Next-Level Security and Resilience with VMware Cloud Foundation 9.0
When you think about cloud infrastructure security there are three main goals you are trying to achieve. First, you want to be secure quickly and stay that way. Second, you want to drive trust in your infrastructure. Third, you want to be resilient, easily. Broadcom’s Bob Plankers will take you through the latest security innovations in VMware Cloud Foundation 9.0 for providing next-level security, trust and resilience, empowering IT operations amidst regulatory complexities and geopolitical uncertainty.
The presentation focused on security and trust in VCF 9.0, emphasizing a “security first” approach, prioritizing ongoing security practices over infrequent compliance audits. A key theme was enabling customers to be secure faster, recognizing that security is a means to delivering services and running workloads. Plankers highlighted the importance of resilience, referencing features like vMotion and the EU’s Digital Operational Resilience Act, addressing both tactical and strategic scenarios such as failed application upgrades and disaster recovery.
The core differentiator of VCF 9.0 is inherent trust in the stack, moving towards less trust and more continuous verification. This includes verifying the platform’s security state, data sovereignty, and controlled access. The discussion covered lifecycle patching enhancements with Lifecycle Manager, aiming to simplify updates and manage multi-vendor cluster images. Features like live patching, custom EVC profiles, and improved GPU usage were also discussed as facilitating easier maintenance and patching, reducing friction.
The presentation went into deep dive on enhancements inside the hypervisor for security, including code signing, secure boot, and sandboxing. Confidential computing with AMD SEV-ES and Intel SGX technologies was explored, along with the introduction of a user-level monitor to de-privilege VM escapes. Workload security improvements encompass secure boot, hardened virtual USB, TPM 2.0 updates, and forensic snapshots. Cryptographic enhancements included TLS 1.3 by default, cipher suite selection, and key wrapping. Centralized password management, unified security operations, and standardized APIs for role-based access control further enhance security and automation.
Presented by Bob Plankers, Product Management & Marketing, Broadcom, as part of VMware Cloud Foundation 9.0 Showcase – Modern Private Cloud. Watch the entire presentation at https://techfieldday.com/appearance/vcf9showcase/ or https://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation for more information.
Transcript
Hey, I'm Bob Planker, and I am talking about security and compliance, security and trust. Actually, uh, you know, compliance is one thing. 0.
So, I like to start with sort of our approach to security and our approach to all of this stuff. And in fact, our approach when we talk about security and compliance, our approach is security first, security. You do good.
Security. Security's an always sort of thing, always on compliance. You're getting audited once a year, something like that.
If that's all you're doing security wise, you're probably in trouble at that point, but, uh, uh, you know, good security is explainable to your auditors, or it should be at least. And so that's actually one of our goals. But, you know, we really want our customers to be able to be secure faster.
Security itself is not something that advances an organization. It's not the prime thing for most organizations. Some organizations actually do security and they care deeply about that, but most it's just a means to an end.
They want to deliver services, run workloads, that sort of thing. And so where we can turn things on, we like doing that, uh, where security's always a trade off in some ways. So we don't turn certain things on because of those trade-offs, but we want it to remain flexible.
Not everyone is the same. Not everyone has the same requirements, many workloads, there's always something, right? So that really try to stay flexible there, recovering quickly.
All manner of stuff can happen in an environment, and being able to, to be resilient to that is really important. Uh, resilience has really been the primary feature since v uh, of VMware infrastructure software since what, 2005 or so when vMotion was invented. And we kind of stopped talking about it, but we shouldn't have.
And actually, the EU Digital Operational Resilience Act, uh, where banks in the eu were really doing a lot of work with that, uh, late last year, mid last year, uh, really highlighted all of the resilience features that we have. And then we've got a ton of stuff and, you know, just tactical stuff, uh, from failed application upgrades or de-risking just day-to-day stuff, or, you know, strategic stuff, what happens if I get run over by a hurricane and that sort of thing. And so, very important there.
And then last on my list, really what we're after in VCF and the, the real differentiator is trust, inherent trust in the stack. Well, we talk about zero trust a lot. The industry talks about zero trust, but I see zero trust implementations there end up being lots more trust.
