3. Enterprise Configurations for App Volumes and Dynamic Environment Manager
- On your ControlCenter server
- Open the Remote Desktops > Site 1 folder
- select and launch the Appvol-01a.RDP shortcut
- Open the Remote Desktops > Site 1 folder

- In the Windows Security window
- login as TechSeals\administrator
- in the password area
- enter Pa$$w0rd
- select OK
- in the password area
- login as TechSeals\administrator

- On the AppVol-01a server
- from the Taskbar
- select the folder icon
- from the Taskbar

- In the File Explorer window
-
Quick access bar
- expand This PC
- select Local Disk (C:)
- expand This PC
-
Quick access bar

- In the File Explorer window
- browse to
- C:\Program Files (x86)\CloudVolumes\Manager\nginx\conf
-
In the conf folder
- rename appvol_self_vmware.com.crt to appvol_self_vmware.com.crt.origin
- rename appvol_self_vmware.com.key to appvol_self_vmware.com.key.origin
- browse to

- On the Appvol-01a Desktop
- select and open the Software shortcut
- in the Software folder, open
- certificates > Techseals
- In the Techseals folder
- copy and paste
- _techseals_co.crt and private.key
- to C:\Program Files (x86)\CloudVolumes\Manager\nginx\conf
- copy and paste
- in the Software folder, open
- select and open the Software shortcut

- In the File Explorer window
- in the conf folder
- rename
-
_techseals_co.crt to server.crt
- and
- private.key to server.key
-
_techseals_co.crt to server.crt
- rename
- in the conf folder

- In the File Explorer window
-
conf folder
- select nginx.conf
-
right-click
- select Open with
-
right-click
- In the Windows can't open this type of file (.conf) window
- select Try an app on this PC
- in the How do you want to open this file? window
- select Notepad
- select OK
- select Notepad
- select nginx.conf
-
conf folder

- In the nginx.conf file
-
scroll down to ssl_certificate
- rename appvol_self_vmware.com.crt to server.crt
- next to ssl_certificate_key
- rename appvol_self_vmware.com.key to server.key
-
scroll down to ssl_certificate

- In the nginx.conf file
- select File
- select Save
- Close the Notepad window
- select File

- On the AppVol-01a server
- select the START button
- right click
- select Run
- right click
- In the Run window
- next to Open:
- enter services.msc
- select OK
- next to Open:
- select the START button

- In the Services window
- select App Volumes Manager
- right-click
- select Restart
- right-click
- select App Volumes Manager

- On your ControlCenter server
- open your Site 1 Browser
- in the Favourites bar
- select the App Volumes shortcut
- Note your App Volumes address now has a trusted CA signed certificate
- in the Favourites bar
- open your Site 1 Browser
Note:
- It will take a few minutes for the App Volumes Manager Admin Console to show, refresh your browser to validate.
- Wait until it shows before starting Part 2

- On your Controlcenter server
- open the Site1 - Bangalore Chrome Browser

- On your ControlCenter server
-
Chrome browser
- in the address bar
- enter http://localhost/certsrv
-
In the Welcome page
-
below Select a task
- select Download a CA certificate, certificate chain or CRL
-
below Select a task
- in the address bar
-
Chrome browser

- In the Download a CA certificate, certificate chain or CRL window
-
below Encoding method
-
next to Base 64
- select the radio button
- select Download CA certificate
-
next to Base 64
-
below Encoding method

- On the Chrome browser
- to the right of the address bar
- select the Download icon
- in the Recent download history window
- to the right of certnew.cer
- select the Show in folder icon
- to the right of certnew.cer
- to the right of the address bar

- In the File Explorer window
- select certnew.cer
- right-click certnew.cer
- In the dropdown menu
- select Rename
- In the dropdown menu
- right-click certnew.cer
- select certnew.cer

- In the File Explorer window
- rename certnew.cer
- to adCA.pem
- In the Rename window
- select Yes
- rename certnew.cer
Note, there is a case sensitive requirement when renaming the cert to adCA.pem

- In the File Explorer window
- select adCA.pem
- right-click adCA.pem
- In the dropdown menu
- select Copy
- In the Quick access menu
- select Desktop
- select adCA.pem

- In the File Explorer window
-
Desktop area
- select the Software shortcut
- In the Software folder
- browse and open App Volumes
- within the App Volumes folder
- select and Paste adCA.pem
- In the Software folder
- select the Software shortcut
-
Desktop area

- On your ControlCenter server desktop
- open the Remote Desktops > Site 1 folder
- launch the Appvol-01a.RDP shortcut

- On your Appvol-01a RDP session
- select the Software shortcut
- In the Software area
- browse and open the App Volumes folder
- In the App Volumes folder
- select and right click adCA.pem
- in the dropdown menu
- select Copy
-
In the File Explorer window
- Quick access bar
- select This PC

