VMware vSphere

 View Only
  • 1.  Authentication methods

    Posted May 09, 2018 03:41 PM

    So i've taken over an environment setup by an MSP and trying to understand differences in authentication methods.  I have previously joined a domain during the setup of esxi / vsphere but here they are using SSO configuration which i am not familiar with.  So each host shows 'local authentication' but here we connecting with AD creds clearly due to the SSO.

    is one method preferred to the other?



  • 2.  RE: Authentication methods

    Posted May 09, 2018 04:19 PM

    It's important not to conflate ESXi authentication with vCenter authentication. If ESXi shows local auth, then users could only login with root or another local principle. In the case of vCenter, this uses SSO and may involve an external identity source like Active Directory. When logging into vCenter with domain credentials, you are accessing information on the ESXi hosts because vCenter communicates to them using a host-local account. The two are otherwise separate.



  • 3.  RE: Authentication methods

    Posted May 10, 2018 01:01 PM

    Thank you, perhaps i phrased this incorrectly.   Vcenter aside, after installation of esxi i can join to the domain, the option is there in configuration.  This would allow local (esxi) access via an AD account correct?  Is there a reason not to do this?  other than just simply limiting local access.



  • 4.  RE: Authentication methods
    Best Answer

    Posted May 10, 2018 01:12 PM

    Yes, it's possible, but the question is why. Why do you need your ESXi hosts to join the domain? Do you really need, on a regular basis, domain user accounts to have either direct console or SSH access into ESXi? There are use cases where this is so, however I find most people are under a false impression on what this does and, in most cases, it complicates configuration and opens up holes that do not need to be there.