So zero trust should be less trust, not more trust. And it's maybe just my opinion, but, uh, you know, that's, you know, fewer things to secure. The easiest thing to secure is the thing that you don't have, you know, and so reducing the amount of trust, reducing the population of people that can have access, all of that stuff, very important for security.
And then being able to replace trust with continuous verification. I mean, there's the old eighties cold war thing. Uh, trust but verify.
That's exactly right. You know, like you can, if you've got data from the last hour that your hosts are all up to date and are running the right level of firmware, all of this stuff, that's really powerful. And so the ability to trust that your platform, your data is where you think it is.
You know, data sovereignty is really important. There's a lot of regulations nowadays about data having to remain in certain places, uh, that you know, who's got access. You know, what has access, not just who, but what other systems that the system is verifiably secure that, uh, it's being monitored, it's continuously monitored, and you can verify that the security state of it, uh, problems.
When that changes should be highlighted rapidly, it should, uh, come to people's attention. You know, somebody that can do something about it, dear human, dear human maintainer of mine, I am VCF and you should fix me. You know, that sort of thing.
And maybe it's, maybe it's innocuous, maybe it's an actual breach, but a lot of times it's just innocuous. Somebody changed something. I used to change security controls to debug and to debug things, to fix things, and then I'd forget to put 'em back, you know, and then I'd find out about it during an audit.
And then resolving things, uh, resolutions to problems should be quick, non-disruptive. If, if they can be, you know, vMotion is a great example of that, again, where we can patch infrastructure without taking the workloads down. And so that's, uh, kind of the core of how we think about security moving forward.
And, and really, again, not about security, but about trust. Can you trust your platform? Do you trust your platform and why?
So I'd like to talk a little bit about lifecycle patching. Some of the highlights, hit some of the highlights from, uh, uh, the security world. Things that are pertinent.
There's a lot to be said about lifecycle, being able to, to update, upgrade patch when there's a patch available. And we've gone through some changes over the last few major versions. Update manager's gone, we miss you Update manager.
But lifecycle Manager's really cool. It cares deeply about the way a system is configured. It's doing the continuous monitoring as well.
Hey, a system has extra pieces of software on it. Well, that's not good. You know, like, we should check that out.
That sort of thing. And so we've taken a lot of feedback around that. How do we make that easier to use?
How do we make it more valuable? Multi-vendor cluster images. Uh, you know, in a perfect world, we all get a dump truck full of money backed up to us every couple of years, and we buy a whole new homogenous cluster.
That's not how the real world works. Not at my real world at least. And so, uh, um, yeah, uh, making that easier to deal with, taking out some of the friction, uh, ha the high availability and NSX components were add-ons and installed separately, and they get into dependency loops where one big family now and VCF, it all just ships as part of it, so that's gone.
But also, things like GPUs, all this ai, newfangled AI stuff is neat, but we've spent 10 years making GPU usage just part of just one of the gang as far as our workload is concerned. Being able to move it around, you know, AI researchers and data scientists can feel important on their own, you know, but from an infrastructure perspective, it's just all the same. And that's really nice, especially in nine.
We've really done a lot of work with the vMotion stuff. Live patching and custom EVC profiles. Talk a little bit about those here.
So live patching is something we announced in eight, vSphere eight, but it's scope was so limited, we actually haven't had an opportunity to use it yet, you know, and that's gonna continue in the near future too. But, uh, in nine, our, our vision for it is that about 80% of anything that a host needs to be patched for should be covered by live patching, you know, and that's really nice. The, the ability to not move workloads.
Most workloads can move just fine, but there's big ones. There's, uh, workload administrators that are jumpy about it. And so we want to, uh, uh, where we can leave 'em where they're at.
We enter partial maintenance mode and then partial maintenance mode just stabilizes the machine. Nothing going in, nothing coming out as far as workloads. And then it does what it needs to, if it needs to repair, uh, and patch the virtual machine monitor.
And we'll talk a lot more about the virtual machine monitor in a few minutes here. Uh, then we do what's known as a Fast Suspend resume. It's basically a process to process V Motion is what it amounts to.
