可以将导出的 ESXi 主机和 vCenter Server 信息导入到 vSphere Trust Authority 集群中,以便 Trust Authority 集群了解可以证明哪些主机。
前提条件
过程
结果
示例: 将受信任主机信息导入到 Trust Authority 集群
以下示例显示了如何使用 PowerCLI 将受信任集群的 vCenter Server 主体信息和受信任主机信息文件导入到 Trust Authority 集群。该示例假设您已经以 Trust Authority 管理员身份连接到 Trust Authority 集群的 vCenter Server。下表显示了所使用的示例组件和值。
组件 | 值 |
---|---|
变量 $vTA |
Get-TrustAuthorityCluster 'vTA Cluster1' |
Trust Authority 集群的 vCenter Server | 192.168.210.22 |
Trust Authority 集群名称 | vTA Cluster1 (Enabled) vTA Cluster2 (Disabled) |
主体信息文件 | C:\vta\principal.json |
TPM 证书文件 | C:\vta\cacert.cer |
ESXi 主机基础映像文件 | C:\vta\image.tgz |
Trust Authority 管理员 | [email protected] |
PS C:\Users\Administrator> Disconnect-VIServer -server * -Confirm:$false PS C:\Users\Administrator> Connect-VIServer -server 192.168.210.22 -User [email protected] -Password 'VMware1!' Name Port User ---- ---- ---- 192.168.210.22 443 VSPHERE.LOCAL\trustedadmin PS C:\Users\Administrator> Get-TrustAuthorityCluster Name State Id ---- ----- -- vTA Cluster1 Enabled TrustAuthorityCluster-domain-c8 vTA Cluster2 Disabled TrustAuthorityCluster-domain-c26 PS C:\Users\Administrator> $vTA = Get-TrustAuthorityCluster 'vTA Cluster1' PS C:\Users\Administrator.CORP> New-TrustAuthorityPrincipal -TrustAuthorityCluster $vTA -FilePath C:\vta\principal.json Name Domain Type TrustAuthorityClusterId ---- ------ ---- ----------------------- vpxd-de207929-0601-43ef-9616-47d0cee0302f vsphere.local STS_USER TrustAuthorityCluster-domain-c8 PS C:\Users\Administrator.CORP> Get-TrustAuthorityPrincipal -TrustAuthorityCluster $vTA Name Domain Type TrustAuthorityClusterId ---- ------ ---- ----------------------- vpxd-de207929-0601-43ef-9616-47d0cee0302f vsphere.local STS_USER TrustAuthorityCluster-domain-c8 PS C:\Users\Administrator.CORP> New-TrustAuthorityTpm2CACertificate -TrustAuthorityCluster $vTA -FilePath C:\vta\cacert.cer TrustAuthorityClusterId Name Health ----------------------- ---- ------ TrustAuthorityCluster-domain-c8 52BDB7B4B2F55C925C047257DED4588A7767D961 Ok PS C:\Users\Administrator.CORP> New-TrustAuthorityVMHostBaseImage -TrustAuthorityCluster $vTA -FilePath C:\vta\image.tgz TrustAuthorityClusterId VMHostVersion Health ----------------------- ------------- ------ TrustAuthorityCluster-domain-c8 ESXi 7.0.0-0.0.14828939 Ok