6.0

Table Of Contents
n
name.tld/container/path (for example, domain.com/OU1/OU2): The account is created under a particular
organizational unit (OU).
To use the vSphere Authentication Proxy service, see vSphere Security.
Procedure
1 Click Manage in the VMware Host Client inventory and click Security & Users.
2 Click Authentication and click Join domain.
3 Enter a domain name.
Use the form name.tld or name.tld/container/path.
4 Enter the user name and password of a directory service user account that has permissions to join the
host to the domain and click Join domain.
5 (Optional) If you intend to use an authentication proxy, enter the proxy server IP address and click Join
domain.
Using Active Directory to Manage ESXi Users
You can congure ESXi to use a directory service such as Active Directory to manage users.
Creating local user accounts on each host presents challenges with having to synchronize account names
and passwords across multiple hosts. Join ESXi hosts to an Active Directory domain to eliminate the need to
create and maintain local user accounts. Using Active Directory for user authentication simplies the ESXi
host conguration and reduces the risk for conguration issues that could lead to unauthorized access.
When you use Active Directory, users supply their Active Directory credentials and the domain name of the
Active Directory server when adding a host to a domain.
Using vSphere Authentication Proxy
When you use the vSphere Authentication Proxy, you do not need to transmit Active Directory credentials
to the host . Users supply the domain name of the Active Directory server and the IP address of the
authentication proxy server when they add a host to a domain.
vSphere Authentication Proxy is especially useful when used with Auto Deploy. You can set up a reference
host that points to Authentication Proxy and set up a rule that applies the reference host's prole to any
ESXi host provisioned with Auto Deploy. Even if you use vSphere Authentication Proxy in an environment
that uses certicates that are provisioned by VMCA or third-party certicates, the process works seamlessly
as long as you follow the instructions for using custom certicates with Auto Deploy. See the vSphere
Security guide.
N You cannot use vSphere Authentication Proxy in an environment that supports only IPv6.
Managing Host Certificates by Using the VMware Host Client
When you log in to an ESXi host by using the VMware Host Client, you can view the certicate details of
your host, such as the issuer and the validity period, and you can also import new certicates
View Certificate Details for an ESXi Host in the VMware Host Client
For ESXi 6.0 and later, hosts that are in VMCA mode or custom mode, you can view certicate details when
you are logged in to the host with the VMware Host Client. The certicate information can be useful for
debugging.
Procedure
1 Click Manage in the VMware Host Client inventory and click Security & