Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

VMWARE SSO 5.5 : advice needed for identity source type

Posted on 2014-01-17
3
Medium Priority
?
721 Views
Last Modified: 2014-07-22
I am looking at this screen ID an It looks like SSO automaticly uses the machine account to connect to and browse AD. I am not sure IF I have a good reason to use the SPN and UPN for this , it seems like it is not needed . I am not going to rename the Vcenter server and I am able to add users from the domain . I have never seen this before

the domain name is DS.companyname.com and I know this is redundant and can fail over from one domain controller to another

1. is there any reason I cannot use this configuration as is?

2.what is the difference between " active directory ( integrated Windows authentication )

and " active directory as LDAP server"??????

thanks
0
Comment
Question by:NAMEWITHELD12
3 Comments
 
LVL 124

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 1000 total points
ID: 39788925
1. is there any reason I cannot use this configuration as is?

But I would use Active Directory ( integrated Windows authentication

2.what is the difference between " active directory ( integrated Windows authentication )

and " active directory as LDAP server"??????

see here, gives an explanation in the documents,

http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html

Add you Domain as an Indentity Source, for AD users to be able to login.
0
 
LVL 13

Assisted Solution

by:Abhilash
Abhilash earned 1000 total points
ID: 39788954
You  can use your environment as is. As far you do not have problems with adding the domain accounts and give permissions on vcenter you should not have any issues.

There is a really good article of connecting AD(IWA) with local account or SPN and UPN.
http://wahlnetwork.com/2013/09/09/using-active-directory-integrated-windows-authentication-sso-5-5/

For difference between them, see the VMware documentation.
http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html
0
 
LVL 1

Author Comment

by:NAMEWITHELD12
ID: 39789046
SO , it looks like you 2 agree , I have looked at the WAHLnetwork link about and found that not having a service account express is a reason within it self to use the machine account

I am going to leave the config "AS-IS"

thanks !!!!!
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question