Podcast
Questions and Answers
What does the VMware Cloud Foundation Developer Center primarily provide?
What does the VMware Cloud Foundation Developer Center primarily provide?
VMware Cloud Foundation requires all users to participate in the Customer Experience Improvement Program.
VMware Cloud Foundation requires all users to participate in the Customer Experience Improvement Program.
False
What should you do in the SDDC Manager UI to log out?
What should you do in the SDDC Manager UI to log out?
Click the logged-in account name and then click Log out.
The collected information during the Customer Experience Improvement Program does not personally identify any __________.
The collected information during the Customer Experience Improvement Program does not personally identify any __________.
Signup and view all the answers
Match the following sections with their descriptions:
Match the following sections with their descriptions:
Signup and view all the answers
How can a user deactivate CEIP after the initial login?
How can a user deactivate CEIP after the initial login?
Signup and view all the answers
The option to join the VMware Customer Experience Improvement Program is selected by default when logging into SDDC Manager for the first time.
The option to join the VMware Customer Experience Improvement Program is selected by default when logging into SDDC Manager for the first time.
Signup and view all the answers
What is the function of the API Explorer in the Developer Center?
What is the function of the API Explorer in the Developer Center?
Signup and view all the answers
To access the Customer Experience Improvement Program settings, navigate to the __________ tab in the SDDC Manager UI.
To access the Customer Experience Improvement Program settings, navigate to the __________ tab in the SDDC Manager UI.
Signup and view all the answers
What feature allows you to manage users and groups in VMware Cloud Foundation?
What feature allows you to manage users and groups in VMware Cloud Foundation?
Signup and view all the answers
The Backup feature does not allow scheduling for SDDC Manager.
The Backup feature does not allow scheduling for SDDC Manager.
Signup and view all the answers
What role does the Proxy Settings feature play in VMware Cloud Foundation?
What role does the Proxy Settings feature play in VMware Cloud Foundation?
Signup and view all the answers
VMware Aria Suite allows you to deploy VMware Aria Suite __________ and configure connections between workload domains.
VMware Aria Suite allows you to deploy VMware Aria Suite __________ and configure connections between workload domains.
Signup and view all the answers
Match the following features with their functionalities:
Match the following features with their functionalities:
Signup and view all the answers
Which feature allows integration with external servers for backups in VMware Cloud Foundation?
Which feature allows integration with external servers for backups in VMware Cloud Foundation?
Signup and view all the answers
Proxy Settings is used for configuring user roles in VMware Cloud Foundation.
Proxy Settings is used for configuring user roles in VMware Cloud Foundation.
Signup and view all the answers
What must be done before uploading CA-signed certificates using the legacy method?
What must be done before uploading CA-signed certificates using the legacy method?
Signup and view all the answers
VMware Cloud Foundation by default uses the legacy method for installing CA-signed certificates.
VMware Cloud Foundation by default uses the legacy method for installing CA-signed certificates.
Signup and view all the answers
What is the name of the PEM-encoded root CA certificate chain file that must be included in the top-level directory?
What is the name of the PEM-encoded root CA certificate chain file that must be included in the top-level directory?
Signup and view all the answers
To skip the certificate installation if validation fails, you can click ______.
To skip the certificate installation if validation fails, you can click ______.
Signup and view all the answers
Match the steps with the correct actions in installing third-party CA-signed certificates:
Match the steps with the correct actions in installing third-party CA-signed certificates:
Signup and view all the answers
What does the SDDC Manager UI provide to notify users about certificates?
What does the SDDC Manager UI provide to notify users about certificates?
Signup and view all the answers
The Certificates tab in the SDDC Manager UI displays the certificate authority name.
The Certificates tab in the SDDC Manager UI displays the certificate authority name.
Signup and view all the answers
What must be configured before performing certificate operations in SDDC Manager?
What must be configured before performing certificate operations in SDDC Manager?
Signup and view all the answers
SDDC Manager manages certificates by integrating with ________.
SDDC Manager manages certificates by integrating with ________.
Signup and view all the answers
Match the certificate status with its definition:
Match the certificate status with its definition:
Signup and view all the answers
Which of the following is NOT displayed on the Certificates tab?
Which of the following is NOT displayed on the Certificates tab?
Signup and view all the answers
Only self-signed certificates can be installed using SDDC Manager.
Only self-signed certificates can be installed using SDDC Manager.
Signup and view all the answers
What is necessary to replace self-signed certificates in SDDC Manager?