It's milliseconds, nanoseconds, I dunno, I I used to say that it's measured, and it could be measured in CPU cycles, but any, anything can be measured in CPU cycles. Caveat here is, uh, DPU and TPM enabled hosts are not yet compatible. D P's got the ESX running on the DPU itself, so there's considerations there, and tpms, the extra security.
So what we're doing with Live Patch is replacing part of the operating system, you know, and we don't want to ta we turn on extra security to prevent attackers from being able to do that. So we need a way to authenticate ourselves to the system so that attackers can't do this maliciously, but we can. So it's in pro in process.
It's number one question. Hey, we got a quick question there. Yeah.
The, the TPM enabled hosts, we know that Microsoft has made a big deal about future versions of Windows needing a TPM to be enabled. Uh, is this something you feel is gonna impact the ability to virtualize, like, at this point, workstation endpoints, or do you feel like this is something that's gonna be easily overcome very soon, like you working on figuring out how to make this TPM compatibility thing work? Uh, so this is at the host level.
This is ESX itself. So ESX is the, the hardware trusted platform module belongs to ESX and no workloads touch it. Um, there's no workload data stored there whatsoever.
Uh, for workloads, we've got the virtual TPM, which is completely separate. It's rooted in VM encryption, so it keeps it secret safe that, that direction, and it's not impacted by this at all. So, okay, thank You if that, I, since, uh, Tom broken, now we can ask questions.
I'll go, um, how does patching work in the context of E-S-X-I-I being part of the whole product of VCF? Can I just use this feature to pack, just patch, just so when something critical happens, or does it have to come apart, come to, to me, as part of a huge VCF upgrade or patch, uh, itself? It, It can be both.
Uh, so we've got a new versioning scheme as well. Uh, some logic has been applied to our versioning. 0 U three Q-Z-S-S-P whatever anymore.
Uh, nobody knows what those are. Uh, everyone knows what Arabic numerals are and that, you know, the versions go up and we have newer stuff. So really trying to do that.
0. 2 as an example. 1 is a VCF bundle, and you, you'll get things as that as well.
1 is a tactical patch, basically. And, uh, so we're gonna apply that. 1 is released, that'll be something you'll apply like this.
But you can get these patches in both directions, uh, if it's big enough or, um, and there's a, there are timeframes associated with these things as well, you know, monthly, quarterly. 1, for example, would be a quarterly patch, that sort of thing. So, you know, trying to make some sense out of it.
But yeah, to your question, you'll, you'll be able to see the, uh, ESX updates in all of those sorts of ways. Bob, this is, uh, Jack Poller from Paradigm Technica. Uh, another question on patching, which I know is, is sort, not really security, but still security is, are, are patches going to be inclusive or admins gonna have to be responsible for saying, I need to build up a stack and a chain of patches in order to get my machines?
Oh, that sounds like a nightmare, Jack. The, uh, um, no, they're always inclusive. Uh, and with very few exceptions over my experience with VMware, basically, we all, we, they're always cumulative.
So if you apply the latest stuff, the latest version, you go out into the support portal, download the latest thing, you'll have all of the patches up until that point. So you cool. No good questions.
Uh, EVC. So making patching easy also, you know, uh, if you've got mixed, mixed clusters, clusters that, uh, so you get different, um, generations of CPUs, you can't vMotion back and forth between them. EVC, enhanced vMotion compatibility basically smooths out the differences between them.
But it's been incredibly hard to use because you had to, you had to remember to turn it on when the cluster was absolutely empty, right when you built it, and nobody remembered that. And then, or you gotta wait for a power outage or some other catastrophe and then make an unscheduled change, that sort of thing. And so, a couple with that, the, uh, uh, CPU generation CPUs have kind of gone nuts, and there's a whole bunch of different types and varieties, and there's all this edge stuff now that uses all this stuff.
We've got the ability to just capture what you're using. And in fact, uh, uses link mode if you've, you've got your hosts in link mode, uh, clusters are all linked to, to each other. It'll look at the whole thing and say, here's the baseline for all of this stuff, and then you can just turn it on right where you're at.
