5.1

Table Of Contents
Configuring LDAP Settings
You can configure Orchestrator to connect to a working LDAP server on your infrastructure to manage user
permissions.
If you are using secure LDAP over SSL, Windows Server 2003 or 2008, and AD, verify that the LDAP Server
Signing Requirements group policy is disabled on the LDAP server.
If you configure Orchestrator to work with LDAP, you will not be able to use the Orchestrator Web Client for
managing vSphere inventory objects.
IMPORTANT Multiple domains that are not in the same tree, but have a two-way trust, are not supported and
do not work with Orchestrator. The only configuration supported for multi-domain Active Directory is domain
tree. Forest and external trusts are not supported.
1 Import the LDAP Server SSL Certificate on page 39
If your LDAP server uses SSL, you can import the SSL certificate file to the Orchestrator configuration
interface and activate secure connection between Orchestrator and LDAP.
2 Generate the LDAP Connection URL on page 40
The LDAP service provider uses a URL to configure the connection to the directory server. To generate
the LDAP connection URL, you must specify the LDAP host, port, and root.
3 Specify the Browsing Credentials on page 42
Orchestrator must read your LDAP structure to inherit its properties. You can specify the credentials
that Orchestrator uses to connect to an LDAP server.
4 Define the LDAP User and Group Lookup Paths on page 42
You can define the users and groups lookup information.
5 Define the LDAP Search Options on page 43
You can customize the LDAP search queries and make searching in LDAP more effective.
6 Common Active Directory LDAP Errors on page 44
When you encounter the LDAP:error code 49 error message and experience problems connecting to your
LDAP authentication server, you can check which LDAP function is causing the problem.
Import the LDAP Server SSL Certificate
If your LDAP server uses SSL, you can import the SSL certificate file to the Orchestrator configuration interface
and activate secure connection between Orchestrator and LDAP.
You can import the LDAP SSL certificate from the SSL Trust Manager tab in the Orchestrator configuration
interface.
Prerequisites
n
If you are using LDAP servers, Windows 2003 or 2008, and AD, verify that the LDAP Server Signing
Requirements group policy is disabled on the LDAP server.
n
Obtain a self-signed server certificate or a certificate that is signed by a Certificate Authority.
n
Configure your LDAP server for SSL access. See the documentation of your LDAP server for instructions.
n
Explicitly specify the trusted certificate to perform the SSL authorization correctly.
Procedure
1 Log in to the Orchestrator configuration interface as vmware.
2 Click Network.
Chapter 5 Configuring the Orchestrator Server
VMware, Inc. 39