Solved

VMWARE SSO 5.5 : advice needed for identity source type

Posted on 2014-01-17
3
672 Views
Last Modified: 2014-07-22
I am looking at this screen ID an It looks like SSO automaticly uses the machine account to connect to and browse AD. I am not sure IF I have a good reason to use the SPN and UPN for this , it seems like it is not needed . I am not going to rename the Vcenter server and I am able to add users from the domain . I have never seen this before

the domain name is DS.companyname.com and I know this is redundant and can fail over from one domain controller to another

1. is there any reason I cannot use this configuration as is?

2.what is the difference between " active directory ( integrated Windows authentication )

and " active directory as LDAP server"??????

thanks
0
Comment
Question by:NAMEWITHELD12
3 Comments
 
LVL 118

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE) earned 250 total points
ID: 39788925
1. is there any reason I cannot use this configuration as is?

But I would use Active Directory ( integrated Windows authentication

2.what is the difference between " active directory ( integrated Windows authentication )

and " active directory as LDAP server"??????

see here, gives an explanation in the documents,

http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html

Add you Domain as an Indentity Source, for AD users to be able to login.
0
 
LVL 13

Assisted Solution

by:Abhilash
Abhilash earned 250 total points
ID: 39788954
You  can use your environment as is. As far you do not have problems with adding the domain accounts and give permissions on vcenter you should not have any issues.

There is a really good article of connecting AD(IWA) with local account or SPN and UPN.
http://wahlnetwork.com/2013/09/09/using-active-directory-integrated-windows-authentication-sso-5-5/

For difference between them, see the VMware documentation.
http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html
0
 
LVL 1

Author Comment

by:NAMEWITHELD12
ID: 39789046
SO , it looks like you 2 agree , I have looked at the WAHLnetwork link about and found that not having a service account express is a reason within it self to use the machine account

I am going to leave the config "AS-IS"

thanks !!!!!
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When converting a physical machine to a virtual machine using VMware vCenter Converter Standalone or vCenter Converter Enterprise, if an adapter type is not selected during the initial customization the resulting virtual machine may contain an IDE d…
In this article, I will show you HOW TO: Perform a Physical to Virtual (P2V) Conversion the easy way from a computer backup (image).
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now