6.0

Table Of Contents
Getting Started with vSphere Command-Line Interfaces
26 VMware, Inc.
vicfg-authconfigallowsyoutoremotelyconfigureActiveDirectorysettingsonESXihosts.Youcanlist
supportedandactiveauthenticationmechanisms,listthecurrentdomain,andjoinorpartfromanActive
Directorydomain.BeforeyourunthecommandonanESXihost,youmustpreparethehost.
To prepare ESXi hosts for Active Directory Integration
1Makesurethe
ESXisystemandtheActiveDirectoryserverareusingthesametimezonebyconfiguring
ESXiandADtousesameNTPserver.
TheESXisystem’stimezoneisalwayssettoUTC.
2ConfiguretheESXisystem’sDNStobeintheActiv eDirectorydomain.
Youcanrunvicfg-authconfigtoaddthe
hosttothedomain.Auserwhorunsvicfg-authconfigto
configureActiveDirectorysettingsmusthavetheappropriateActiveDirectorypermissions,andmusthave
administrativeprivilegesontheESXihost.Youcanrunthecommanddirectlyagainstthehostoragainsta
vCenterServersystem,specifyingthehostwith--vihost.
To set up Active Directory
1InstalltheESXihost,asexplainedinthevSphereInstallationandSetupdocumentation.
2InstallWindowsActiveDirectoryonaWindowsServerthatrunsWindows2000,Windows2003,or
Windows2008.SeetheMicrosoftWebsiteforinstructionsandbestpractices.
3SynchronizetimebetweentheESXisystemandWindowsActiveDirectory(AD).
4TestthattheWindowsADServercanpingtheESXihostbyusingthehostname.
ping <ESX_hostname>
5Runvicfg-authconfigtoaddthehosttotheActiveDirectorydomain.
vicfg-authconfig --server=<ESXi Server IP Address>
--username=<ESXi Server Admin Username>
--password=<ESXi Server Admin User's Password>
--authscheme AD --joindomain <AD Domain Name>
--adusername=<Active Directory Administrator User Name>
--adpassword=<Active Directory Administrator User's Password>
Thesystempromptsforusernamesandpasswordsifyoudonotspecifythemonthecommandline.
Passwordsarenotechoedtothescreen.
6CheckthataSuccessfully Joined <Domain Name>messageappears.
7VerifytheESXihostisintheintendedWindowsADdomain.
vicfg-authconfig --server XXX.XXX.XXX.XXX --authscheme AD -c
YouarepromptedforausernameandpasswordfortheESXisystem.
Updating Hosts
Whenyouaddcustomdriversorpatchestoahost,theprocessiscalledanupdate.
UpdateESXi4.0andESXi4.1hostswiththevihostupdatecommand,asdiscussedinthevSphere
CommandLineInterfaceInstallationandReferenceGuideincludedinthevSphere4.1documentationset.
UpdateESXi5.0hostswithesxcli software vibcommandsdiscussedinthevSphereUpgrade
documentationincludedinthevSphere5.0documentationset.Youcannotrunthevihostupdate
commandagainstESXi5.0orlater.
UpdateESXi5.1hostswithesxcli software vibcommandsdiscussedinthevSphereUpgrade
documentationincludedinthevSphere5.1documentationset.
I
MPORTANTAllhoststhatjoinActiveDirectorymustalsobemanagedbyanNTPServertoavoidissueswith
clockskewsandKerberostickets.