What is necessary to replace self-signed certificates in SDDC Manager?
Signup and view all the answers
To ensure secure connectivity, SDDC components require _____ certificates.
To ensure secure connectivity, SDDC components require _____ certificates.
Signup and view all the answers
What is the first step in managing Microsoft CA-Signed certificates using SDDC Manager?
What is the first step in managing Microsoft CA-Signed certificates using SDDC Manager?
Signup and view all the answers
What is the first step in the process of generating signed certificates?
What is the first step in the process of generating signed certificates?
Signup and view all the answers
It is recommended to use wildcard subject alternate names like *.example.com when generating certificates.
It is recommended to use wildcard subject alternate names like *.example.com when generating certificates.
Signup and view all the answers
What drop-down menu selection is required for generating certificates?
What drop-down menu selection is required for generating certificates?
Signup and view all the answers
You must click ________ to generate signed certificates after selecting the resource type.
You must click ________ to generate signed certificates after selecting the resource type.
Signup and view all the answers
Match the following actions with their corresponding steps in the process:
Match the following actions with their corresponding steps in the process:
Signup and view all the answers
What is the default method for installing third-party CA-signed certificates in VMware Cloud Foundation 4.5.1 and later?
What is the default method for installing third-party CA-signed certificates in VMware Cloud Foundation 4.5.1 and later?
Signup and view all the answers
You can install third-party certificates using both the new method and the legacy method.
You can install third-party certificates using both the new method and the legacy method.
Signup and view all the answers
What should you do after clicking the workload domain you want to view?
What should you do after clicking the workload domain you want to view?
Signup and view all the answers
To install the generated signed certificates for each component, select the check box and click ________.
To install the generated signed certificates for each component, select the check box and click ________.
Signup and view all the answers
Which of the following actions is NOT part of generating CSR files for target components?
Which of the following actions is NOT part of generating CSR files for target components?
Signup and view all the answers
What is the primary function of the SDDC Manager UI?
What is the primary function of the SDDC Manager UI?
Signup and view all the answers
Users can deactivate the onboarding tour in the SDDC Manager UI at any time.
Users can deactivate the onboarding tour in the SDDC Manager UI at any time.
Signup and view all the answers
What action allows users to rearrange widgets on the SDDC Manager dashboard?
What action allows users to rearrange widgets on the SDDC Manager dashboard?
Signup and view all the answers
To add a new widget to the dashboard, click the three dots in the upper right corner and select __________.
To add a new widget to the dashboard, click the three dots in the upper right corner and select __________.
Signup and view all the answers
Match the following dashboard features with their descriptions:
Match the following dashboard features with their descriptions:
Signup and view all the answers
Which of the following is a way to hide a widget on the SDDC Manager dashboard?
Which of the following is a way to hide a widget on the SDDC Manager dashboard?
Signup and view all the answers
The dashboard only displays a fixed set of widgets and cannot be customized.
The dashboard only displays a fixed set of widgets and cannot be customized.
Signup and view all the answers
Which of the following provides detailed information about all hosts in the Inventory section?
Which of the following provides detailed information about all hosts in the Inventory section?
Signup and view all the answers
Workload Management provides access to view workload domain details.
Workload Management provides access to view workload domain details.
Signup and view all the answers
What information is displayed collectively across all workload domains?
What information is displayed collectively across all workload domains?
Signup and view all the answers
The Hosts page includes information such as FQDN, host IP, and __________.
The Hosts page includes information such as FQDN, host IP, and __________.
Signup and view all the answers
Match the sections of Inventory with their functionalities:
Match the sections of Inventory with their functionalities:
Signup and view all the answers
What type of information is NOT included in the summary of workload domains?
What type of information is NOT included in the summary of workload domains?
Signup and view all the answers
Each host's CPU and memory utilization can be viewed collectively across all hosts.
Each host's CPU and memory utilization can be viewed collectively across all hosts.
Signup and view all the answers
The __________ page provides access to all workload domains.
The __________ page provides access to all workload domains.
Signup and view all the answers
What key details are provided about each host on the Hosts page?
What key details are provided about each host on the Hosts page?
Signup and view all the answers
What is the purpose of the VMware Customer Experience Improvement Program (CEIP)?
What is the purpose of the VMware Customer Experience Improvement Program (CEIP)?
Signup and view all the answers
How can a user deactivate the CEIP?
How can a user deactivate the CEIP?
