6.0.3

Table Of Contents
2 Click the Manage tab and click .
3 Under System, select Authentication Services.
The Authentication Services page displays the directory service and domain seings.
Using vSphere Authentication Proxy
When you use the vSphere Authentication Proxy, you do not need to transmit Active Directory credentials
to the host. Users supply the domain name of the Active Directory server and the IP address of the
authentication proxy server when they add a host to a domain.
vSphere Authentication Proxy is especially helpful when used in conjunction with Auto Deploy. You set up
a reference host that points to Authentication Proxy and set up a rule that applies the reference host's prole
to any ESXi host provisioned with Auto Deploy. Even if you use vSphere Authentication Proxy in an
environment that uses certicates that are provisioned by VMCA or third-party certicates, the process
works seamlessly as long as you follow the instructions for using custom certicates with Auto Deploy. See
“Use Custom Certicates with Auto Deploy,” on page 171.
N You cannot use vSphere Authentication Proxy in an environment that supports only IPv6.
Install or Upgrade vSphere Authentication Proxy
Install vSphere Authentication Proxy to enable ESXi hosts to join a domain without using Active Directory
credentials. vSphere Authentication Proxy enhances security for PXE-booted hosts and hosts that are
provisioned using Auto Deploy by removing the need to store Active Directory credentials in the host
conguration.
If an earlier version of the vSphere Authentication Proxy is installed on your system, this procedure
upgrades the vSphere Authentication Proxy to the current version.
You can install vSphere Authentication Proxy on the same machine as the associated vCenter Server, or on a
dierent machine that has network connection to the vCenter Server. vSphere Authentication Proxy is
supported with vCenter Server versions 5.0 and later.
The vSphere Authentication Proxy service binds to an IPv4 address for communication with vCenter Server,
and does not support IPv6. The vCenter Server instance can be on a host machine in an IPv4-only, IPv4/IPv6
mixed-mode, or IPv6-only network environment, but the machine that connects to the vCenter Server
through the vSphere Web Client must have an IPv4 address for the vSphere Authentication Proxy service to
work.
Prerequisites
n
Install Microsoft .NET Framework 3.5 on the machine where you want to install vSphere Authentication
Proxy.
n
Verify that you have administrator privileges.
n
Verify that the host machine has a supported processor and operating system.
n
Verify that the host machine has a valid IPv4 address. You can install vSphere Authentication Proxy on
a machine in an IPv4-only or IPv4/IPv6 mixed-mode network environment, but you cannot install
vSphere Authentication Proxy on a machine in an IPv6-only environment.
n
If you are installing vSphere Authentication Proxy on a Windows Server 2008 R2 host machine,
download and install the Windows hotx described in Windows KB Article 981506 on the
support.microsoft.com Web site. If this hotx is not installed, the vSphere Authentication Proxy
Adapter fails to initialize. This problem is accompanied by error messages in camadapter.log similar to
Failed to bind CAM website with CTL and Failed to initialize CAMAdapter.
n
Download the vCenter Server installer.
vSphere Security
192 VMware, Inc.