from managed machines, such as:
l
Collected data
l
File uploads
l
Private keys: Enterprise, Collector, Agent, and IIS HTTPS certificate
l
Managed machine login credentials
l
Proxy machine credentials
l
VCM Patching patch alternate source credentials
l
Secure Communication Session Cache(s)
l
Network Authority Account passwords
l
Collector and agent install kits
l
VCM license files
Proper erasure of these values from the respective machines is a requirement for decommissioning. In this context,
erasure involves more than deleting files. After transferring any sensitive data you wish to retain, best practices
recommend securely erasing any disks that stored confidential data. A utility such as sdelete1 can be used for this
purpose.
13.2 Collector and Agent private keys used for TLS are not copied between machines
VCM associates a unique machine identity with private keys used with TLS. Besides being difficult to copy securely,
copying a private key presents the risk of sharing it between more than one machine (a configuration that is not
supported). VMware recommends you generate a distinct public/private key pair for each collector during the
installation process. If TLS Mutual Authentication is being used, a distinct key pair should also be created for each
Agent when the Agent kit is installed.
Przeglądanie stron 27
1 2 ... 23 24 25 26 27 28 29 30 31 32

Komentarze do niniejszej Instrukcji

Brak uwag