Signup and view all the answers
The Customer Experience Improvement Program collects technical information about your organization’s use of VMware products and services regularly in association with your organization’s VMware ________.
The Customer Experience Improvement Program collects technical information about your organization’s use of VMware products and services regularly in association with your organization’s VMware ________.
Signup and view all the answers
Match the following sections of the Developer Center with their descriptions:
Match the following sections of the Developer Center with their descriptions:
Signup and view all the answers
What should you do to log out of the SDDC Manager UI?
What should you do to log out of the SDDC Manager UI?
Signup and view all the answers
VMware collects personal identification information through the Customer Experience Improvement Program.
VMware collects personal identification information through the Customer Experience Improvement Program.
Signup and view all the answers
What is displayed on the Certificates tab in the SDDC Manager UI?
What is displayed on the Certificates tab in the SDDC Manager UI?
Signup and view all the answers
You can activate or deactivate CEIP from the ________ tab in the SDDC Manager UI.
You can activate or deactivate CEIP from the ________ tab in the SDDC Manager UI.
Signup and view all the answers
Which option must be selected to apply changes made to CEIP settings?
Which option must be selected to apply changes made to CEIP settings?
Signup and view all the answers
Which key size options are available when generating a CSR?
Which key size options are available when generating a CSR?
Signup and view all the answers
The organizational unit field in the CSR generation process is used to identify specific persons involved in the organizational structure.
The organizational unit field in the CSR generation process is used to identify specific persons involved in the organizational structure.
Signup and view all the answers
What is the first step to access the workload domain page?
What is the first step to access the workload domain page?
Signup and view all the answers
To identify the legal registrant of the domain name in the certificate request, you must provide the name of your __________.
To identify the legal registrant of the domain name in the certificate request, you must provide the name of your __________.
Signup and view all the answers
Match the following CSR configuration fields with their descriptions:
Match the following CSR configuration fields with their descriptions:
Signup and view all the answers
Which authentication method must be enabled for the CertSrv web site?
Which authentication method must be enabled for the CertSrv web site?
Signup and view all the answers
The template display name must be 'VMware' when creating a certificate template.
The template display name must be 'VMware' when creating a certificate template.
Signup and view all the answers
What application is launched with the command 'Inetmgr.exe'?
What application is launched with the command 'Inetmgr.exe'?
Signup and view all the answers
To enable Basic Authentication, navigate to ______ under IIS.
To enable Basic Authentication, navigate to ______ under IIS.
Signup and view all the answers
Match the following steps with their corresponding actions in setting up a certificate template:
Match the following steps with their corresponding actions in setting up a certificate template:
Signup and view all the answers
What values must be configured in the Properties of New Template for the Compatibility tab?
What values must be configured in the Properties of New Template for the Compatibility tab?
Signup and view all the answers
You need to restart the Default Web Site for changes to take effect after enabling authentication.
You need to restart the Default Web Site for changes to take effect after enabling authentication.
Signup and view all the answers
What role does the CertSrv web site play?
What role does the CertSrv web site play?
Signup and view all the answers
After duplicating the Web Server template, you must configure the ______ tab.
After duplicating the Web Server template, you must configure the ______ tab.
Signup and view all the answers
Match the following components with their functions:
Match the following components with their functions:
Signup and view all the answers
What do you need to log in to the SDDC Manager UI?
What do you need to log in to the SDDC Manager UI?
Signup and view all the answers
The onboarding dashboard in SDDC Manager assists with configuring a healthy environment.
The onboarding dashboard in SDDC Manager assists with configuring a healthy environment.
Signup and view all the answers
What does the dashboard display after logging into the SDDC Manager UI?
What does the dashboard display after logging into the SDDC Manager UI?
Signup and view all the answers
To connect to the SDDC Manager appliance, you must use a supported __________.
To connect to the SDDC Manager appliance, you must use a supported __________.
Signup and view all the answers
Match the following elements of the SDDC Manager UI with their descriptions:
Match the following elements of the SDDC Manager UI with their descriptions:
Signup and view all the answers
How do you open the VMware Host Client?
How do you open the VMware Host Client?
Signup and view all the answers
It is unnecessary to have the password for the single-sign-on user when logging into SDDC Manager.
It is unnecessary to have the password for the single-sign-on user when logging into SDDC Manager.
Signup and view all the answers
What must be contained in the Basic Constraints field of root CA and intermediate certificates?
