Install an SSL certificate

Nutanix supports SSL certificate-based authentication for console access. To install a self-signed or custom SSL certificate, do the following: Recommended Key Configurations Key Type Size/Curve Signature Algorithm RSA 2048 SHA256-with-RSAEncryption EC DSA 256 prime256v1 ecdsa-with-sha256 EC DSA 384 secp384r1 ecdsa-with-sha384 EC DSA 521 secp521r1 ecdsa-with-sha512

Read more...

Configure user authentication

Prism currently supports integrations with the following authentication providers: Prism Element (PE) Local Active Directory LDAP Prism Central (PC) Local Active Directory LDAP SAML Authn (IDP)

Read more...

Explain Data-at-Rest Encryption (DARE) functionality

The data-at-rest encryption feature is being released with NOS 4.1 and allow Nutanix customers to encrypt storage using strong encryption algorithm and only allow access to this data (decrypt) when presented with the correct credentials, and is compliant with regulatory requirements for data at rest encryption. Nutanix data-at-rest encryption leverages FIPS 140-2 Level-2 validated self-encrypting…

Read more...

Explain security concepts such as two-factor authentication, key management and cluster lockdown

Two Factor Authentication You can enable two-factor authentication for users through a combination of a client certificate and/or username/password to address stringent security needs. Key Management Nutanix supports key-based SSH access to a cluster. Adding a key through the Prism web console provides key-based access to the cluster, Controller VM, and hypervisor host. Each node…

Read more...

Describe how Nutanix provides cluster security

User accounts control access, and the web console allows you to set the authentication method (see Configuring Authentication). Nutanix uses SSL to secure communication with a cluster, and the web console allows you to install SSL certificates (see Installing an SSL Certificate). Nutanix supports key-based SSH access to a cluster, but you have the option…

Read more...

Use the REST API Explorer to retrieve and/or make changes to a cluster

REST API Methods The HTTP verbs comprise a major portion of our “uniform interface” constraint and provide us the action counterpart to the noun-based resource. The primary or most-commonly-used HTTP verbs (or methods, as they are properly called) are POST, GET, PUT, PATCH, and DELETE. These correspond to create, read, update, and delete (or CRUD)…

Read more...

Identify how to download and configure tools and applications like Prism Central, Cmdlets, and REST API

Prism Central Coming Soon PowerShell cmdlets Sign in to the Nutanix web console. Click the user icon in the upper-right corner of the web console and select Download Cmdlets Installer. After the installer completes downloading, double-click the installer and follow the prompts. The cmdlets are installed and a desktop shortcut NutanixCmdlets is created. Double-click the…

Read more...

Differentiate between Pulse and Alert technologies

Pulse After you have completed initial setup, created a cluster, and opened ports 80 or 8443 in your firewall, each cluster sends a Pulse message once every 24 hours to a Nutanix Support server by default. Each message includes cluster configuration and health status that can be used by Nutanix Support to address any cluster…

Read more...