6.0.3

Table Of Contents
Procedure
1 Browse to the host in the vSphere Web Client and click the Manage tab.
2 Click  and select Authentication Services.
3 Click Join Domain.
4 Enter a domain.
Use the form name.tld or name.tld/container/path.
5 Select Using Proxy Server.
6 Enter the IP address of the authentication proxy server.
7 Click OK.
Replace the Authentication Proxy Certificate for the ESXi Host
You can import a certicate from a trusted certicate authority from the vSphere Web Client
Prerequisites
n
Upload the authentication proxy certicate le to the ESXi host.
Procedure
1 In the vSphere Web Client, select the ESXi host.
2 In the  tab, select Authentication Services in the System area.
3 Click Import .
4 Enter the SSL certicate path and the vSphere Authentication Proxy server.
Configuring Smart Card Authentication for ESXi
You can use smart card authentication to log in to the ESXi Direct Console User Interface (DCUI) by using a
Personal Identity Verication (PIV), Common Access Card (CAC) or SC650 smart card instead of the default
prompt for a user name and password.
A smart card is a small plastic card with an embedded integrated circuit chip. Many government agencies
and large enterprises use smart card based two-factor authentication to increase the security of their systems
and comply with security regulations.
When smart card authentication is enabled on an ESXi host, the DCUI prompts you for a valid smart card
and PIN combination instead of the default prompt for a user name and password.
1 When you insert the smart card into the smart card reader, the ESXi host reads the credentials on it.
2 The ESXi DCUI displays your login ID, and prompts you for your PIN.
3 After you enter your PIN, the ESXi host matches it with the PIN stored on the smart card and veries
the certicate on the smart card with Active Directory.
4 After a successful verication of the smart card certicate, ESXi logs you in to the DCUI.
You can switch to user name and password authentication from the DCUI by pressing F3.
The chip on the smart card locks after a few consecutive incorrect PIN entries, usually three. If a smart card
is locked, only selected personnel can unlock it.
vSphere Security
196 VMware, Inc.