7.3

Table Of Contents
6 Enter the appropriate information in the Server Location text box if you selected Active Directory over
LDAP, or enter information in the Join Domain Details text boxes if you selected Active Directory
(Integrated Windows Authentication).
Option Description
Server Location - Displayed when
Active Directory over LDAP is selected
n
If you want to use DNS Service Location to locate Active Directory domains,
leave the This Directory supports DNS Service Location check box
selected.
Note You cannot change the port assignment to 636 if you select this option.
A domain_krb.properties file, auto-populated with a list of domain
controllers, is created along with the directory. See About Domain Controller
Selection.
If the Active Directory requires STARTTLS encryption, select the This
Directory requires all connections to use STARTTLS check box in the
Certificates section and copy and paste the Active Directory Root CA
certificate in the SSL Certificate field.
n
If the specified Active Directory does not use DNS Service Location lookup,
deselect the check box beside This Directory supports DNS Service
Location in the Server Location fields and enter the Active Directory server
host name and port number in the appropriate text boxes.
Select the This Directory has a Global Catalog check box if the associated
Active Directory uses a global catalog. A global catalog contains a
representation of all objects in every domain in a multi-domain Active
Directory forest.
To configure the directory as a global catalog, see the Multi-Domain Single
Forest Active Directory Environment section in Active Directory
Environments.
If Active Directory requires access over SSL, select the This Directory
requires all connections to use SSL check box under the Certificates
heading and provide the Active Directory SSL certificate.
When you select this option, port 636 is used automatically and cannot be
changed.
Ensure that the certificate is in PEM format and includes the BEGIN
CERTIFICATE and END CERTIFICATE lines.
Join Domain Details - Displayed when
Active Directory (Integrated Windows
Authentication) is selected
Enter the appropriate credentials in the Domain Name, Domain Admin User
Name, and Domain Admin Password text boxes.
If the Active Directory requires STARTTLS encryption, select the This Directory
requires all connections to use STARTTLS check box in the Certificates
section and copy and paste the Active Directory Root CA certificate in the SSL
Certificate field.
Ensure that the certificate is in PEM format and includes the BEGIN
CERTIFICATE and END CERTIFICATE lines.
If the directory uses multiple domains, add the Root CA certificates for all
domains, one at a time.
Note If the Active Directory requires STARTTLS and you do not provide the
certificate, you cannot create the directory.
Configuring vRealize Automation
VMware, Inc. 92