What must be contained in the Basic Constraints field of root CA and intermediate certificates?
Signup and view all the answers
All certificate files must be in Windows file format.
All certificate files must be in Windows file format.
Signup and view all the answers
What is the requirement for the server certificate in relation to Basic Constraints?
What is the requirement for the server certificate in relation to Basic Constraints?
Signup and view all the answers
The content of the .crt files must end with a __________ character.
The content of the .crt files must end with a __________ character.
Signup and view all the answers
Match the certificate types with their corresponding Basic Constraints value:
Match the certificate types with their corresponding Basic Constraints value:
Signup and view all the answers
Which of the following permissions is selected for the user account on the Microsoft Certificate Authority Template?
Which of the following permissions is selected for the user account on the Microsoft Certificate Authority Template?
Signup and view all the answers
The Microsoft Certificate Authority must be configured for basic authentication to establish a connection with SDDC Manager.
The Microsoft Certificate Authority must be configured for basic authentication to establish a connection with SDDC Manager.
Signup and view all the answers
Which URL format is required for the CA Server when configuring settings?
Which URL format is required for the CA Server when configuring settings?
Signup and view all the answers
What must be verified between the Microsoft Certificate Authority and the SDDC Manager appliance?
What must be verified between the Microsoft Certificate Authority and the SDDC Manager appliance?
Signup and view all the answers
It is acceptable to configure systems with different NTP sources.
It is acceptable to configure systems with different NTP sources.
Signup and view all the answers
To configure least privilege access, the ______ permission must be deselected.
To configure least privilege access, the ______ permission must be deselected.
Signup and view all the answers
What type of account should be used when entering the User Name in the CA settings?
What type of account should be used when entering the User Name in the CA settings?
Signup and view all the answers
Match the actions with their corresponding steps in configuring the Microsoft Certificate Authority.
Match the actions with their corresponding steps in configuring the Microsoft Certificate Authority.
Signup and view all the answers
To generate a CSR, you must select the check box for the resource type for which you want to ________.
To generate a CSR, you must select the check box for the resource type for which you want to ________.
Signup and view all the answers
Match the following components with their actions related to Certificate Authority:
Match the following components with their actions related to Certificate Authority:
Signup and view all the answers
Which role must be installed on the same machine as the Certificate Authority for proper configuration?
Which role must be installed on the same machine as the Certificate Authority for proper configuration?
Signup and view all the answers
The Examine Certificate Policy option is automatically available after installing the Certificate Authority.
The Examine Certificate Policy option is automatically available after installing the Certificate Authority.
Signup and view all the answers
What is the correct action to take after generating CSR files?
What is the correct action to take after generating CSR files?
Signup and view all the answers
You must create the issuing certificate template in Microsoft Certificate Authority before entering its name.
You must create the issuing certificate template in Microsoft Certificate Authority before entering its name.
Signup and view all the answers
What must a valid certificate template be configured on the Microsoft Certificate Authority to facilitate?
What must a valid certificate template be configured on the Microsoft Certificate Authority to facilitate?
Signup and view all the answers
What dialog box allows you to accept CA Server Certificate Details?
What dialog box allows you to accept CA Server Certificate Details?
Signup and view all the answers
To configure a connection between SDDC Manager and a Microsoft Certificate Authority, enter your service account ______.
To configure a connection between SDDC Manager and a Microsoft Certificate Authority, enter your service account ______.
Signup and view all the answers
To replace self-signed certificates with Microsoft CA-signed certificates, you can use ________ Manager.
To replace self-signed certificates with Microsoft CA-signed certificates, you can use ________ Manager.
Signup and view all the answers
Which step is NOT part of the process of installing Microsoft CA-Signed Certificates?
Which step is NOT part of the process of installing Microsoft CA-Signed Certificates?
Signup and view all the answers
Which of the following files must be included in the top-level directory when uploading CA-signed certificates using the legacy method?
Which of the following files must be included in the top-level directory when uploading CA-signed certificates using the legacy method?
Signup and view all the answers
The new method is the default for installing third-party CA-signed certificates in VMware Cloud Foundation 4.5.1.
The new method is the default for installing third-party CA-signed certificates in VMware Cloud Foundation 4.5.1.
Signup and view all the answers
What is the first step you must take to switch to legacy certificate management in the SDDC Manager UI?
What is the first step you must take to switch to legacy certificate management in the SDDC Manager UI?
