<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>VMware Communities: Message List - VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
    <link>http://communities.vmware.com/community/vmtn/vi/esx3.5?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Tue, 28 Aug 2007 20:47:21 GMT</pubDate>
    <generator>Clearspace 1.10.12 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2007-08-28T20:47:21Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735940?tstart=0#735940</link>
      <description>The file in question is the authorization.xml which has the users that the VIclient will use to connect.  This list of users is different then the ones used for ssh</description>
      <pubDate>Tue, 28 Aug 2007 20:47:21 GMT</pubDate>
      <author>sbeaver</author>
      <guid>http://communities.vmware.com/message/735940?tstart=0#735940</guid>
      <dc:date>2007-08-28T20:47:21Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735895?tstart=0#735895</link>
      <description>Super!&lt;br /&gt;
&lt;br /&gt;
Good to know.  Thanks.</description>
      <pubDate>Tue, 28 Aug 2007 20:07:28 GMT</pubDate>
      <author>hicksj</author>
      <guid>http://communities.vmware.com/message/735895?tstart=0#735895</guid>
      <dc:date>2007-08-28T20:07:28Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735893?tstart=0#735893</link>
      <description>As per my previous post - I can add my AD user in VIClient as an admin under the permissions tab and then it works.</description>
      <pubDate>Tue, 28 Aug 2007 20:06:48 GMT</pubDate>
      <author>TheBigQ</author>
      <guid>http://communities.vmware.com/message/735893?tstart=0#735893</guid>
      <dc:date>2007-08-28T20:06:48Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735892?tstart=0#735892</link>
      <description>Ok, got it! Using this link:&lt;br /&gt;
&lt;br /&gt;
&lt;a class="jive-link-external" href="http://blog.baeke.info/blog/_archives/2006/10/13/2414173.html"&gt;http://blog.baeke.info/blog/_archives/2006/10/13/2414173.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
If I go into the "permissions" tab in the VIClient, add my AD account as an administrator then it works.&lt;br /&gt;
&lt;br /&gt;
Thanks for the amazingly quick responses though. &lt;img class="jive-emoticon" border="0" src="http://communities.vmware.com/images/emoticons/happy.gif" alt=":)" /&gt;</description>
      <pubDate>Tue, 28 Aug 2007 20:05:48 GMT</pubDate>
      <author>TheBigQ</author>
      <guid>http://communities.vmware.com/message/735892?tstart=0#735892</guid>
      <dc:date>2007-08-28T20:05:48Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735882?tstart=0#735882</link>
      <description>Check out the posting here:&lt;br /&gt;
&lt;br /&gt;
&lt;a class="jive-link-external" href="http://www.vmware.com/community/thread.jspa?messageID=635376&amp;#38;#635376"&gt;http://www.vmware.com/community/thread.jspa?messageID=635376&amp;#38;#635376&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
This provides pam changes that appear to work.  Note: I've not tested them, so cannot verify whether it works or possibly compromises security.&lt;br /&gt;
&lt;br /&gt;
Message was edited by: &lt;br /&gt;
        hicksj&lt;br /&gt;
    Followup note:  Those are legacy settings, similar to what I did in ESX 2.5.  They may work, but there is probably a better way.</description>
      <pubDate>Tue, 28 Aug 2007 20:00:46 GMT</pubDate>
      <author>hicksj</author>
      <guid>http://communities.vmware.com/message/735882?tstart=0#735882</guid>
      <dc:date>2007-08-28T20:00:46Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735876?tstart=0#735876</link>
      <description>Ah, you are right. I had used "useradd" to add the user - whilst the VIClient still doesn't work, SSH access does.&lt;br /&gt;
&lt;br /&gt;
I'll take a look at that file now.</description>
      <pubDate>Tue, 28 Aug 2007 19:54:54 GMT</pubDate>
