6.0.1

Table Of Contents
3 Enable Kerberos Authentication in Active Directory on page 160
If you use NFS 4.1 storage with Kerberos, you must add each ESXi host to an Active Directory domain
and enable Kerberos authentication. Kerberos integrates with Active Directory to enable single sign-on
and provides an additional layer of security when used across an insecure network connection.
What to do next
After you congure your host for Kerberos, you can create an NFS 4.1 datastore with Kerberos enabled.
Configure DNS for NFS 4.1 with Kerberos
When you use NFS 4.1 with Kerberos, you must change the DNS seings on ESXi hosts to point to the DNS
server that is congured to hand out DNS records for the Kerberos Key Distribution Center (KDC). For
example, use the Active Directory server address, if AD is used as a DNS server.
Procedure
1 In the vSphere Web Client, navigate to the host.
2 Click the Manage tab, and click Networking and select TCP/IP .
3 Select TCP/IP  and click the Edit icon.
4 Enter the DNS seing information.
Option Description
Domain
AD Domain Name
Preferred DNS server
AD Server IP
Search domains
AD Domain Name
Configure Network Time Protocol for NFS 4.1 with Kerberos
If you use NFS 4.1 with Kerberos, congure Network Time Protocol (NTP) to make sure all ESXi hosts on
the vSphere network are synchronized.
Procedure
1 Select the host in the vSphere inventory.
2 Click the Manage tab and click .
3 In the System section, select Time .
4 Click Edit and set up the NTP server.
a Select Use Network Time Protocol (Enable NTP client).
b Set the NTP Service Startup Policy.
c Enter the IP addresses of the NTP servers to synchronize with.
d Click Start or Restart in the NTP Service Status section.
5 Click OK.
The host synchronizes with the NTP server.
Chapter 16 Working with Datastores
VMware, Inc. 159