2.5

Table Of Contents
ACE Management Server Administrator’s Manual
38 VMware, Inc.
Create Users and Groups for Integration with Active Directory
TouseActiveDirectoryforauthenticatingusers,adduserstoanActiveDirectory
groupandcreateausersothatACEManagementServercanqueryLDAP.
WhenyouconfigureACEManagementServertouseLDAP,followtheseguidelinesto
avoidnegativelyaffectingperformance:
ThedefaultdomainisthedomainforwhichtheLDAPhostisadomaincontroller.
Thequeryuserisauserinthedefaultdomain.
Theadminusergroupisagroupthatexistsinthedefaultdomain.
IntegratingwithActiveDirectorythroughLDAPisimplementeddifferentlyinthe
WindowsbasedACEManagementServerthanintheLinuxbasedACEManagement
Server.TheoperatingsystemsdifferinthelibrariestheyusetoconnecttoActive
Directory
andtheexternaldatabasestheysupport.TheWindowsACEManagement
ServerusestheWinLDAPlibrarybundledwiththeWindowsoperatingsystem.
The LinuxACEManagementServerusesathirdpartyKerberosLibraryandOpenSSL.
VMwareinternaltestingresultsindicatethattheWindowsimplementationisprovides
betterperformancethanLinux.
To create users and groups for integration with Active Directory
1 Createauser
thatACEManagementServercanusetoconnecttotheLDAPserver
anduseforquerying.
MakeanoteofthesAMAccountNamevalueforthatuser(forexample,aceuser.)
2 CreateanACEAdministratorsgroupinthedomain.
3AddACEadministratoruserstotheACEAdministratorsgroup.
4 (Optional)CreateaHelpDesk
groupandassignuserstoitfortheHelpDeskrole.
YoucanlogintotheHelpDeskWebapplicationwithyouradministrativeLDAP
credentialsorpassword.CreatingaHelpDeskroleallowsyoutopermitcertain
userstoperformHelpDesktasksfromwithintheHelpDeskapplicationbut
does
notgivethemaccesstootheradministrativetools.