And so hopefully that will make things a lot easier moving forward for, uh, uh, again, just patching, being able to deal with it. The, some of the friction here deep inside the hypervisor itself, doing a lot of work as far as security and the layers of security in here. Uh, first couple of things, code signing, we've been talking about that for a long time.
Our ecosystem's got a lot of inertia to it. We still have partners, vendors out there that are telling people to shut security off because they're not signing their code. You can do that, you can still do that.
We're on our way to making that not possible. But, uh, um, if you do that, now you get an INDISPENSIBLE warning that you've got a security problem, which you do. Uh, secure boot, 40% of the world uses secure boot.
It's been around for 15 years. It's a great way to prevent malware. Trying to make that easy as well.
You can enforce it via, uh, configuration profiles. Now you can actually just turn it on, switch over to it, and ESX will boot just fine using, uh, using that now. So shouldn't be any barriers there anymore, except, uh, in people's minds, hopefully.
So, let's talk about the user level, monitor sandboxing, and then confidential computing a little bit too. Uh, so inside of ESX, we've got all these different layers of, I often compare it to an onion, you know, you peel it a little bit, you cry a little bit, it's all good. And, uh, but you've got these different layers there.
The guest operating system, unless you're running Windows three one or dos or something, which still run by the way, uh, you've probably got inpro process protections there. You've got a, a role-based access control model, something like that around that. You've got the VM runtime, container runtimes as well, just a workload runtime, and that's a security boundary.
And then around that, in seven, vSphere seven, we introduced a sandbox. Basically, it watches what the runtime does, and if it didn't try something funny, it kills it and sends alerts, you know, and it's not perfect, but it's a heck of a lot better than it used to be. And these protections are available on all of the workloads running on E-S-X-E-S-X itself is a security boundary.
You know, there's, uh, you can, uh, sequester certain types of workloads and certain, uh, security, you know, keep the same security levels together, that sort of thing. Then underneath CPU in memory, which about eight years ago, we discovered that the promises made by CPUs and memory controllers and IO controllers, and that aren't necessarily what actually gets implemented. And so, and there's more of those.
I mean, recently in the last couple of weeks, there's even been announcements about new versions of Specter and Meltdown esque vulnerabilities from a MD and and such. So nobody, nobody's, nobody gets out of this one without a little bit of blame. But what do we do about it?
So we've got the, the two main types of vulnerabilities here, hardware vulnerabilities, where your guest operating system, an attacker that's got access to a guest operating system, can coerce the hardware into giving it data it shouldn't have access to. And then you've got the VM escapes, you know, the, uh, um, where you can, an attacker breaks into the guest operating system and then can get out into ESX, and you don't want them there either. So, as far as hardware vulnerabilities, we'll talk about a little bit about that.
Confidential computing, for example, we've had A-M-D-S-E-V-E-S and Intel's, SGX technologies built in since seven. You know, there's follow ons. Those were kind of hard to use, and they kept secrets from the hypervisors.
And so the hypervisor basically takes its ball and goes home, says, I'm not gonna help you with vMotion, I'm not gonna help you with all this other stuff. And so, a MD and Intel came up with, uh, new versions of these that help with, with a lot of that stuff. And so S-E-V-S-M-P-T-D-X, the follows, uh, follow-ons to these, those technologies.
And so, uh, a MD in particular, they, uh, uh, they implement their versions of the security, the confidential computing, uh, uh, technology. They've got a security processor. It's an arm chip that's actually integrated into their epic CPUs, which is cooled by itself.
And a guest operating system that wants to participate can request an encryption key. And, uh, uh, it gets the encryption key. Its data is encrypted in memory and in the CPU registers as well.
And so that's really nice. And so it's not an all or nothing thing. You can turn certain guest operating systems can enable it.
If you've got a guest operating system, if you are running Windows three, one, you don't have to enable it, whatever, it can be just its own little operation going on there. And then if there is a security vulnerability, uh, and a guest operating system can get access to something, it shouldn't have access to the, uh, um, all it gets back is ciphertext. It doesn't have the encryption keys there.
So that's a nice powerful protection. It's actually kinda interesting that CPU manufacturers are basically admitting that they are probably gonna have more problems like this. And so, but it's a way to protect yourself.
