If you have VMware vCM (Configuresoft ECM, EMC Ionix SCM) and want to collect from ESX/ESXi you have to create a local user on the ESXi host and give that user Administrator permissions. That can be quite a daunting task if you have more than a handful of machines so I wrote the below powershell program that allows interactive use or automated use with a .CSV file.
---Start Script
Function NextUser
{
if ($newUser)
{
Write-host "Do you want to specify a new service account username or password? [y],[n]" -Fore Green
$continueUser = read-host
if ($continueUser -eq "y")
{
DoIt
}
if ($continueUser -eq "n")
{
DoItUsers
}
}
}
Function ExistingUsers
{
if ($newUser)
{
Write-host "Do you want to specify a new service account username or password? [y],[n]" -Fore Green
$continueUser = read-host
if ($continueUser -eq "n")
{
DoItUsers
}
if ($continueUser -eq "y")
{
DoIt
}
}
if (!$newUser)
{
DoIt
}
}
Function DoIt
{
write-host "Please enter the username that you would like to use for the vCM Service Account:" -Fore Green
$newUser = read-host
write-host "Please enter the password that will be used for the service account:" -Fore Green
$newPass = read-host
write-host "Ok, I am going to add $newUser with a password of $newPass to $connectedServer" -Fore Green
Start-Sleep -seconds 3
New-VMHostAccount -ID $newUser -password $newPass -Description "vCM Service Account"
write-host "Ok, I am now adding administrator permissions to the account we just created" -Fore Green
New-VIPermission -Role admin -Principal $newUser -Entity $connectedServer
write-host "Congratulations, you have added the new vCM service account successfully." -Fore Green
write-host "Would you like to configure another host? [y],[n]" -Fore Green
$nextHost = read-host
if ($nextHost -eq "y")
{
NextHost
}
if ($nextHost -eq "n")
{
write-host "Thanks, have a great day!" -Fore Green
exit
}
}
Function DoItUsers
{
write-host "Ok, I am going to add $newUser with a password of $newPass to $connectedServer" -Fore Green
Start-Sleep -seconds 3
New-VMHostAccount -ID $newUser -password $newPass -Description "vCM Service Account"
write-host "Ok, I am now adding admin permissions to the account we just created" -Fore Green
New-VIPermission -Role admin -Principal $newUser -Entity $connectedServer
write-host "Congratulations, you have added the new vCM service account successfully." -Fore Green
write-host "Would you like to configure another host? [y],[n]" -Fore Green
$nextHost = read-host
if ($nextHost -eq "y")
{
NextHost
}
if ($nextHost -eq "n")
{
write-host "Thanks, have a great day!" -Fore Green
}
}
Function NextHost
{
write-host "Please enter the FQDN of the server that you would like to connect to:" -Fore Green
$server = read-host
write-host "Connecting to $server using the credentials that you specified..." -Fore Green
Connect-VIServer -Server $server -User $existingUser -Password $existingPass
$connectedServer = Get-VMHost
write-host "Now using $connectedServer..." -Fore Green
if (!$connectedServer)
{
write-host ""
write-host "That host does not appear to be valid, please try again." Fore Yellow
NextHost
}
ExistingUsers
}
write-host ""
write-host ""
write-host "-- Welcome to my VMware vCM ESX/ESXi Service Account user deployment tool. This tool will allow you to easily deploy a vCM Service Account to your ESX/ESXi hosts -calebs71.blogspot.com --" -Fore Cyan
write-host ""
if (!$args[0])
{
write-host "Did you know that you can provide a CSV file with your server FQDN, ESX user, ESX Password, New Service User, New Service Password and automate the whole process?" -Fore Yellow
write-host ""
write-host "Example: vCM Service Acct on ESX.ps1 c:\list.csv"
write-host "FQDN,User,Password,SVCuser,SVCPass"
write-host "machine1.test,root,password,vcm_svc,password2"
write-host ""
write-host "Please enter a valid ESX/ESXi account with permissions to add a new user:" -Fore Green
$existingUser = read-host
write-host "Please enter the password:" -Fore Green
$existingPass = read-host
$connectedServer = Get-VMHost
if (!$connectedServer)
{
write-host ""
write-host "You are not connected to an ESX host..." -Fore Yellow
NextHost
}
write-host "You are currently connected to $connectedServer do you want to change servers? [y], [n]" -Fore Green
$response = read-host
if ($response -eq "y")
{
NextHost
}
if ($response -eq "n")
{
write-host "Continuing to use $connectedServer" -Fore Green
DoIt
}
}
if ($args[0])
{
$listMachines = import-csv $args[0]
if ($listMachines)
{
foreach ($MachineItem in $listMachines)
{
# write-host "FQDN : " $MachineItem.FQDN
# write-host "User : " $MachineItem.User
# write-host "Password : " $MachineItem.Password
# write-host "SVC User : " $MachineItem.SVCUser
# write-host "SVC Pass : " $MachineItem.SVCPass
# write-host "Connect-VIServer -Server "$MachineItem.FQDN " -User "$MachineItem.User " -Password "$MachineItem.Password
# write-host "New-VMHostAccount -ID "$MachineItem.SVCUser " -password "$MachineItem.SVCPass " -Description "vCM Service Account""
# write-host "New-VIPermission -Role admin -Principal " $MachineItem.SVCUser " -Entity " $MachineItem.FQDN
Connect-VIServer -Server $MachineItem.FQDN -User $MachineItem.User -Password $MachineItem.Password
New-VMHostAccount -ID $MachineItem.SVCUser -password $MachineItem.SVCPass -Description "vCM Service Account"
New-VIPermission -Role admin -Principal $MachineItem.SVCUser -Entity $MachineItem.FQDN
}
}
}
Friday, November 12, 2010
Wednesday, October 27, 2010
Error Removing Host from vSphere
I have a host (ESX 4.0) that I need to remove from one of my clusters but after putting it into maintenance mode and shutting it down the Remove option is grayed out. I found some references online that mention using the PowerCLI to manually remove the host but ran into a caveat that none of the other posts mentioned. When I ran the remove-vmhost command I got the following error: "The method is disabled by 'com.vmware.vcintegrity'". To get around this I had to take the disconnected host and remove it from the cluster and then run the remove-vmhost command to remove it from vSphere. I imagine that this is related to capacity issues on our old cluster but we are trying to move our blades and accompanying guests to a new cluster so HA and DRS is not high on the priority list.
