MC1903's Posts

Are you aware of "ESXiArgs Ransomware". You really do not want to put your ESXi hosts on the public Internet.
Did you ever manage to expand this workload domain stretched cluster? Is your hardware VCF on VxRail or VCF on vSAN ready node? The operation is supported by API only. From the VMware Cloud Founda... See more...
Did you ever manage to expand this workload domain stretched cluster? Is your hardware VCF on VxRail or VCF on vSAN ready node? The operation is supported by API only. From the VMware Cloud Foundation - Planning Management Operations v4.3 training notes:  
Hello Piotr; It's Martin from the other group. I need to validate the SHA256 with a known good from the vendor in order to run it outside of my lab sandbox.
Hi, Here's a doc I created when working through this for the first time. Hope it helps. M
Hi, I would like to run the vCert.sh tool on a vCenter Server that I care about, but I would like to confirm that the download has not been tainted first; as I was pointed to the file on a non-VMwar... See more...
Hi, I would like to run the vCert.sh tool on a vCenter Server that I care about, but I would like to confirm that the download has not been tainted first; as I was pointed to the file on a non-VMware site. Would anyone in GSS be able to confirm the official SHA256 hash for vCenter 7.0 Certificate Management Utility (4.7.0) vCert.sh file? #!/bin/bash #------------------------------ # Script to manage vCenter SSL certificates. # # Author: [REDACTED] #------------------------------ #------------------------------ # for debugging purposes only, uncomment the following line: # export PS4='+[${SECONDS}s][${BASH_SOURCE}:${LINENO}]: ${FUNCNAME[0]:+${FUNCNAME[0]}(): }'; set -x; # to debug run: ./vCert 2>vCert-debug.txt #------------------------------ VERSION="4.7.0" #------------------------------   I would be most grateful. Cheers, M  
Fantastic. Thank you. M
Thank you, this is a great idea! I genuinely hope this will facilitate some level of two way discussion between customer/partners and VMware; and not the usual one sided conversation that is VMTN. ... See more...
Thank you, this is a great idea! I genuinely hope this will facilitate some level of two way discussion between customer/partners and VMware; and not the usual one sided conversation that is VMTN. It would be fantastic if you could persuade other VMware product managers to do the same for their product areas! M
Initial VCF 5.0.0 SDDC Manager feedback... Once again, please add a way to acknowledge and permanently silence these annoying banners. This is a clean VCF 5.0 install, so why are you giving me crit... See more...
Initial VCF 5.0.0 SDDC Manager feedback... Once again, please add a way to acknowledge and permanently silence these annoying banners. This is a clean VCF 5.0 install, so why are you giving me critical information on upgrading to VCF 5.0? Also, why is this banner not cancellable like the others? The continual forced product marketing around subscription is getting tiresome for me. If I have got to the stage of installing VCF in my environment, I am more than aware of the licensing options available to me. Thanks M    
I managed to accidently power down one of my management domain ESXi hosts and realised that SDDC Manager does not report this as an issue? Should it? The only 'tell' I can find in SDDC Manag... See more...
I managed to accidently power down one of my management domain ESXi hosts and realised that SDDC Manager does not report this as an issue? Should it? The only 'tell' I can find in SDDC Manager is the 0% CPU & 0% Memory usage. Hardly ideal.        
Apologies for the delayed response. @RajeevVCP4 - I didn't even think to try them as a normal vSAN Cluster; very good shout!  @mannharry - I did see KB89738; I didn't have mismatched vSAN disk size... See more...
Apologies for the delayed response. @RajeevVCP4 - I didn't even think to try them as a normal vSAN Cluster; very good shout!  @mannharry - I did see KB89738; I didn't have mismatched vSAN disk sizes across the nested hosts. @AbbedSedkaoui - Yes; I think the boot disk size was the problem. It's a shame that the errors SDDC manager kicks out are so vague. Thank you all for your suggestions.  I blew the entire VCF 4.4 environment away and will be rebuild as VCF 4.5 (If I can get past another issue with Cloud Builder; If not, I fear another VMTN post soon). Cheers all. M
Hi, I am trying to complete a Add VI Workload Domain (vSAN) in my Lab with 4 nested ESXi Hosts and I am getting stopped at the subtask "Validate vSAN disks for ESXi Host(s)" with this error: Des... See more...
