Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

vCenter 5.5 SSO Issue - cannot add rights

Posted on 2014-10-30
5
344 Views
Last Modified: 2014-11-06
Greetings,

We have 2 vCenters in a 4 node linked group that cannot have SSO permissions added to them. The servers do reside in a sub-domain of the root domain, but have the identity source showing as the root domain. When attempting to add users or groups to SSO rights (user/administrator), the AD search finds the user/group fine and looks like it will add, but does not. We've tried refreshing/logout-login/rebooting. Neither users/groups from the root or sub domains work.

 I have not found any articles specifically for this on the web or VMware's site.

Thanks in advance,
Rick
0
Comment
Question by:Virene
  • 3
  • 2
5 Comments
 
LVL 19

Accepted Solution

by:
compdigit44 earned 500 total points
ID: 40422901
What OS are your vCenter servers also what is your vCenter build number?

Have you view the SSO logs for any errors?
http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2033430
0
 

Author Closing Comment

by:Virene
ID: 40424604
Thanks for your response Compdigit44.
I got a response from VMware support - they said, "you will need to remove the xxx.com identity source as Integrated Windows Authentication, and add it back under AD over LDAP. Then, you can add the child domain as AD over LDAP as well."
0
 
LVL 19

Expert Comment

by:compdigit44
ID: 40425181
Interesting .. did they give an explanation WHY?
0
 

Author Comment

by:Virene
ID: 40426297
They did not explain. I questioned further and received this reply:
"One of the largest issues with AD over LDAP is that you have to hard code a domain controller for SSO to bind to. If that DC becomes unavailable, SSO cannot talk to AD. You cannot use a round-robin address either, it must be the name of an actual DC.

And, if the account used to authenticate to the DC changes (username, password) then the identity source must be updated before continuing to authenticate users.

The integrated windows authentication (IWA) is a much better option for most environments compared to AD over LDAP. Unless of course, you have the requirements that you thought you had.

Here's a link to the documentation about the different identity source options:
https://pubs.vmware.com/vsphere-55/topic/com.vmware.vsphere.security.doc/GUID-1F0106C9-0524-4583-9AC5-A748FD1DC4C5.html"

So, for us, we will stick with Integrated authentication vs. LDAP and have to use a single service account to administer SSO on the vCenters from sub-domains.
0
 
LVL 19

Expert Comment

by:compdigit44
ID: 40426419
good to know...

thanks
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

HOW TO: Upload an ISO image to a VMware datastore for use with VMware vSphere Hypervisor 6.5 (ESXi 6.5) using the vSphere Host Client, and checking its MD5 checksum signature is correct.  It's a good idea to compare checksums, because many installat…
In this article, I will show you HOW TO: Suppress Configuration Issues and Warnings Alert displayed in Summary status for ESXi 6.5 after enabling SSH or ESXi Shell.
Teach the user how to install ESXi 5.5 and configure the management network System Requirements: ESXi Installation:  Management Network Configuration: Management Network Testing:
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…

837 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question