And it's really important in shared environments, especially public cloud. It's been very popular in public cloud because you don't know who your neighbors are. You know, it's a little bit of different security profile when you, when you're your own neighbor, you own the whole box, the whole box belongs to you, that sort of thing.
And so, but, uh, uh, building that in, we've got a lot of customers that are running in shared environments and that do want to take advantage of this. So we've got the initial steps here, uh, to enable these particular technologies. Does require host hardware support, as would seem obvious.
Uh, right now it's delivered by RPQ. We actually want to ask you a couple of questions. If you want to turn this on.
It's not very ones, uh, so just, um, yeah, uh, reach out. If, if people want to turn it on, uh, it will be, yeah, it'll be a, in in the future. It'll be fully, it's tech preview, essentially, but, uh, um, yeah, more to come.
So, Bob, yeah, what's up? Uh, I understand the use case here for confidential computing. Makes sense.
You wanna protect from lateral movement. Uh, any kind of idea, what kind of overhead, if any, that could introduce, uh, on the host itself? That's a good question.
And actually it, well, and it's gonna get the, you know, if it had a motto, it would be, it depends, you know, the workload, it depends on IO and that, there's actually a complicating factor here too, and I'll get to that in just a second. Uh, the user level monitor, we implemented this with a change in the virtual machine monitor. So performance testing is actually ongoing right now.
Uh, it's, yeah, it's less, you get, it's less performant than the, the old style. But, uh, um, yeah, we're working on it right now. I don't have a specific number.
You know, everyone wants a number. Is it 5%? Is it 35%?
I don't have a number for you, But there, there is a number out there. And it could vary based on the customer, but there's prob likely to be some kind of impact that you need to account for. Oh, yeah, there is a number for sure.
We don't know what it is right now. Okay. And we don't, we haven't properly, we haven't characterized the workloads enough.
So the virtual machine monitor that we've been dealing with is 20 years old. You know, like, and we've got good characterization of workloads on it. The, uh, um, yeah, the new one is not that old.
And so, uh, our performance in the office that the Broadcom office I'm part of, uh, there's a guy that sits down the hall for me. And he, that's exactly what what we're talking about right here is exactly what he's been doing the last few weeks. So, yep.
And he was unwilling to give me answers about it as well. I asked the exact same questions. So the, uh, uh, moving forward, let's talk a little bit about that.
So, uh, CPUs basically have two modes in which they can operate. The, uh, um, one mode is VM kernel or the kernel mode where anything running runs really fast, has no permissions. 'cause that's why it runs really fast.
And, uh, can, has a run of the box user mode is a little different. The, uh, user mode is, uh, um, doesn't have the run of the box. It's got permissions.
It's, it doesn't have permission to do anything really. But for performance reasons, all hypervisors run things in kernel mode. And, uh, it makes sense.
But that means when you've got a a VM escape, you root your administrator, you, you can do whatever you want there. And so that's not good. So what we're, what we're doing is part of this, and you'll see it in nine.
It's in nine, but it's not the default yet for a lot of these same reasons, Ken, that we were just talking about, that we're kind of conservative when it comes to this stuff. So, uh, it's the default, if you turn on memory tiering, it's the default if you turn on confidential computing, but it's not the default. There's some, uh, advanced parameters you can set if you want to, uh, uh, to make it the default or make it a certain percentage of the workloads that you start.
But, uh, um, yeah, it de privileges it. So somebody gets out, does a VM escape, gets out out of the sandbox even, well, what are they gonna do? They don't, they have no rights to anything.
And then beyond that, we've taken those sandboxes, you know, the idea of, Hey, we've got these sandboxes around the workloads themselves, but what about all these other processes? Well, we applied them to the other processes. So these are just four different examples.
I didn't want, there's a lot more little boxes I could draw, but they've got a sandbox around them as well. They've got a permission model, and if they try to do something funky, again, killed alarms. Thanks for playing.
So, uh, uh, yeah, just trying to sandbox as much as possible. Contain the blast radius there. We're basically doing a change through with a vm, like you're doing process, uh, Services.
