<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't use Windows session authentication after change from machine account to LDAPS in vCenter™ Server Discussions</title>
    <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924119#M93422</link>
    <description>&lt;P&gt;o.k. i made some tests in my testing environment, there i have the same problem and i'm using LDAPS too.&lt;BR /&gt;&lt;BR /&gt;I joined the VCSA to the domain, but this has no change, only join isn't enough.&lt;BR /&gt;&lt;BR /&gt;After deleting the LDAPS identity source and created a Machine Account identity source, i was able to connect to the vCenter in the PowerShell without entering my credentials.&lt;BR /&gt;&lt;BR /&gt;So with IWA the login with the AD session is working but not with LDAPS.&lt;BR /&gt;&lt;BR /&gt;Will this work with LDAPS? Or is this a limitation in LDAPS?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2022 13:28:21 GMT</pubDate>
    <dc:creator>Raudi</dc:creator>
    <dc:date>2022-08-16T13:28:21Z</dc:date>
    <item>
      <title>Can't use Windows session authentication after change from machine account to LDAPS</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2923500#M93401</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;i changed a customers VCSA 7.0.3.00500 from machine account to LDAPS, now we get this error when trying to use the&amp;nbsp;Windows session authentication:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The specified target is unknown or unreachable&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;I found nothing regarding this error, what log-files should i search to find what goes wrong? Or what must i change to fix that error?&lt;BR /&gt;&lt;BR /&gt;All other is working, login with only username, domain\username or username@domain.&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 09:02:18 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2923500#M93401</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2022-08-12T09:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use Windows session authentication after change from machine account to LDAPS</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924109#M93421</link>
      <description>&lt;P&gt;The same i have now in the PowerShell:&lt;BR /&gt;&lt;BR /&gt;VERBOSE: Attempting to connect using SSPI&lt;BR /&gt;VERBOSE: Reversely resolved 'vc' to 'vc.domain.intern'&lt;BR /&gt;VERBOSE: SSPI Kerberos: Acquired credentials for user 'domain\user'&lt;BR /&gt;VERBOSE: SSPI Kerberos: InitializeSecurityContext failed for target 'host/vc.domain.intern'. Error code: 0x80090303&lt;BR /&gt;VERBOSE: Connect using SSPI was unsuccessful&lt;BR /&gt;&lt;BR /&gt;I found something with google, that the VCSA still needs to be a member of the AD, is that possible?&lt;BR /&gt;&lt;BR /&gt;Perhaps i need to rejoin the VCSA to the AD but then still use the LDAPS for authentication and not the machine account?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 13:49:50 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924109#M93421</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2022-08-16T13:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use Windows session authentication after change from machine account to LDAPS</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924119#M93422</link>
      <description>&lt;P&gt;o.k. i made some tests in my testing environment, there i have the same problem and i'm using LDAPS too.&lt;BR /&gt;&lt;BR /&gt;I joined the VCSA to the domain, but this has no change, only join isn't enough.&lt;BR /&gt;&lt;BR /&gt;After deleting the LDAPS identity source and created a Machine Account identity source, i was able to connect to the vCenter in the PowerShell without entering my credentials.&lt;BR /&gt;&lt;BR /&gt;So with IWA the login with the AD session is working but not with LDAPS.&lt;BR /&gt;&lt;BR /&gt;Will this work with LDAPS? Or is this a limitation in LDAPS?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 13:28:21 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924119#M93422</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2022-08-16T13:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use Windows session authentication after change from machine account to LDAPS</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924146#M93424</link>
      <description>&lt;P&gt;Seems to be by design.&lt;BR /&gt;&lt;BR /&gt;When using AD with LDAPS no session authentication is possible, that is the feedback from the support.&lt;BR /&gt;&lt;BR /&gt;The prerequisites for session authentication is that the vCenter is "joined" to the AD.&lt;BR /&gt;&lt;BR /&gt;Will be nice when such informations will be written more clear in the documentation or in several KB articles, for example here:&amp;nbsp;&lt;A href="https://kb.vmware.com/s/article/78506" target="_blank"&gt;Deprecation of Integrated Windows Authentication (78506) (vmware.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 15:18:53 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/Can-t-use-Windows-session-authentication-after-change-from/m-p/2924146#M93424</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2022-08-16T15:18:53Z</dc:date>
    </item>
  </channel>
</rss>