Hi, I am trying to complete a Add VI Workload Domain (vSAN) in my Lab with 4 nested ESXi Hosts and I am getting stopped at the subtask "Validate vSAN disks for ESXi Host(s)" with this error: Description Validate vSAN disks for ESXi Host(s) Progress Messages vSAN Disks Validation on the ESXi Host(s) failed: ESXi Host vcf01-m01-esx05.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one), ESXi Host vcf01-m01-esx06.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one), ESXi Host vcf01-m01-esx07.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one), ESXi Host vcf01-m01-esx08.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one) Error Message: vSAN Disks Validation on the ESXi Host(s) failed: ESXi Host vcf01-m01-esx05.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one), ESXi Host vcf01-m01-esx06.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one), ESXi Host vcf01-m01-esx07.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one), ESXi Host vcf01-m01-esx08.vcf.momusconsulting.com does not have valid boot disk (Expecting at least one) Remediation Message: Make sure that ESXi Hosts disks are eligible for use by vSAN Reference Token: BJ47Q8 Cause:   SDDC Manager Version: 4.5.0 ESXi Version: 7.0.3-20328353   My nested ESXi hosts are booted and thus have valid boot disks, so I am lost as to why this error is being kicked out. Each host has 4 disks. 1 x 12GB boot disk, 1 x 100Gb vSAN Cache disk & 2 x 250Gb vSAN Capacity disks. The vSAN capacity disks have been tagged as IsCapacityFlash =1. I have tried manually creating the /store/.capacityflash.json files on each host, as per https://kb.vmware.com/s/article/52586    [root@vcf01-m01-esx05:/vmfs/volumes/631a0f8a-7e2b33b5-a1fb-005056a94fe1/store] vdq -q > /store/.capacityflash.json [root@vcf01-m01-esx05:/vmfs/volumes/631a0f8a-7e2b33b5-a1fb-005056a94fe1/store] cat /store/.capacityflash.json [ { "Name" : "naa.6000c29580337e490eeef16ca096f84c", "VSANUUID" : "", "State" : "Ineligible for use by VSAN", "Reason" : "Has partitions", "IsSSD" : "1", "IsCapacityFlash": "0", "IsPDL" : "0", "Size(MB)" : "12288", "FormatType" : "512n", "IsVsanDirectDisk" : "0" }, { "Name" : "naa.6000c290d6ff5b9c627918f381ab94f0", "VSANUUID" : "", "State" : "Eligible for use by VSAN", "Reason" : "None", "IsSSD" : "1", "IsCapacityFlash": "1", "IsPDL" : "0", "Size(MB)" : "256000", "FormatType" : "512n", "IsVsanDirectDisk" : "0" }, { "Name" : "naa.6000c29dc55120c5120f4ea2b0819a08", "VSANUUID" : "", "State" : "Eligible for use by VSAN", "Reason" : "None", "IsSSD" : "1", "IsCapacityFlash": "1", "IsPDL" : "0", "Size(MB)" : "256000", "FormatType" : "512n", "IsVsanDirectDisk" : "0" }, { "Name" : "naa.6000c292c78fe2a69bd08fafb498c4c6", "VSANUUID" : "", "State" : "Eligible for use by VSAN", "Reason" : "None", "IsSSD" : "1", "IsCapacityFlash": "0", "IsPDL" : "0", "Size(MB)" : "102400", "FormatType" : "512n", "IsVsanDirectDisk" : "0" } ] [root@vcf01-m01-esx05:/vmfs/volumes/631a0f8a-7e2b33b5-a1fb-005056a94fe1/store]   Additionally; what is the Reference Token: BJ47Q8 referring to? Is there a lookup / log I can correlate? Any help or suggestions very much welcomed. Cheers, M  
Additional feedback on the Add VI Workload wizard. If on the license selection step there are not enough licenses, please have it rescan the available licenses every few seconds (or add a license re... See more...