Yeah, exactly. Yep. So, you know, the old school, uh, vulnerabilities, like the service location protocol, which has gone in nine, by the way.
Uh, that open source project was unmaintained for a number of years and had vulnerabilities, and we had to issue advisories about it and stuff like that. You know, uh, the problems there could have been contained. Certainly we want to get it fixed, but you know, the idea is to buy time so that you can do the stuff that's not in a panic.
And, uh, so, and that's nice. So workloads, people wanna run workloads on their platforms, and I don't blame 'em. Uh, most people don't just run VCF for the sake of running VCF like I do.
Um, number of sort of tactical, uh, incremental improvements to workloads. Uh, the really interesting things here, secure Boot. There's a lot of people wanting to sign their own, do their own secure boot stuff.
And that's, uh, cool. We support that now, support that officially now, there was a backdoor way to do it before. And, uh, so we, that's been promoted, uh, hardened virtual USB, we had some advisories about that.
And anytime we have an advisory or two about the same subsystem, we'll take a look at it and harden it. So, virtual machine hardware 22, you'll see that, uh, Microsoft's Black Lotus vulnerabilities where they lost control of their signing keys for Secure Boot, uh, that was not good. Uh, they've been slowly, quietly replacing the, uh, on revoking UEFI certificates over the last few years as part of Windows update.
Uh, so if you are running nine and running the latest versions of, uh, virtual hardware, you'll need the latest versions of the Microsoft ISOs. 0, we bumped the revision on there. There are some feature changes, but forensic snapshots, this is another interesting thing, because again, we're kind of conservative when it comes to operations and any snapshot that we, we take, we want to be runable again, and convincing engineering that forensic snapshots don't need to be runnable.
Actually, that was easier than than we thought, but, uh, uh, forensic snapshots don't need to be runnable. They need to be scannable by a tool, but that's it. So we've got support for that now too.
And so that's really nice. I think the biggest thing for me, for workloads, we get a lot of resilience features in the platform for workloads, but the VPCs, the virtual private clouds, eh, I, yeah, the, uh, um, are really interesting. The, the idea that you can dynamically create network segments for workloads to isolate them, apply security controls to them, all of that stuff.
And you can do it globally, all kinds of, there's all kinds of neat stuff there. I think that's a really interesting thing moving forward. And as NSX becomes tightly integrated, well just becomes part of ESX, it's, uh, um, yeah, that integration is getting a lot less complicated to do too, and a lot easier to set up.
Cryptography. People are deeply interested in keeping their secrets and cryptographic methods or how that works. 3 is the default all the way around.
Uh, we can fall back by default. 2. Again, we're a little conservative for backwards compatibility, but, uh, you can set that, I'll show that to you in a second.
And you can choose your cipher suites as well. Um, one, I've got slides for all of these things, so I'll just skip into it. Key wrapping.
So one of the ways in which you can do encryption is to keep your keys externally in a key management system. And that's great. People, uh, uh, people do that, but we never delete a key.
We actually can't tell if you're still using the key or not. And so people get really angry for a bunch of different reasons. One, they get all these keys in there and they don't know what's in use and what isn't.
2 million bucks in keys every year, you know, and that's a lot, you know, like, I, I think that's a lot. And so people asked, and three, they wanna rotate their keys. And so that kind of plays into which keys are actually in use.
And so we've got a wrapping key now. Uh, and so it's not just the two keys, the data encryption key and the key encryption key anymore. You can, we can wrap the key encryption key.
You know, all problems are solvable with another layer of abstraction, right? You know, and so we, uh, um, we can wrap that key. We can rotate that key.
We can give it a name that your KMS provider, uh, admin or your KMS admins can find. So In that case, you are wrapping a relatively static key with the dynamic key store in the KMS that people would rotate. Can we do a, can we do a force and say, Hey, we're, we're not sure of the, the, the validity or that, that the, the key we've wrapped is compromised.
Can we force rotation on that one as well? Yep. You can, uh, you can also create, uh, so one thing I didn't mention here, and I'm sorry, should have actually, because yeah, uh, so there's this idea of rekeying.
