7.1

Table Of Contents
If you do not have the rights to join a domain, or if your company policy requires a custom location for the
computer object, you must ask your administrator to create the object and then join the connector machine
to the domain.
Procedure
1 Ask your Active Directory administrator to create the computer object in Active Directory in a location
determined by your company policy. You must provide the host name of the connector. Ensure that you
provide the fully-qualied domain name, for example server.example.com.
You can nd the host name in the Host Name column on the Connectors page in the administrative
console. Select Administration > Directories Management > Connectors.
2 After the computer object is created, click Join Domain on the Connectors page to join the domain
using any domain user account available in Directories Management.
About Domain Controller Selection
The domain_krb.properties le determines which domain controllers are used for directories that have DNS
Service Location (SRV records) lookup enabled. It contains a list of domain controllers for each domain. The
connector creates the le initially, and you must maintain it subsequently. The le overrides DNS Service
Location (SRV) lookup.
The following types of directories have DNS Service Location lookup enabled.
n
Active Directory over LDAP with the This Directory supports DNS Service Location option selected
n
Active Directory (Integrated Windows Authentication), which always has DNS Service Location lookup
enabled
When you rst create a directory that has DNS Service Location lookup enabled, a domain_krb.properties
le is created automatically in the /usr/local/horizon/conf directory of the virtual machine and is auto-
populated with domain controllers for each domain. To populate the le, the connector aempts to nd
domain controllers that are at the same site as the connector and selects two that are reachable and that
respond the fastest.
When you create additional directories that have DNS Service Location enabled, or add new domains to an
Integrated Windows Authentication directory, the new domains, and a list of domain controllers for them,
are added to the le.
You can override the default selection at any time by editing the domain_krb.properties le. As a best
practice, after you create a directory, view the domain_krb.properties le and verify that the domain
controllers listed are the optimal ones for your conguration. For a global Active Directory deployment that
has multiple domain controllers across dierent geographical locations, using a domain controller that is in
close proximity to the connector ensures faster communication with Active Directory.
You must also update the le manually for any other changes. The following rules apply.
n
The domain_krb.properties le is created in the virtual machine that contains the connector. In a typical
deployment, with no additional connectors deployed, the le is created in the Directories Management
service virtual machine. If you are using an additional connector for the directory, the le is created in
the connector virtual machine. A virtual machine can only have one domain_krb.properties le.
n
The le is created, and auto-populated with domain controllers for each domain, when you rst create a
directory that has DNS Service Location lookup enabled.
n
Domain controllers for each domain are listed in order of priority. To connect to Active Directory, the
connector tries the rst domain controller in the list. If it is not reachable, it tries the second one in the
list, and so on.
n
The le is updated only when you create a new directory that has DNS Service Location lookup enabled
or when you add a domain to an Integrated Windows Authentication directory. The new domain and a
list of domain controllers for it are added to the le.
Chapter 2 Configuring Tenant Settings
VMware, Inc. 93