Signup and view all the answers
To create a certificate bundle, the relevant certificate files must be assembled into a single __________ file.
To create a certificate bundle, the relevant certificate files must be assembled into a single __________ file.
Signup and view all the answers
Match the certificate management processes with their descriptions:
Match the certificate management processes with their descriptions:
Signup and view all the answers
What should you do if validation fails during the certificate installation process?
What should you do if validation fails during the certificate installation process?
Signup and view all the answers
You can skip certificate installation by clicking 'Remove' if validation fails.
You can skip certificate installation by clicking 'Remove' if validation fails.
Signup and view all the answers
What directory structure must be followed in the .tar.gz file for the root CA certificates?
What directory structure must be followed in the .tar.gz file for the root CA certificates?
Signup and view all the answers
A successful installation of all signed certificates requires you to click __________ after validation.
A successful installation of all signed certificates requires you to click __________ after validation.
Signup and view all the answers
What is the role of the PEM-encoded root CA certificate chain file in the legacy method?
What is the role of the PEM-encoded root CA certificate chain file in the legacy method?
Signup and view all the answers
What must be the value of the Basic Constraints field for root CA and intermediate certificates?
What must be the value of the Basic Constraints field for root CA and intermediate certificates?
Signup and view all the answers
Each sub-directory for component resources must contain a .csr file with a name that matches the resource hostname.
Each sub-directory for component resources must contain a .csr file with a name that matches the resource hostname.
Signup and view all the answers
What field value must the Server certificate (NSX_FQDN.crt) contain?
What field value must the Server certificate (NSX_FQDN.crt) contain?
Signup and view all the answers
Match the following certificate types with their requirements:
Match the following certificate types with their requirements:
Signup and view all the answers
What must be installed on the same server as the Microsoft Certificate Authority for SDDC Manager to function correctly?
What must be installed on the same server as the Microsoft Certificate Authority for SDDC Manager to function correctly?
Signup and view all the answers
SDDC Manager can request and sign certificates automatically if the Certificate Authority and Web Enrollment roles are installed on different machines.
SDDC Manager can request and sign certificates automatically if the Certificate Authority and Web Enrollment roles are installed on different machines.
Signup and view all the answers
What are the two primary roles required for SDDC Manager to manage certificates?
What are the two primary roles required for SDDC Manager to manage certificates?
Signup and view all the answers
To manage signed certificates, SDDC Manager requires __________ authentication configured on the Microsoft Certificate Authority.
To manage signed certificates, SDDC Manager requires __________ authentication configured on the Microsoft Certificate Authority.
Signup and view all the answers
Match the steps for adding roles to the Microsoft Certificate Authority server with their correct descriptions:
Match the steps for adding roles to the Microsoft Certificate Authority server with their correct descriptions:
Signup and view all the answers
What is the first step to add Basic Authentication to the Web Server?
What is the first step to add Basic Authentication to the Web Server?
Signup and view all the answers
You can perform certificate operations in SDDC Manager without configuring Microsoft CA first.
You can perform certificate operations in SDDC Manager without configuring Microsoft CA first.
Signup and view all the answers
What is necessary for SDDC Manager to request and sign certificates?
What is necessary for SDDC Manager to request and sign certificates?
Signup and view all the answers
To start the Add Roles and Features wizard, click __________ in the ServerManager.
To start the Add Roles and Features wizard, click __________ in the ServerManager.
Signup and view all the answers
Match the following components with their roles:
Match the following components with their roles:
Signup and view all the answers
Which of the following tasks is NOT performed by an administrator of a VMware Cloud Foundation system?
Which of the following tasks is NOT performed by an administrator of a VMware Cloud Foundation system?
Signup and view all the answers
VMware Cloud Foundation is intended for users who are new to virtualization technologies.
VMware Cloud Foundation is intended for users who are new to virtualization technologies.
Signup and view all the answers
Name one VMware technology covered in the VMware Cloud Foundation Administration Guide.
Name one VMware technology covered in the VMware Cloud Foundation Administration Guide.
Signup and view all the answers
The _________ document provides a high-level overview of the VMware Cloud Foundation product.
The _________ document provides a high-level overview of the VMware Cloud Foundation product.
Signup and view all the answers
Match the features of VMware Cloud Foundation with their corresponding functions:
Match the features of VMware Cloud Foundation with their corresponding functions:
Signup and view all the answers
What is one of the responsibilities involved in lifecycle management within VMware Cloud Foundation?