Additional feedback on the Add VI Workload wizard. If on the license selection step there are not enough licenses, please have it rescan the available licenses every few seconds (or add a license rescan button). I opened another SDDC manager session, installed additional vSphere licenses; but the wizard does not pick the new ones up. I had to restart the whole process, which is a real pain in the rear end. If you could allow the wizard to be saved at any point and resumed later, that would be amazing. Thx. M
Some feedback on SDDC Manager in VCF 4.5.0. Please can you add an 'acknowledge' option to silence the red/warning and blue/notification banners that keep popping up every few minutes? I am fed ... See more...
Some feedback on SDDC Manager in VCF 4.5.0. Please can you add an 'acknowledge' option to silence the red/warning and blue/notification banners that keep popping up every few minutes? I am fed up being blasted with your 'supports subscription' messaging! I know it does and I might explore that option in my own time; I don't need to be nagged constantly. The 2 red/warnings are just as annoying. They are both complaining that my NSX-T manager DNS and NTP server configurations may not be uniform when they are. You need to fix the detection of both please and/or allow me to silence this noise as well. Bundle Management page is awful and confusing. I would like to hide bundles that have no relevance to me. I don't use NSX-V so it would be nice to filter these bundles out. I am using VCF 4.5.0, so do I really need to see the VCF 4.4.0 bundles? Same with vCenter Server; I am using VC 7.0.3.01000-20395099, so do I need to see the two previous versions? Additionally, it would be really helpful to get a current bundle download speed (Mbps) as well as the percentage bar. An estimate on download time would also be really good. Not everyone is on superfast internet connections and knowing the download will be around 3 hours allows me to go do something else whilst waiting. Finally, adding a sortable release date column on the Bundle Management page would make working out what's new a whole lot easier. Thanks M  
Thanks Stephen, I got it working by nesting the ESXi host I want to keep the 'wrong' date/time, inside another nested host; where I have manually changed it's date/time back 2 years. The extra late... See more...
Thanks Stephen, I got it working by nesting the ESXi host I want to keep the 'wrong' date/time, inside another nested host; where I have manually changed it's date/time back 2 years. The extra later of nesting made things a little slower, but I was able to test what I need to. Cheers, M
So I used image builder to export a ESXi-6.7.0-20191204001-no-tools image profile as a bootable ISO. Reset the VM date, booted from said ISO and I get the same date change as 'Jumpstart plugin vmtool... See more...
So I used image builder to export a ESXi-6.7.0-20191204001-no-tools image profile as a bootable ISO. Reset the VM date, booted from said ISO and I get the same date change as 'Jumpstart plugin vmtoolsd activated" is executed. So I am now thinking I just need to remove/uninstall the actual VMtools daemon vmtoolsd from the ESXi installation or stop it executing.  
I am trying to stand up a nested ESXi 6.x host with the date purposely about 2 years earlier than today. I have disabled/unchecked the VM options "sync time periodically" and the 4 "run VMware Tools... See more...
I am trying to stand up a nested ESXi 6.x host with the date purposely about 2 years earlier than today. I have disabled/unchecked the VM options "sync time periodically" and the 4 "run VMware Tools scripts" options. I booted the VM to BIOS and reset the date back to where I wanted. Booting the ESXi installer initially shows the 'wrong' date, until just at the end, when 'Jumpstart plugin vmtoolsd activated" is executed and it syncs the current time/date with my physical host. Is there a simple way of stopping this happening? Is there an ESXi 6.x installer without the VMtools packages pre-installed - I can't see one to download? Is there any way to remove the VMtools packages from the ISO and re-package it? Any thoughts/pointers will be appreciated. Cheers, M
Hi, I am upgrading a test vRA 3-node cluster from 8.6.0 to 8.6.1, using vRSLCM, and I have noticed that the health checks from my load balancer to each individual backend node on http://{node-fqdn}:... See more...
