To be able to create and use an SPN in SSO 5.5, ensure that:
- Log in to vCenter Server using a domain administrator account.
Note: If using the vCenter Server Appliance 5.1 (VCSA), these actions can be performed on a Windows workstation joined to the same domain as the VCSA.
- Open an elevated command prompt. For more information, see Opening a command or shell prompt (1003892).
- Type echo %UserDNSDomain%and press Enter. This echoes the DNS domain name in which the current Windows system resides.
For example:
C:\>echo %UserDNSDomain%
You see output similar to:
child-domain.vmware.com
- Type setspn -Q sts/DNS_domain_name and press Enter. This verifies that no other SPNs have been created on this domain.
For example:
C:\>setspn -Q STS/child-domain.vmware.com
You see output similar to:
No such SPN Found.
Note: If a SPN is found, consult your Active Directory administrator.