5.0

Table Of Contents
vSphere Management Assistant Guide
16 VMware, Inc.
Troubleshooting Unattended Authentication
IfyouarenotabletoauthenticatefromvMAorcannotaddvMAtothedomaincontroller,verifythefollowing
conditions:
YourDNSserversetupinvMAresolvestheIPaddressorhostnameofthevCenterservertoafully
qualifieddomainname(FQDN)andthattheFQDNcontainsthedomainnametowhichvMAisadded.
Thecommandvifp listserversshowsthenameofvCenterserverastheFQDNthatcontainsthe
domainnametowhichvMAisaddedasthesuffix.
ThedateandtimesettingsonvMA,thedomaincontrollerandthevCenterserverarethesame.Verifythe
timezoneaswell.Thetimemayvarybyanhour,butalargetimeskewmightcauseauthentication
problems.
Enable the vi-user Account
Aspartofconfiguration,vMAcreatesaviuseraccountwithnopassword.However,youcannotusethe
viuseraccountuntilyouhavespecifiedaviuserpassword.
To enable the vi-user account
1LogintovMAasviadmin.
2RuntheLinuxpasswdcommandforviuserasfollows:
sudo passwd vi-user
IfthisisthefirsttimeyouusesudoonvMA,amessageaboutrootuserprivilegesappears,andyouare
promptedfortheviadminpassword.
3Specifytheviadminpassword.
4Whenprompted,typeandconfirmthepasswordforviuser.
AftertheviuseraccountisenabledonvMA,
ithasnormalprivilegesonvMAbutisnotinthesudoerslist.
WhenyouaddESXitargetservers,vMAcreatestwousersoneachtarget:
viadminhasadministrativeprivilegesonthetargetsystem.
viuserhasreadonlyprivilegesonthetargetsystem.vMAcreatesviuseroneachtargetthatyouadd,
evenifviuserisnotcurrentlyenabledonvMA.
WhenauserisloggedintovMAasviuser,vMAusesthataccountontargetESXihosts,andthe
usercanrun
onlycommandsontargetESXihoststhatdonotrequireadministrativeprivileges.
vMA User Account Privileges
Table 21liststheprivilegesthatthedifferentuseraccountshaveforvCLIusageagainstdifferenttargets.
I
MPORTANTTheviuseraccounthaslimitedprivilegesonthetargetESXihostsandcannotrunany
commandsthatrequiresudoexecution.YoucannotuseviusertoruncommandsforActiveDirectorytargets
(ESXiorvCenterServer).ToruncommandsfortheActiveDirectorytargets,usethevi-adminuseror
login
asanActiveDirectoryusertovMA.
Table 2-1. Account Privileges for vCLI Usage
Target
Authentication
Policy vi-admin vi-user domain user
ESXifpauthYYN
ESXi adauth Y N Y
vCenterServer fpauth Y N N
vCenterServer adauth Y N Y