5.0
Table Of Contents
- vSphere Management Assistant Guide
- Contents
- About This Book
- Introduction to vMA
- Getting Started with vMA
- Hardware Requirements
- Software Requirements
- Required Authentication Information
- Deploy vMA
- Configure vMA at First Boot
- vMA Console and Web UI
- Configure vMA for Active Directory Authentication
- Configure Unattended Authentication for Active Directory Targets
- Enable the vi-user Account
- vMA User Account Privileges
- Add Target Servers to vMA
- Running vSphere CLI for the Targets
- Reconfigure a Target Server
- Remove Target Servers from vMA
- Modifying Scripts
- Configure vMA to Use a Static IP Address
- Configure vMA to Use a DHCP Server
- Setting the Time Zone
- Shut Down vMA
- Delete vMA
- Troubleshooting vMA
- Update vMA
- Configure Automatic vMA Updates
- vMA Interfaces
- Index
vSphere Management Assistant Guide
16 VMware, Inc.
Troubleshooting Unattended Authentication
IfyouarenotabletoauthenticatefromvMAorcannotaddvMAtothedomaincontroller,verifythefollowing
conditions:
YourDNSserversetupinvMAresolvestheIPaddressorhostnameofthevCenterservertoafully
qualifieddomainname(FQDN)andthattheFQDNcontainsthedomainnametowhichvMAisadded.
Thecommandvifp listserversshowsthenameofvCenterserverastheFQDNthatcontainsthe
domainnametowhichvMAisaddedasthesuffix.
ThedateandtimesettingsonvMA,thedomaincontrollerandthevCenterserverarethesame.Verifythe
timezoneaswell.Thetimemayvarybyanhour,butalargetimeskewmightcauseauthentication
problems.
Enable the vi-user Account
Aspartofconfiguration,vMAcreatesavi‐useraccountwithnopassword.However,youcannotusethe
vi‐useraccountuntilyouhavespecifiedavi‐userpassword.
To enable the vi-user account
1LogintovMAasvi‐admin.
2RuntheLinuxpasswdcommandforvi‐userasfollows:
sudo passwd vi-user
IfthisisthefirsttimeyouusesudoonvMA,amessageaboutrootuserprivilegesappears,andyouare
promptedforthevi‐adminpassword.
3Specifythevi‐adminpassword.
4Whenprompted,typeandconfirmthepasswordforvi‐user.
Afterthevi‐useraccountisenabledonvMA,
ithasnormalprivilegesonvMAbutisnotinthesudoerslist.
WhenyouaddESXitargetservers,vMAcreatestwousersoneachtarget:
vi‐adminhasadministrativeprivilegesonthetargetsystem.
vi‐userhasread‐onlyprivilegesonthetargetsystem.vMAcreatesvi‐useroneachtargetthatyouadd,
evenifvi‐userisnotcurrentlyenabledonvMA.
WhenauserisloggedintovMAasvi‐user,vMAusesthataccountontargetESXihosts,andthe
usercanrun
onlycommandsontargetESXihoststhatdonotrequireadministrativeprivileges.
vMA User Account Privileges
Table 2‐1liststheprivilegesthatthedifferentuseraccountshaveforvCLIusageagainstdifferenttargets.
I
MPORTANTThevi‐useraccounthaslimitedprivilegesonthetargetESXihostsandcannotrunany
commandsthatrequiresudoexecution.Youcannotusevi‐usertoruncommandsforActiveDirectorytargets
(ESXiorvCenterServer).ToruncommandsfortheActiveDirectorytargets,usethevi-adminuseror
login
asanActiveDirectoryusertovMA.
Table 2-1. Account Privileges for vCLI Usage
Target
Authentication
Policy vi-admin vi-user domain user
ESXifpauthYYN
ESXi adauth Y N Y
vCenterServer fpauth Y N N
vCenterServer adauth Y N Y