Hi, I am upgrading a test vRA 3-node cluster from 8.6.0 to 8.6.1, using vRSLCM, and I have noticed that the health checks from my load balancer to each individual backend node on http://{node-fqdn}:8008/health still receive 'HTTP/1.1 200 OK' when the underlying vRA site on https://{node-fqdn}/ is actually offline. Eventually the health checks do fail and the load balancer marks the node as down, but before the upgrade on that node has completed, they start to respond 200/OK again. This happens several times during the upgrade process.  It doesn't make any sense to me. If the node is down for upgrade I would expect the health check to consistently respond with something other than 200/OK, so the load balancer stops sending traffic to it. This is my first vRA cluster upgrade experience - is this usual? Cheers, M    
Tried 'disabling CEIP' as per https://kb.vmware.com/s/article/76053 but the service restart eventually got stuck in a loop waiting longer and longer each time for something to come ready. Gave up an... See more...
Tried 'disabling CEIP' as per https://kb.vmware.com/s/article/76053 but the service restart eventually got stuck in a loop waiting longer and longer each time for something to come ready. Gave up and trashed the vRA deployment: SSH'd into the vRA, as root, and confirmed the vco-app pod was in the CrashLoopBackOff state with kubectl -n prelude get pods Crashed out the vRA install (powered the vRA VM off & deleted it). SSH'd into the vRSLCM instance and gracefully restarted it. Deleted the dead vRA environment from within vRSLCM Recreated a new environment for vRA within vRSLCM Added a certificate for vRA into the locker Installed vRA into the newly created environment. SSH'd into the vRA once it was up and monitored the pod install/startup with  watch -n 5 kubectl -n prelude get pods 34 minutes from start to finish. Done!
Hi, Is it possible to have multiple concurrent instances of vRA (different versions) configured into the same vCenter Server? I am in a lab environment and am trying to get to grips with vRealize S... See more...
Hi, Is it possible to have multiple concurrent instances of vRA (different versions) configured into the same vCenter Server? I am in a lab environment and am trying to get to grips with vRealize Suite setup/initial configuration. I used vRSLCM v8.6 to successfully deploy (after a few attempts) vIDM & vRA, using the Easy Installer. I have then used vRSLCM to install vRLI and vROps (again both v8.6). All working great. I wanted to try a vRSLCM managed upgrade, so I downloaded vRSLCM v8.3 and started a new Easy Installer installation, into the same vCenter Server, using new VM names/hostnames/etc. It has been installing for a few hours (much longer than the v8.6 took) and I just got a vRA installation failure message during stage 6 (initialize vRealize Automation); but when I checked the requests queue the error cleared itself and it is back as 'in progress' at the same point in stage 6. Can I have multiple vRA clusters configured to the same vCenter Server? Thanks M EDIT: Typical... I just after pressing submit here it failed again: This is a single vRA node installation Error: " Error Code: LCMVRAVACONFIG590003 Cluster initialization failed on vRealize Automation. vRealize Automation virtual appliance initialization failed on mc-vvra-v-202a.momusconsulting.com. Login to vRealize Automation and check /var/log/deploy.log file for more information about the failure. If it is a vRealize Automation high availability and the load balancer has to be reset, set the 'isLBRetry' to 'true' and enter a valid load balancer hostname. com.vmware.vrealize.lcm.common.exception.EngineException: vRealize Automation virtual appliance initialization failed on mc-vvra-v-202a.momusconsulting.com. Login to vRealize Automation and check /var/log/deploy.log file for more information about the failure. If it is a vRealize Automation high availability and the load balancer has to be reset, set the 'isLBRetry' to 'true' and enter a valid load balancer hostname. at com.vmware.vrealize.lcm.plugin.core.vra80.task.VraVaInitializeTask.execute(VraVaInitializeTask.java:126) at com.vmware.vrealize.lcm.plugin.core.vra80.task.VraVaInitializeTask.retry(VraVaInitializeTask.java:221) at com.vmware.vrealize.lcm.automata.core.TaskThread.run(TaskThread.java:43) at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source) at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source) at java.base/java.lang.Thread.run(Unknown Source)   "        
@astins0nI have just had the opportunity to upgrade to vCenter Server 7.0 Update 2c (7.0.2.00400) b18356314 and I can confirm that the issue has been resolved. Hopefully you wont have to wait too lon... See more...
@astins0nI have just had the opportunity to upgrade to vCenter Server 7.0 Update 2c (7.0.2.00400) b18356314 and I can confirm that the issue has been resolved. Hopefully you wont have to wait too long for the VxRail upgrade bundle that includes this version to be released.