- In the File Explorer folder
-
This PC area
- browse to Local Disk (C:)
- in Local Disk (C):
- Browse to > Program Files (x86) > CloudVolumes > Manager > config
-
in the config folder
- paste adCA.pem
- in Local Disk (C):
- browse to Local Disk (C:)
-
This PC area

- On the ControlCenter server
- on your Site 1 Browser
- from the Favourites bar
- launch the App Volumes shortcut
- from the Favourites bar
- in the App Volumes admin console
- under Username
- enter Administrator
- under Password
- enter Pa$$w0rd
- select LOGIN
- under Username
- on your Site 1 Browser

- In the App Volumes Manager admin Console
- select the CONFIGURATION tab

- In the App Volumes Manager admin Console
- In the CONFIGURATION area
- select the Domains tab
- In the CONFIGURATION area

- In the Active Directory Domains area
- under Domains
- in front of techseals.co
- select the expand button
- to the right of techseals.co
- select EDIT
- in front of techseals.co
- under Domains

- In the Edit Active Directory Domain area
- enter and validate the following:
- next to Domain Controller Hosts
- validate that 192.168.110.10 is the IP address
- next to Password
- enter Pa$$w0rd
- next to Security
- from the dropdown
- select Secure LDAP (LDAPS)
- from the dropdown
- in the bottom left-corner
- select UPDATE
- next to Domain Controller Hosts
- enter and validate the following:

- In the Directory Services Domains area
- note your Active Directory Domain is now secured with LDAPS

- On the AppVol-01a server
- select and right-click the START button
- select Run
- In the Run window
- next to Open
- enter services.msc
- select OK
- enter services.msc
- next to Open
- select and right-click the START button

- In the Services window
- select and right - click the App Volumes Manager service
- from the dropdown select Restart

Wait for about 2 minutes for the services to come back online
The reason we have to do Part 3 is we our App Volumes Manager had a self-signed certificate prior to deploying App Volumes agents. In a Production environment. App Volumes Manager would be deployed first, configured with CA signed Certificates and then one would deploy the Agents
- On your ControlCenter server
- on your Site 1 browser
- select your vcenter-01a shortcut
- on your Site 1 browser

- In the VMware vSphere page
- in the username area
- enter [email protected]
- in the password area
- enter Pa$$w0rd
- select LOGIN
- in the username area

- In the vSphere client
- select esxi-01a.techseals.co
- select the VMs tab
- in the VMs tab area
-
select the State column
-
next to :-
- APPVolprov-01a
- RDSHPROV-01a
- W11INST-1
- W11INST-2
- RDSBLR -01-1
- RDSBLR -01-2
- W11EXT-01a
- W11FullClone-1
-
select the checkboxes
- right click
- from the dropdown menu
- select Power > Restart Guest OS
-
next to :-
-
when prompted to Confirm Guest Restart window
- select YES
- select the VMs tab
- select esxi-01a.techseals.co

- In the VMware vSphere Client
- next to :-
- appVolprov-01a
- W11INST-1
- W11INST-2
- RDSBLR -01-1
- RDSBLR -01-2
- uncheck the checkboxes
- next to :-

- In the VMware vSphere Client
- next to RDSHProv-01a
- select the checkbox
- right click
- from the dropdown menu
- select Power > Power On
- from the dropdown menu
- right click
- select the checkbox
- next to RDSHProv-01a

The default NOAD.xml file comes with default Export paths to archive the User Profile and an archive for the Logs, but there is no Archive Backups configuration by default.
If Archive Backups are configured , Users are able to use Self-Support and Administrators are able to use the Help Desk Support tool.
In the next part we will configure the NOAD.xml file and enable Archive Backups
- On the ControlCenter server
- from the Taskbar
- select the File Explorer folder

- In the File Explorer folder
- Quick Access bar
- select and expand This PC
- select and expand Local Disk (C:)
- select the DEMConfig folder
- select and expand Local Disk (C:)

- In the File Explorer folder
- DEMConfig folder
- open the General > FlexRepository > NoAD folders
- In the NoAD folder
- select and right-click NoAD.xml
- from the Dropdown
- select Edit with Notepad++
- DEMConfig folder

- In the NoAD.xml file
- append the following information after EventLogUEMRefresh="1"
BackupPath="\\controlcenter.techseals.co\demprofiles$\%username%\Backups"
BackupCount="4"
BackupDaily="1"
- In the NoAD.xml file
- select File > Save
- close the NoAD.xml file

We have put in Steps for Arhive backups to work , we will look at Self-Support and Help Desk support with regard to Dynamic Environment Manager later in the labs
This Concludes this Lab Module
0 Comments
Add your comment