Monday, January 31, 2011

ESXi

To follow up on Call "UserDirectory.RetrieveUserGroups" for object "ha-user-directory" on ESXi "" failed.

YEP! Changing the LDAP SSL certificate requirements from "required" to uh.. not.. made the error go away on our domain.

Computer configuration - Policies - Windows Settings - Security Settings - Local Policies/Security Options - Domain Controller: LDAP server signing requirements (None/Require signing/Undefined[which is the same as None])


A quick google search brought up this likewise discussion, where a member of likewise states that they don't support ldaps.


The ticket for me was the "LDAP error code: 8 (Strong(er) authentication required)" line in /host/messages. No verbose logging was required to get to the root of the problem.
Good enough for me and my crew.

Friday, January 28, 2011

ESXi Active Directory Lookup failure

Call "UserDirectory.RetrieveUserGroups" for object "ha-user-directory" on ESXi "" failed.

Wha?

ESXi 4.1.0 v320137, evaluation license

Looks like a known bug: http://communities.vmware.com/message/1688839.

Note my message there at the bottom that says that the actual authentication and user/group add/del works fine... you just have to manually type the users/groups.

Here's my traceback in /host/messages:

Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.905 FFDC2B90 verbose 'UserDirectory' opID=C6A12DE4-00000176] Searching for LDAP server for AD
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.909 FFDC2B90 verbose 'UserDirectory' opID=C6A12DE4-00000176] Using LDAP base dn: DC=ad,DC=mycompany,DC=com
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.910 FFDC2B90 verbose 'SysCommandPosix' opID=C6A12DE4-00000176] ForkExec '/bin/kinit', pid 30416, rc 0
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.959 FFDC2B90 error 'UserDirectory' opID=C6A12DE4-00000176] LDAP error code: 8 (Strong(er) authentication required)
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.959 FFDC2B90 error 'App' opID=C6A12DE4-00000176] Error accessing directory: Can't bind to LDAP server for domain: AD
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.959 FFDC2B90 info 'App' opID=C6A12DE4-00000176] AdapterServer caught exception: 68130fd8
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 info 'Vmomi' opID=C6A12DE4-00000176] Activation [N5Vmomi10ActivationE:0x68094b10] : Invoke done [retrieveUserGroups] on [vim.UserDirectory:ha-user-directory]
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg domain:
Jan 29 00:43:07 Hostd: "AD"
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg searchStr:
Jan 29 00:43:07 Hostd: ""
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg belongsToGroup:
Jan 29 00:43:07 Hostd: (null)
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg belongsToUser:
Jan 29 00:43:07 Hostd: (null)
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg exactMatch:
Jan 29 00:43:07 Hostd: false
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg findUsers:
Jan 29 00:43:07 Hostd: true
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 verbose 'Vmomi' opID=C6A12DE4-00000176] Arg findGroups:
Jan 29 00:43:07 Hostd: true
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 info 'Vmomi' opID=C6A12DE4-00000176] Throw vmodl.fault.SystemError
Jan 29 00:43:07 Hostd: [2011-01-29 00:43:07.960 FFDC2B90 info 'Vmomi' opID=C6A12DE4-00000176] Result:
Jan 29 00:43:07 Hostd: (vmodl.fault.SystemError) {
Jan 29 00:43:07 Hostd: dynamicType = ,
Jan 29 00:43:07 Hostd: faultCause = (vmodl.MethodFault) null,
Jan 29 00:43:07 Hostd: reason = "Error accessing directory",
Jan 29 00:43:07 Hostd: msg = "",
Jan 29 00:43:07 Hostd: }


Also seems from the logs that there's something running in the background using the credentials that added the host to AD for some other lookup. Not sure how I feel about that one.

I'll see if I can devote any more time to this next week. As it is, it just looks to be an obnoxious bug...

Wednesday, January 12, 2011

ESXi log file location

Damned if I had a brain freeze today and couldn't remember the url path where ESXi has it's log files:
https://hostname/host


There.

Tuesday, December 7, 2010

New VMware Licensing (updated)

ESX licensing doesn't look to be changing. The quick word back from our rep is:

"We will be changing how some of the management products are licensed (moving from socket-based to vm-based)."

New Cluster Voting


Thursday, December 2, 2010

New vSphere licensing on the way?

I heard a scoop that VMware has hired the individual that was in charge of Oracle's per core licensing model... So there's a good chance that vSphere will see licensing changes. We'll see if my vmware contacts can confirm anything.

Tuesday, November 9, 2010

Will Steve drink the kool-aid?

A co-worker passed on this well written letter to Apple from UW-Madison to support virtualization, especially in a post Xserve world. Drink Me

Which made me remember a bit of research I did for a potential client in Jul 2009. Below is the email in full:

---
I got a question about VMWare's enterprise product line on Apple Hardware (as this is a requirement to run OSX). Looks like there was a recent thread started in a few places online talking about this. Here is the thread, excerpts below. http://communities.vmware.com/thread/213146

From a VMWare employee:
vSphere support for xServe requires supporting UEFI. This capability is on VMware's roadmap for a future release. Sorry, I can't give you an ETA but hope that helps.
Thoughts from me:
2011? 2012? I wouldn't think sooner.

From a VMWare customer:
So, though the Parallels Server Virtualization Product IS more Serverish than running Fusion, it is still not Bare Metal, and definately NOT VSphere.

Info from me on this:
http://www.parallels.com/products/server/mac/features/ "Parallels Server for Mac" requires OSX to be installed on the hardware. At one point in the marketing on their site they call it a "bare-metal" solution but it DOES require a base install of OSX to run the APPLICATION "Parallels Server for Mac".
The single biggest thing that precludes us from looking at other hypervisor solutions is memory optimization. ANY other hypervisor solution (HyperV, Xen, xVM, Parallels, etc..) do not have the ability to oversubscribe memory. When the same piece of physical hardware can comfortably host 5 Hyper-V VMs or 20 ESX VMs I'll choose ESX.

For "illegal" use of vSphere on xServe hardware we've got this jem from that thread:
The Xserves DO NOT have BIOS emulation in the EFI firmware like the desktops do (http://community.brighton.ac.uk/ajd9/weblog/15666.html).
Thoughts from me:
So you could get ESX on a laptop or MacPro but not an XServe.

More thoughts from the peanut gallery:
For an enterprise-grade solution I would want to wait for ESX to run on apple hardware or for Apple to allow OSX to run on ESX legally. Anything else would not have the same level of redundancy and support that comes along with an enterprise-grade price tag.

---

In a post Xserve world, what are Apple enterprise clients left with? Currently nothing.