Search the VMware Knowledge Base (KB)
View by Article ID

Setting up Kerberos authentication for vCloud Director (2015986)

  • 2 Ratings

Purpose

This article provides steps to set up Kerberos authentication for vCloud Director (vCD).

Resolution

Notes:
  • Ensure to note the use of upper and lower case alphabets in this procedure.
  • This article assumes these sample domain name and host name:
    • Domain name in Active Directory - abcd.com
    • Hostname for the Active Directory server - xyz.abcd.com

To set up Kerberos for vCD:

  1. Open the /etc/hosts file located in your vCloud Director cell machine using a text editor.
  2. Add the entry for the Active Directory host and the IP address to resolve the hostname, if this is not resolving through DNS.

    For example, if the IP address of the AD server is 192.168.1.1, add the entry:

    192.168.1.1 xyz.abcd.com xyz

  3. In the vCloud Director user interface, from either the system page or from within an Organization, navigate to Administration > LDAP.
  4. In this settings page, add the server name as xyz.abcd.com and provide a proper base distinguished name for Active Directory.
  5. Select Kerberos as the Authentication method.
  6. Click Edit All Realms to add a realm and DNS for this setup.
  7. Add ABCD.COM as the realm and xyz.abcd.com as the kdc.
  8. In the DNS tab, add .abcd.com as the DNS for your realm.
  9. After adding the realm properties, in the main LDAP settings page, select the realm from the dropdown list.
  10. Give a username similar to user1@abcd.com and the password to authenticate.
  11. Under Domain/Users in the Active Directory server, create a user, such as user1, and give an appropriate password.
  12. Run this command on the Active Directory machine:

    setspn -A LDAP/user1.ABCD.COM user1

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 2 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.

What can we do to improve this information? (4000 or fewer characters)




Please enter the Captcha code before clicking Submit.
  • 2 Ratings
Actions
KB: