6.0.3

Table Of Contents
What to do next
Import the certicate to ESXi.
Import a Proxy Server Certificate to ESXi
To authenticate the vSphere Authentication Proxy server to ESXi, upload the proxy server certicate to ESXi.
You use the vSphere Web Client user interface to upload the vSphere Authentication Proxy server certicate
to the ESXi host.
Prerequisites
Install the vSphere Authentication Proxy service (CAM service) on a host. See “Install or Upgrade vSphere
Authentication Proxy,” on page 189.
Export the vSphere Authentication Proxy server certicate as described in “Export vSphere Authentication
Proxy Certicate,” on page 194.
Procedure
1 Browse to the host, click the Manage tab, click , and click Authentication Services.
2 Click Import .
3 Enter the full path to the authentication proxy server certicate le on the host and the IP address of the
authentication proxy server.
Use the form [datastore name] le path to enter the path to the proxy server.
4 Click OK.
Use vSphere Authentication Proxy to Add a Host to a Domain
When you join a host to a directory service domain, you can use the vSphere Authentication Proxy server
for authentication instead of transmiing user-supplied Active Directory credentials.
You can enter the domain name in one of two ways:
n
name.tld (for example, domain.com): The account is created under the default container.
n
name.tld/container/path (for example, domain.com/OU1/OU2): The account is created under a particular
organizational unit (OU).
Prerequisites
n
Connect to a vCenter Server system with the vSphere Web Client.
n
If ESXi is congured with a DHCP address, set up the DHCP range.
n
If ESXi is congured with a static IP address, verify that its associated prole is congured to use the
vSphere Authentication Proxy service to join a domain so that the authentication proxy server can trust
the ESXi IP address.
n
If ESXi is using a VMCA-signed certicate, verify that the host has been added to vCenter Server. This
allows the authentication proxy server to trust ESXi.
n
If ESXi is using a CA-signed certicate and is not provisioned by Auto Deploy, verify that the CA
certicate has been added to the local trust certicate store of the authentication proxy server as
described in “Congure a Host to Use the vSphere Authentication Proxy for Authentication,” on
page 193.
n
Authenticate the vSphere Authentication Proxy server to the host.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 195