Solved

VMWARE SSO 5.5 : advice needed for identity source type

Posted on 2014-01-17
3
696 Views
Last Modified: 2014-07-22
I am looking at this screen ID an It looks like SSO automaticly uses the machine account to connect to and browse AD. I am not sure IF I have a good reason to use the SPN and UPN for this , it seems like it is not needed . I am not going to rename the Vcenter server and I am able to add users from the domain . I have never seen this before

the domain name is DS.companyname.com and I know this is redundant and can fail over from one domain controller to another

1. is there any reason I cannot use this configuration as is?

2.what is the difference between " active directory ( integrated Windows authentication )

and " active directory as LDAP server"??????

thanks
0
Comment
Question by:NAMEWITHELD12
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 120

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 250 total points
ID: 39788925
1. is there any reason I cannot use this configuration as is?

But I would use Active Directory ( integrated Windows authentication

2.what is the difference between " active directory ( integrated Windows authentication )

and " active directory as LDAP server"??????

see here, gives an explanation in the documents,

http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html

Add you Domain as an Indentity Source, for AD users to be able to login.
0
 
LVL 13

Assisted Solution

by:Abhilash
Abhilash earned 250 total points
ID: 39788954
You  can use your environment as is. As far you do not have problems with adding the domain accounts and give permissions on vcenter you should not have any issues.

There is a really good article of connecting AD(IWA) with local account or SPN and UPN.
http://wahlnetwork.com/2013/09/09/using-active-directory-integrated-windows-authentication-sso-5-5/

For difference between them, see the VMware documentation.
http://pubs.vmware.com/vsphere-55/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html
0
 
LVL 1

Author Comment

by:NAMEWITHELD12
ID: 39789046
SO , it looks like you 2 agree , I have looked at the WAHLnetwork link about and found that not having a service account express is a reason within it self to use the machine account

I am going to leave the config "AS-IS"

thanks !!!!!
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article we will learn how to backup a VMware farm using Nakivo Backup & Replication. In this tutorial we will install the software on a Windows 2012 R2 Server.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question