Red Hat LINUX VIRTUAL SERVER 5.1 - ADMINISTRATION Instrukcja Użytkownika Strona 27

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 38
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 26
VMware, Inc. 27
Chapter 3 Using the vSphere Command-Line Interface
Using Microsoft Windows Security Support Provider Interface
The--passthroughauthoption,whichisavailableifyourunvCLIcommandsfromaMicrosoftWindows
system,allowsyoutousetheMicrosoftWindowsSecuritySupportProviderInterface(SSPI).SeetheMicrosoft
WebsiteforadetaileddiscussionofSSPI.
Youcanuse--passthroughauthtoestablishaconnectionwithavCenterServer
system(vCenterServer
systemorVirtualCenterServer3.5Update2orlater).Aftertheconnectionhasbeenestablished,authentication
forthevCenterServersystemoranyESXisystemitmanagesisnolongerrequired.Using
--passthroughauthpassesthecredentialsoftheuserwhorunsthecommandtothetargetvCenterServer
system.Noadditionalauthenticationisrequirediftheuserwhorunsthecommandisknownbythecomputer
fromwhichyouaccessthevCenterServ ersystemandbythecomputerrunningthevCenterServersoftware.
IfvCLIcommandsandthevCenterServersoftwarerunonthesamecomputer,theuser
needsonlyalocal
accounttorunthecommand.IfthevCLIcommandandthevCenterServersoftwarerunondifferent
machines,theuserwhorunsthecommandmusthaveanaccountinadomaintrustedbybothmachines.
SSPIsupportsseveralprotocols.Bydefault,itselectstheNegotiateprotocol,where
clientandservertryto
findaprotocolthatbothsupport.Youcanuse--passthroughauthpackagetoexplicitlyspecifyaprotocol
thatissupportedbySSPI.Kerberos,theWindowsstandardfordomainlevelauthentication,isused
frequently.IfthevCenterServersystemisconfiguredtoacceptonlyaspecificprotocol,specifying
theprotocol
with --passthroughauthpackagemightberequiredforsuccessfulauthentication.Ifyouuse
--passthroughauth,youdonothavetospecifyauthenticationinformationbyusingotheroptions.
Example
esxcli --server <vc_server> --passthroughauth --passthroughauthpackage “Kerberos”
--vihost my_esx network ip interface list
vicfg-mpath.pl --server <vc_server> --passthroughauth --passthroughauthpackage “Kerberos”
--vihost my_esx --list
ConnectstoaserverthatissetuptouseSSPI.Whenatrusteduserrunsthecommand,thesystemcallsthe
ESXCLIcommandorvicfg-mpathwiththe--listoption.Thesystemdoesnotpromptforausernameand
password.
vCLI and Lockdown Mode
LockdownmodedisablesalldirectrootaccesstoESXimachines.TomakechangestoESXisystemsin
lockdownmodeyoumustgothroughavCenterServersystemthatmanagestheESXisystem.Youcanusethe
vSphereClientorvCLIcommandsthatsupportthe--vihostoption.Thefollowingcommandscannotrun
againstvCenterServersystemsandarethereforenotavailableinlockdownmode:
vicfg-snmp
vifs
vicfg-user
vicfg-cfgbackup
vihostupdate
vmkfstools
vicfg-ipsec
IfyouhaveproblemsrunningacommandonanESXihostdirectly(withoutspecifyingavCenterServer
target),checkwhetherlockdownmodeisenabledonthathost.SeethevSphereSecuritydocumentation.
Common Options for vCLI Execution
Table 32listsoptionsthatareavailableforallvCLIcommandsinalphabeticalorder.Thetableincludes
optionsforuseonthecommandlineandvariablesforuseinconfigurationfiles.
IMPORTANTForconnections,vCLIsupportsonlytheIPv4protocol,nottheIPv6protocol.Youcan,however,
configureIPv6on thetargethostwithseveralofthenetworkingcommands.
Przeglądanie stron 26
1 2 ... 22 23 24 25 26 27 28 29 30 31 32 ... 37 38

Komentarze do niniejszej Instrukcji

Brak uwag