Meltdown and Spectre Effects on vRealize Operations Manager 6.7
search cancel

Meltdown and Spectre Effects on vRealize Operations Manager 6.7

book

Article ID: 319639

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

vRealize Operations Manager is not effected by Meltdown or Spectre.

In the interest of compliance and security protocols, Page Table Isolation (PTI) has been enabled in vRealize Operations Manager 6.7 for the underlying SLES Operating System.
Due to other performance optimizations in vRealize Operations Manager 6.7, there is no performance degradation with PTI enabled.

PTI can still be disabled on vRealize Operations Manager 6.7 by following the steps in the Resolution section.

Environment

VMware vRealize Operations Manager 6.7.x

Cause

Meltdown and Spectre vulnerabilities both require access to the server; this is critical for systems that have unprivileged user accounts and allow unprivileged users to login.
vRealize Operations Manager does not have unprivileged user accounts
The only way to log into a vRealize Operations Manager node is by using the root or admin accounts.

Resolution

PTI on vRealize Operations Manager 6.7 can be disabled at your own risk by following the steps below:
  1. Log into the Admin UI as admin.
  2. Click the Take Offline button to take the vRealize Operations Manager cluster offline.
  3. Enter a Reason, and click OK.
  4. Log into the Primary node as root via SSH or Console.
  5. Open /boot/grub/menu.lst in a text editor.
  6. In the line(s) starting with kernel, change pti=on to pti=off.
Example: kernel /vmlinuz-3.0.101-108.21-trace root=/dev/sda3 append   resume=/dev/sda2 splash=silent showopts vga=0x311 elevator=noop pti=off noexec=on nousb audit=1​

Note: Change the pti= entry on all kernel lines.
  1. Save and close the file.
  2. Repeat steps 4-7 on all other nodes in the cluster.
  3. Issue a Guest Restart on each node via the vSphere Client.
  4. Log into the Admin UI as admin.
  5. Click the Bring Online button to bring the vRealize Operations Manager cluster online.


Additional Information

Impact/Risks:
Potential Meltdown or Spectre related breaches may occur if unprivileged users are added to the vApp and PTI is disabled.