Wednesday, October 20, 2010
Syntax to install HP CIM Providers on ESX4i
First, download and install the vCLI tools from vmware.com on your desktop.
Second, download the CIM Providers from HP.com
Third, Place host in Maintenance Mode and then scan the ESXi host for the Bulletin ID to be installed
c:\Program Files (x86)\VMware\VMware vSphere CLI\bin>vihostupdate.pl -server -username root - scan - bundle
should return a name like
hpq-esxi4.1uX-bundle-1.0 (note: this is case sensitive)
Fourth, install the bulletin
c:\program files (x86)\VMware\VMware vSphere CLI\bin>vihostupdate.pl -server -username root -bundle c:\hpq-esxi4.1uX-bundle-1.0.zip -install - bulletin hpq-esxi4.1uX-bundle-1.0
Fifth, reboot the host.
Second, download the CIM Providers from HP.com
Third, Place host in Maintenance Mode and then scan the ESXi host for the Bulletin ID to be installed
c:\Program Files (x86)\VMware\VMware vSphere CLI\bin>vihostupdate.pl -server
should return a name like
hpq-esxi4.1uX-bundle-1.0 (note: this is case sensitive)
Fourth, install the bulletin
c:\program files (x86)\VMware\VMware vSphere CLI\bin>vihostupdate.pl -server
Fifth, reboot the host.
Monday, September 27, 2010
A Truly Virtual ESX Environment
Here is a training environment that I am almost done building on my laptop. I am running Windows 7 x64 with 8GB RAM and VMware Workstation 7.
Guests are:
1. Openfiler NAS (iSCSI Target)
2. ESX 4.1 Host
3. ESX 4.1 Host
4. XP
5. vCenter Server
In the past I always put the vCenter box on the ESX hosts however 4.1 requires a 64 bit OS and that is not possible yet in a nested virtual environment.

Up next DRS needs configured and I will have a ready to roll ESX Cluster.
Guests are:
1. Openfiler NAS (iSCSI Target)
2. ESX 4.1 Host
3. ESX 4.1 Host
4. XP
5. vCenter Server
In the past I always put the vCenter box on the ESX hosts however 4.1 requires a 64 bit OS and that is not possible yet in a nested virtual environment.

Up next DRS needs configured and I will have a ready to roll ESX Cluster.
Issues Configuring VMware ESX HA
I got the following error when attempting to add my ESX hosts to a vCenter Cluster: "Cannot complete the configuration of the HA agent on the host. Misconfiguration in the host network setup." This was caused because I don't have a default gateway since it is a small test environment. It appears that you have to be able to ping your default gateway to enable HA. For my test environment I now have a VM that is a guest under my test ESX host that is on the DG IP. Problem solved.
Side note: If you have a VMware ESX cluster and one of the nodes fails and your default gateway is unavailable your HA will fail...
Side note: If you have a VMware ESX cluster and one of the nodes fails and your default gateway is unavailable your HA will fail...
Tuesday, September 21, 2010
SSRS 2008 Domain User Issue
Scenario: I have a new SQL Server Reporting Services 2008 R2 x64 instance that works if you are the local administrator. Once I switch to another user who is an implied administrator via an AD group I get the following error when attempting to access SSRS in a browser:
"User 'TESTDOM\user' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed."
The user is a member of the domain admins group which is obviously a member of the local admins. Also if I right click on IE8 and say "Run As Administrator" it works. The quick fix is to disable the UAC. If you don't want to do that then just do the below:
1. Launch IE8 using "Run As Administrator" and in SSRS (http://servername/Reports) click on Site Settings. In Site Settings navigate to "Security" and add your user "TESTDOM\user" as a System Administrator.
2. Click on "Home" and then "Folder Settings". Now add your account again this time assigning yourself all the roles (Browser, Content Manager, My Reports, Publisher, Report Builder).
3. Close Administrative IE session and open a normal IE8 window and your SSRS should work.
"User 'TESTDOM\user' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed."
The user is a member of the domain admins group which is obviously a member of the local admins. Also if I right click on IE8 and say "Run As Administrator" it works. The quick fix is to disable the UAC. If you don't want to do that then just do the below:
1. Launch IE8 using "Run As Administrator" and in SSRS (http://servername/Reports) click on Site Settings. In Site Settings navigate to "Security" and add your user "TESTDOM\user" as a System Administrator.
2. Click on "Home" and then "Folder Settings". Now add your account again this time assigning yourself all the roles (Browser, Content Manager, My Reports, Publisher, Report Builder).
3. Close Administrative IE session and open a normal IE8 window and your SSRS should work.
Wednesday, September 1, 2010
Removing BitLocker on Windows 7
When attempting to remove BitLocker drive encryption from your Windows 7 machine you would naturally right click on the drive in question and say "Manage BitLocker". This brings up a couple options but none of them will allow you to remove BitLocker and decrypt the drive. What you need to do is go Control Panel > System and Security > BitLocker Drive Encryption and select the option to remove BitLocker.
Labels:
BitLocker,
decrypting drive,
removing bitlocker,
Windows 7
Subscribe to:
Posts (Atom)