What is one of the responsibilities involved in lifecycle management within VMware Cloud Foundation?
Signup and view all the answers
The VMware Cloud Foundation Lifecycle Management document is focused on installation procedures.
The VMware Cloud Foundation Lifecycle Management document is focused on installation procedures.
Signup and view all the answers
What is the primary purpose of the API Explorer in the VMware Cloud Foundation Developer Center?
What is the primary purpose of the API Explorer in the VMware Cloud Foundation Developer Center?
Signup and view all the answers
It is possible to deactivate the Customer Experience Improvement Program in the Administration tab of SDDC Manager.
It is possible to deactivate the Customer Experience Improvement Program in the Administration tab of SDDC Manager.
Signup and view all the answers
What is the first step to upload CA-signed certificates using the legacy method?
What is the first step to upload CA-signed certificates using the legacy method?
Signup and view all the answers
What information does VMware collect through the Customer Experience Improvement Program?
What information does VMware collect through the Customer Experience Improvement Program?
Signup and view all the answers
To log out of the SDDC Manager UI, click the logged-in account name in the upper right corner and then click __________.
To log out of the SDDC Manager UI, click the logged-in account name in the upper right corner and then click __________.
Signup and view all the answers
The legacy method for installing certificates allows for the inclusion of unlimited intermediate certificates.
The legacy method for installing certificates allows for the inclusion of unlimited intermediate certificates.
Signup and view all the answers
Match the following actions with their corresponding outcomes:
Match the following actions with their corresponding outcomes:
Signup and view all the answers
What must be the name of the top-level directory within the .tar.gz file containing CA-signed certificates?
What must be the name of the top-level directory within the .tar.gz file containing CA-signed certificates?
Signup and view all the answers
Which of the following statements about the Customer Experience Improvement Program is incorrect?
Which of the following statements about the Customer Experience Improvement Program is incorrect?
Signup and view all the answers
Match the actions with their corresponding descriptions in the legacy certificate installation process:
Match the actions with their corresponding descriptions in the legacy certificate installation process:
Signup and view all the answers
Where do you find the option to activate or deactivate CEIP the first time you log into SDDC Manager?
Where do you find the option to activate or deactivate CEIP the first time you log into SDDC Manager?
Signup and view all the answers
What is the default action regarding CEIP when logging into SDDC Manager for the first time?
What is the default action regarding CEIP when logging into SDDC Manager for the first time?
Signup and view all the answers
Which file must reside inside the top-level directory of the .tar.gz file?
Which file must reside inside the top-level directory of the .tar.gz file?
Signup and view all the answers
VMware collects technical information about the use of its products as part of the __________.
VMware collects technical information about the use of its products as part of the __________.
Signup and view all the answers
VMware Cloud Foundation exclusively supports the legacy method for certificate installation.
VMware Cloud Foundation exclusively supports the legacy method for certificate installation.
Signup and view all the answers
What action should you take if validation fails during certificate installation?
What action should you take if validation fails during certificate installation?
Signup and view all the answers
To modify the preferences for legacy certificate management, go to the ______ section in the SDDC Manager UI.
To modify the preferences for legacy certificate management, go to the ______ section in the SDDC Manager UI.
Signup and view all the answers
What does the .tar.gz file creation require?
What does the .tar.gz file creation require?
Signup and view all the answers
Study Notes
VMware Cloud Foundation Administration Guide - Study Notes
-
Intended Audience: Cloud architects, infrastructure administrators, and cloud administrators familiar with VMware software and SDDC concepts. Requires experience with virtualization, software-defined data centers, VMware virtualization technologies (e.g., ESXi), software-defined networking (NSX), software-defined storage (vSAN), and networking concepts (Layer-2, Layer-3, BGP).
-
Licensing: Add licenses for component products.
-
Single Sign-On: Manage VMware Cloud Foundation users/groups and configure identity providers for single sign-on. Users log into SDDC Manager using vCenter Server Single Sign-On credentials.
-
Proxy Settings: Configure a proxy server for downloads, installations, and upgrades from the VMware Depot.
-
Depot Settings: Log into your Broadcom Support Portal account for bundle downloads, installations, and upgrades.
-
VMware Aria Suite: Deploy and configure VMware Aria Suite Lifecycle and connections between workload domains and VMware Aria Suite products.
-
Backup: Register an external SFTP server for SDDC Manager and NSX Manager backups. Configure SDDC Manager backup schedules.