      <author>TheBigQ</author>
      <guid>http://communities.vmware.com/message/735876?tstart=0#735876</guid>
      <dc:date>2007-08-28T19:54:54Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735873?tstart=0#735873</link>
      <description>That will setup access for SSH sessions, but doesn't authorize the user to access the host via the VIC.&lt;br /&gt;
&lt;br /&gt;
I used to have this setup so I could access the MUI in ESX2.5 using AD credentials.  The pam setup in ESX3 is different, and I've not had reason to provide this capability in ESX3, so haven't investigated further.  There's probably a small change that needs to be applied to /etc/pam.d/vmware-authd</description>
      <pubDate>Tue, 28 Aug 2007 19:52:07 GMT</pubDate>
      <author>hicksj</author>
      <guid>http://communities.vmware.com/message/735873?tstart=0#735873</guid>
      <dc:date>2007-08-28T19:52:07Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
    </item>
    <item>
      <title>Re: VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735867?tstart=0#735867</link>
      <description>You need to create a corresponding user with useradd apparently ...&lt;br /&gt;
&lt;br /&gt;
Quote resource: &lt;br /&gt;
&lt;br /&gt;
For every user that you want to enable access through authentication to&lt;br /&gt;
Active Directory, you must also create a corresponding user on the ESX Server system using the useradd command.&lt;br /&gt;
&lt;br /&gt;
/Quote&lt;br /&gt;
&lt;p /&gt;
That to me sounds like you need to create the user locally on ESX and on AD.&lt;br /&gt;
&lt;br /&gt;
Haven't played with it yet though ...&lt;br /&gt;
&lt;br /&gt;
C.</description>
      <pubDate>Tue, 28 Aug 2007 19:49:53 GMT</pubDate>
      <author>cemetric</author>
      <guid>http://communities.vmware.com/message/735867?tstart=0#735867</guid>
      <dc:date>2007-08-28T19:49:53Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
    </item>
    <item>
      <title>VIClient cannot access ESX 3.0.2 box using AD credenitals.</title>
      <link>http://communities.vmware.com/message/735860?tstart=0#735860</link>
      <description>Hey all,&lt;br /&gt;
&lt;br /&gt;
Using this guide:&lt;br /&gt;
&lt;br /&gt;
&lt;a class="jive-link-external" href="http://www.vmware.com/vmtn/resources/582"&gt;http://www.vmware.com/vmtn/resources/582&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I've got my ESX box to auth users against AD. The problem is, when I try to logon with the VI Client I get "Error Connecting - Permission to perform this operation was denied.". If I enter the wrong password, it says "login failed due to a bad username or password." so it seems able to work out who I am.&lt;br /&gt;
&lt;br /&gt;
If I pick a user who I've not run "useradd" for I just got the "login failed" message again.&lt;br /&gt;
&lt;br /&gt;
In the server messages I get:&lt;br /&gt;
&lt;br /&gt;
Aug 28 15:37:48 server vmware-authd(pam_unix)[1842]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=  user=myaccount&lt;br /&gt;
Aug 28 15:37:49 server vmware-hostd[1842]: pam_krb5: authentication succeeds for `myaccount&lt;br /&gt;
Aug 28 15:37:49 server vmware-hostd[1842]: Accepted password for user myaccount from 1.2.3.4&lt;br /&gt;
&lt;br /&gt;
Any ideas what else I need to do? NTP is running so the time is sync'd. &lt;br /&gt;
&lt;br /&gt;
I tried adding the user account to the root group, but it still didn't work. I've seen other posts talk about adding it to the administrators/manager group but I know how as they don't seem to exist. Am I missing something?&lt;br /&gt;
&lt;br /&gt;
Thanks!</description>
      <pubDate>Tue, 28 Aug 2007 19:39:38 GMT</pubDate>
      <author>TheBigQ</author>
      <guid>http://communities.vmware.com/message/735860?tstart=0#735860</guid>
      <dc:date>2007-08-28T19:39:38Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:replyCount>8</clearspace:replyCount>
    </item>
  </channel>
</rss>

