Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

Enabling Windows Single Sign-on support in VirtualCenter 2.5 Update 2 (1006611)

Purpose

As of VMware VirtualCenter 2.5 Update 2, the Virtual Infrastructure Client has the ability to use Windows Single Sign-on to log in on to a VirtualCenter Server. The Windows Single Sign-on feature uses the currently logged on user credentials to login to the VirtualCenter Server. This article describes configuring the VI Client to utilize Windows Single Sign-on.

Resolution

To enable Windows Single Sign-on follow these steps:
  1. Log in to a workstation where the VI Client is installed.
  2. Right-click the desktop and select New > Shortcut.
  3. In the Create Shortcut Wizard, click Browse and navigate to the location of the VpxClient.exe program and click OK.

    Note: By default it is located in C:\Program Files\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\

  4. After the full path is in the Type the location of the item field append -passthroughAuth -s <VirtualCenter Server hostname> to the end of the line, where <VirtualCenter Server hostname> is the hostname or IP Address of the VirtualCenter instance you want to connect to.
  5. Click Next.
  6. Give a Name for the shortcut.
  7. Click Finish.
After the shortcut has been created, double-click on the new shortcut, and you are logged into the VirtualCenter Server using the currently logged in credentials.
 
Note: If the currently logged in user does not have appropriate permissions to VirtualCenter log in fails.

Additional Information

By default VirtualCenter uses the "Negotiate" Security Support Provider Interface (SSPI) from the Microsoft SSPI API for communication.  Since VMware has fully implemented this interface, it is possible to change this behaviour to use "Kerberos" instead.  
 
To change the default security SSP to Kerberos add the <sspiProtocol>Kerberos</sspiProtocol> parameter to the <vpxd> node of the vpxd.cfg file on the VirtualCenter server.
 
Note: In a default configuration the vpxd.cfg file is located in the C:\Documents and Settings\All Users\Application Data\VMware\VMware VirtualCenter directory .
 
After the change is complete, the vpxd.cfg file appears similar to:
 
<config>
 ...
  <vpxd>
     ...
     <sspiProtocol>Kerberos</sspiProtocol>
  </vpxd>
...
</config>

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 2 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 2 Ratings
Actions
KB: