VMware and SSL Settings: How to Stay Safe

By Edward L. Haletky, CIO.com |  Virtualization, Secure Socket Layer, VMware 12 comments

Proper use of Secure Socket Layer security is a mystery even to many virtual server administrators, but it seems to be mysterious even to the developers who build it into their products-whether they know it or not.

The VMware v3.5.x Configuration Guide states that SSL is not enabled in the virtualization software by default. It claims that the initial contact between components is protected but no further communication.

While my previous blog on the SSL MiTM attack refutes even the first statement, I didn't mention that the data being communicated along with those early packets is mainly credential information, which should be protected. I also didn't go into whether we need to protect the rest.

Before we can answer that question we need to understand how the traffic is transferred and between what points. There are at least two systems involved, if not three. So a quick summary of communication is needed.

The first connection is between the VMware Infrastructure (VIC), Remote CLI (RCLI), or VI SDK client and the Virtual Center Management Server (VCMS).

The second connection depends on what you plan on doing. You could also need to connect from VCMS to the virtualization host. Alternatively, you may be connecting from VIC, RCLI, or VI SDK direct to the virtualization host.

Now throw in all the other management tools such as Life Cycle Manager, Stage Manager, and Lab Manager and you have even more connection points.

After credential data is transferred to the VCMS or host, anything else that is transferred could be construed as information leakage. Specifically, you have machine names, configurations, network names and configurations, storage names and configurations, advanced options and even security settings data.

The configuration guide does state you need to install new certificates and enable certificate checking. This is one of the better suggestions. From where do you get your certificates?

If you are a large organization, involved with HIPPA, or the government, you may already have a certificate from a known certificate authority like RSA for example. But if you are an SMB or small organization, these certificates are expensive.

The configuration guide further states that self-signed certificates are vulnerable, which they are. Yet, the guide covers a small aspect of the entire picture (namely ESX). There needs to be a concise guide on how to replace certificates that are used to manage the entire virtual infrastructure.

There also should be some sort of map that explains how the management tools interface with your virtual infrastructure. Knowing this will allow you to know how to further protect your system.

However, it is unclear if after credentials are sent (if even with new certificates) if subsequent data is also sent over SSL. The implication is that it is, but just replacing a certificate would only further protect the items sent over SSL (namely credentials) and not subsequent data.

The best suggestion is to replace the SSL certificates in use. However, you have to understand the management data pathways and protect your management workstations and servers as well.

Virtualization expert Edward L. Haletky is the author of "VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers," Pearson Education (2008.) He recently left Hewlett-Packard, where he worked in the Virtualization, Linux, and High-Performance Technical Computing teams. Haletky owns AstroArch Consulting, providing virtualization, security, and network consulting and development. Haletky is also a champion and moderator for the VMware discussion forums, providing answers to security and configuration questions.

12 comments

    ChristopherBickner
    ChristopherBickner 10 weeks ago
    Very interesting discussion glad that I came across such informative post. Keep up the good work friend. Glad to be part of your net community.
    Ellam Mora
    Ellam Mora 21 weeks ago
    Taneja Group's recent survey on virtual server storage practices revealed users of virtual infrastructure are facing some significant storage capacity, performance, provisioning and management issues. wheretofindcoupons.net Taken together, these considerably drive up the cost and risk of virtual server deployments. Fortunately, innovative storage vendors like HP are helping
    VMware looks like a very good alternative, but has anyone here actually used it and can give some first-hand feedback on it ?
    Jai Geeta Kodamanchili
    Jai Geeta Kodamanchili 22 weeks ago
    It also includes direct communication between a browser and the ESX host, *and* remote display and remote device connections initiated by remote clients. The only exception to this are management connections initiated from the same machine over the loopback interface, which are allowed to use unencrypted SOAP over HTTP rather than HTTPS
    Android Tablet
    Android Tablet 24 weeks ago
    VMware is pretty useful to try out new operating systems like Mac OSX under Windows, if only there was an Android Tablet version.
    Fred_1
    Fred_1 24 weeks ago
    VMware sounds great and all that, but this post was made almost 3 years ago. Is there something better out now? I'm trying to find the best solution for this. - Zygor
    Anonymous 46 weeks ago
    you have to change your password frequently or configurate the ip, so only you have access to it
    Anonymous 48 weeks ago
    I'm a developer at VMware. Here's my attempt to clarify exactly how we use SSL. Oyunlar
    Anonymous 1 year ago
    Interesting article. Thanks!!
    Anonymous 1 year ago
    The only way to stay safe is to stay up to date.Torrent divx
    Anonymous 3 years ago
    [Disclaimer: I am an employee at VMware but opinions expressed here are my own and do not necessarily reflect those of my employer.]I'm a developer at VMware. Here's my attempt to clarify exactly how we use SSL. All network communication with the VMware APIs/interfaces in VI3 (ESX 3.0, 3.5, VC 2.0, 2.5 etc. as well as Server 2.0) is SSL encrypted. This includes all SDK and management agent communication with VirtualCenter and the Virtual Infrastructure client, which uses SOAP over HTTPS. It also includes direct communication between a browser and the ESX host, *and* remote display and remote device connections initiated by remote clients. The only exception to this are management connections initiated from the same machine over the loopback interface, which are allowed to use unencrypted SOAP over HTTP rather than HTTPS.
    Anonymous 1 year ago in reply to Anonymous
    The only exception to this are management connections initiated from the same machine over the loopback interface, which are allowed to use unencrypted SOAP over HTTP rather than HTTPS. Oyunlar

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      VirtualizationWhite Papers & Webcasts

      White Paper

      AppAssure vs Backup Exec

      In this new Lab Report, openBench Labs examines AppAssure backup and replication software v4.7 with Symantec Backup Exec 2010 R2. AppAssure implements changed-block tracking technology to provide data protection for both virtual and physical servers in specific OS environments. In contrast, Backup Exec 2010 R2 uses traditional file-based backup to promote compatibility with the largest number of operating systems.

      White Paper

      Top 5 Requirements for Backup of Virtual and Physical Servers - Greg Shields, Microsoft MVP

      Reports by leading industry analysts like Gartner, IDC and Concentrated Technology suggest virtual servers in 2011 will eclipse physical servers in total server deployments. The majority of today's business computing environments already have both virtual and physical servers at the same time.

      White Paper

      Lab Report - Optimizing VM Backup for VMware and Hyper-V

      Data centers are becoming more difficult to manage and protect as more data and applications are moved into virtual environments. Adding fuel to the fire, CIOs must now deal with corporate mandates to build an IT infrastructure that scales to unknown demand levels and provides service assurance for fluctuating conditions that cannot be accurately projected. The solution is a transition to a private cloud characterized by a hypervisor-independent Virtual Infrastructure (VI).

      Webcast On Demand

      Managing Enterprise Mobility Costs

      Mobile employees, especially those traveling internationally, were spending time and resources finding and making connections. Roaming costs were out of control. The IT Administrator at The Hay Group tells you how he got more control over these costs, providing management with predictable budgets and insights while ensuring employee productivity.

      Sponsor: iPass

      White Paper

      Forrester Total Economic Impact (TEI) Case Study - Oracle

      In this paper, Forrester Consulting examines the total economic impact and potential return on investment (ROI) realized by three Enterprise organizations as they virtualized mission-critical Oracle databases on the VMware vSphere platform. The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of VMware vSphere on their organizations.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question