Solved

ESXi Shell Active Directory Authentication

Posted on 2016-07-27
5
85 Views
Last Modified: 2016-08-04
I need to be able to authenticate via SSH using ADS authentication... How do you get this setup?

Once setup, we wont be using root to authenticate via SSH into the esxi console.
0
Comment
Question by:Indyrb
  • 3
  • 2
5 Comments
 
LVL 117

Expert Comment

by:Andrew Hancock (VMware vExpert / EE MVE)
Comment Utility
What is very important is that ESXi host time, is synced to the same time source as your Active Directory domain controllers.

then you add the ESXi Host to the Domain, and then you may need to create an Active Directory group and add ESXi Admins into that group.

see this VMware KB for details

Configuring the ESXi host with Active Directory authentication (2075361)
0
 

Author Comment

by:Indyrb
Comment Utility
is this for accessing the esxi server via SSH or logining into the ESXi box via webclient or FAT client.  I need mostly for SSH access
0
 
LVL 117

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE) earned 500 total points
Comment Utility
SSH and/or Legacy vSphere Client direct to ESXi!
0
 

Author Comment

by:Indyrb
Comment Utility
Sorry to bother you, but if you join the esxi to the domain using above... How can you define what security groups can login and who can NOT.
0
 
LVL 117

Expert Comment

by:Andrew Hancock (VMware vExpert / EE MVE)
Comment Utility
there is a group which is created when you join it to the domain, or if not you create it.

which needs to match the configuration.

Change the Config.HostAgent.plugins.hostsvc.esxAdminsGroup setting to match the Administrator group that you want to use in the Active Directory. These settings takes affect within a minute and no reboot is required.

Source

Configuring the ESXi host with Active Directory authentication (2075361)
0

Featured Post

Free book by J.Peter Bruzzese, Microsoft MVP

Are you using Office 365? Trying to set up email signatures but you’re struggling with transport rules and connectors? Let renowned Microsoft MVP J.Peter Bruzzese show you how in this exclusive e-book on Office 365 email signatures. Better yet, it’s free!

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This article will show you how to create an ISO CD-ROM/DVD-ROM image (*.iso), and MD5 checksum signature, for use with VMware vSphere Hypervisor 6.5 (ESXi 6.5). It's a good idea to compare checksums, because many installations fail because of a corr…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now