(Thanks to virtualization.info for alerting us to this release.) VMware has posted an update to VirtualCenter that addresses a potential security problem with the Virtual Infrastructure clients and the VirtualCenter server. Apparently, the potential security flaw is that SSL server certificate validation was not being performed, allowing a potential man-in-the-middle attack. The update enables the validation of SSL certificates; the exact procedure for how this is done is documented in this VMware KB article.
Tags: Security, Virtualization, VMware




No comments
Comments feed for this article
Trackback link: http://blog.scottlowe.org/2006/11/24/virtualcenter-patch-released/trackback/