6.0.3

Table Of Contents
Enable Smart Card Authentication
Enable smart card authentication to prompt for smart card and PIN combination to log in to the ESXi DCUI.
Prerequisites
n
Set up the infrastructure to handle smart card authentication, such as accounts in the Active Directory
domain, smart card readers, and smart cards.
n
Congure ESXi to join an Active Directory domain that supports smart card authentication. For more
information, see “Using Active Directory to Manage ESXi Users,” on page 189.
n
Use the vSphere Web Client to add root certicates. See “Certicate Management for ESXi Hosts,” on
page 160.
Procedure
1 In the vSphere Web Client, browse to the host.
2 Click the Manage tab and click .
3 Under System, select Authentication Services.
You see the current smart card authentication status and a list with imported certicates.
4 In the Smart Card Authentication panel, click Edit.
5 In the Edit Smart Card Authentication dialog box, select the Certicates page.
6 Add trusted Certicate Authority (CA) certicates, for example, root and intermediary CA certicates.
7 Open the Smart Card Authentication page, select the Enable Smart Card Authentication check box,
and click OK.
Disable Smart Card Authentication
Disable smart card authentication to return to the default user name and password authentication for ESXi
DCUI login.
Procedure
1 In the vSphere Web Client, browse to the host.
2 Click the Manage tab and click .
3 Under System, select Authentication Services.
You see the current smart card authentication status and a list with imported certicates.
4 In the Smart Card Authentication panel, click Edit.
5 On the Smart Card Authentication page, deselect the Enable Smart Card Authentication check box,
and click OK.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 197