There's a deep rekey where you, uh, have to power the VM off and you rekey all the whole stack, you know, from scratch. Yeah. But there's these shallow rekey where you're changing the intermediate keys, and you can do that while everything's online.
And so that's how you would do that. You would rotate it through a shallow rekey process. Uh, you can either create a, another key provider to do that, or you can just do a, uh, a, a shallow, uh, rekey here, however you want to do it.
There's mechanisms for for that. It's, it's very flexible. Good question.
Uh, cipher, I was talking about this. Uh, we've hit a NIST 2024 TLS one three only, which will be a popular option. 3, only the two ciphers that pass, that pass all scanners globally.
You'll have to find other things to talk about with your GRC folks. So sports, weather, international regulatory compliance, whatever. Uh, speaking of international regulatory compliance, the ca browser form the standards body for, uh, browser certificate validity and all that stuff has over the next two years are lowering certificate li legal lifespans to 47 days, which sounds like an absolute nightmare to me.
Uh, I long for the days where I could get a 10 year certificate and be done with it, but, uh, I get why, you know, but the, uh, um, yeah, so VCF has got interfaces for managing these things, being able to see the sta uh, status of it, uh, renewing them automatically, and we've got things on our roadmap for better, uh, support for external ACME protocol, that sort of thing. So, yeah, uh, a lot of good stuff there. A lot of, a lot of good stuff.
Pa, centralized password management, centralized security operations, auditing, all the stuff that was in Aria operations prior, has become VCF operations and really doubling down on the auditing and monitoring for security, being able to dive into, uh, you know, uh, you get an alert that a security control has changed, you know, who did it? Being able to go into the VCF operations for logs, formerly re operations for logs, uh, log insight, whatever we wanna call it. Um, it's all becoming VCF operations, so I'm happy about that.
But the, uh, um, being able to dive into that stuff, being able to see who did it, uh, maybe not tell why it was done, but, you know, get to the, the bottom of things quick, more quickly so you can figure out is it an actual breach or just, yeah, junior admin doing something, you know, or senior admin doing something and forgetting, you know, as I said earlier. So a lot of good stuff going on here too. And also for compliance, trying to get ahead of your compliance so when the auditor shows up, you're ready to go, you know, you don't have any surprises.
But also keep it flexible too. So if you're, if you've made a business decision to not do a security control, you can shut that off. So it's not always bo bothering you.
Getting towards the end here. Access control. Access control is a big way in which organizations are breached, frankly, you know, identity systems.
And so being flexible with this, we're also really trying to get out of the business of being an identity provider because there's so much better stuff going on with real identity providers out there, you know, and if you need an on-premises one, the Symantec VIP stuff works great, otherwise we support Okta. We support Ping Azure AD or Intra id, but also generic pro providers as well. Saml, uh, OAuth providers, all of those, uh, you can set up your own as well.
And so that's, that's been something that's been asked for. And so there it is. Uh, we've got a site-wide VCF wide unified configuration.
You set SSO up once and it'll configure it on all of the different, uh, interfaces. You've also got multiple deployment options. It's the old VIDM stuff, except it's been changed to be a broker.
It's the VMware identity broker, and it's been embedded in all of eight. It was embedded in vCenter, uh, as a broker. It doesn't have its own identity man identity provider stuff in there anymore, like VIDM did.
But it can broker connections to other things. And so you can use the embedded one in vCenter. You can have an external, uh, you can have an appliance deployed as part of VCF or you can have an appliance cluster.
So three, three different appliances deployed, however you want to do that. 0, and some of that is actually programmatic access to the role-based access control systems, which has long been asked for, long been needed so that people can write stuff to automate these things. Uh, you don't have to do weird, uh, weird stuff in the backend.
There's standardized interfaces for it. So that's what I've got for you guys. Uh, we publish all of our, well, we publish as much as we can.
Anytime I run across a, uh, something that could be public, I've been putting it out in our GitHub repository. Um, and whether you believe in QR codes and their security or not, well, here's a QR code and it's doubly bad if you, uh, swing that way because it goes to a redirector, which then goes to my GitHub, URL. But, uh, um, yeah, you can take it out on me and explore some sometime when we see each other.
And that is my, my deal. Thank you folks, and security and trust.