-
VMware CEIP: Join or leave the VMware Customer Experience Improvement Program (CEIP) during first SDDC Manager login or from the Administration tab. VMware collects technical use information associating with organization license keys, but does not personally identify individuals.
-
Password Management: Manage password actions like rotation, updates, and remediation.
-
Certificate Authority: Integrate with a Microsoft Certificate Authority Server. Configure least privilege access for the account managing the Microsoft Certificate Authority Template. Modify SDDC Manager settings specifying Certificate Authority Type, CA Server URL, User Name, Password, and Template Name. Accept CA Server Certificate Details.
-
Developer Center: The VMware Cloud Foundation Developer Center provides API reference documentation for supported Public APIs and an API Explorer for direct API invocation.
SDDC Manager UI Procedures
-
Log Out: Click the logged-in account name in the upper right corner of the SDDC Manager UI and select "Log out".
-
View Certificate Information: In the SDDC Manager UI, navigate to Inventory > Workload Domains, click the target domain, and view certificate details (resource type, issuer, hostname, valid from/until, status, operation status) on the Certificates tab. This includes viewing details for each component resource.
-
Onboarding and Guided Tour: The SDDC Manager UI offers an onboarding dashboard, unless the "Don't show onboarding screen again" option is selected. A guided onboarding experience and SDDC Manager UI tour are available after onboarding. Access via web browser.
-
Dashboard: The Dashboard provides high-level views using widgets (e.g., Solutions, Workload Domains, Usage, Updates, History, CPU/Memory/Storage, Recent Tasks). Widgets can be rearranged, hidden, or added.
Configure VMware Cloud Foundation to Use Microsoft CA-Signed Certificates
-
Preparation: Prepare your Microsoft Certificate Authority for SDDC Manager certificate management. Verify connectivity, roles, authentication, certificate templates, least privileged accounts, and time synchronization.
-
Configuration: Configure a connection between SDDC Manager and the Microsoft Certificate Authority using service account credentials.
-
Installation: Replace VMware self-signed certificates with Microsoft CA-signed certificates using SDDC Manager. Access the SDDC Manager UI via web browser.
Install Third-Party CA-Signed Certificates Using Server Certificate and Certificate Authority Files (New Method)
-
Navigation: In the SDDC Manager UI, navigate to Inventory > Workload Domains, select the target domain, and click the Certificates tab.
-
Generate CSR Files: Generate CSR files for target components. Resolve issues or skip installation if validation fails.
-
Installation: Install signed certificates for each component.
Install Third-Party CA-Signed Certificates Using a Certificate Bundle (Legacy Method)
-
Prerequisites: VMware Cloud Foundation uses a new certificate management method by default (4.5.1 and later). Modify SDDC Manager preferences to use the legacy method if needed.
-
Preferences: Modify SDDC Manager UI settings to switch to legacy certificate management.
-
Directory Structure: Collect certificate files in a .tar.gz archive with a specific directory structure reflecting the workload domain and component resource hostnames. Crucial elements include matching root CA, intermediate certificates, and component resource hostnames with their corresponding .csr and .crt files (UNIX format). NSX certificates must follow specific criteria (e.g., Basic Constraints). Generate and download CSRs, verifying the structure. Request signed certificates from the third-party CA. Create the .tar.gz archive.
-
Upload and Install: In the SDDC Manager UI, upload the .tar.gz archive, and click Install Certificate. Ongoing progress is visible on the Certificates tab.
Add a Trusted Certificate to the SDDC Manager Trust Store
-
Error Resolution: If a component certificate was updated outside SDDC Manager, add the trusted certificate from the error message. Navigate to Inventory > Workload Domains, the target workload's Certificates tab, and click "review".
-
Method: Add trusted certificates through the SDDC Manager UI ("review" option on the Certificates tab) or via the VMware Cloud Foundation API. Access the SDDC Manager UI via web browser.
-
Logging In: Use SDDC Manager IP address or FQDN and single sign-on credentials to log into SDDC Manager. Use "https://FQDN" or "https://IP_address".
-
Accessing Components: Use the VMware Host Client (Actions > Open in VMware Host Client) to open the host selected from the SDDC Manager UI (Inventory > Hosts menu).
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on VMware Cloud Foundation administration with this quiz. Topics include licensing, user management, proxy settings, backup procedures, and integration with VMware Aria Suite. Perfect for students and professionals aiming to solidify their understanding of VMware Cloud Foundation.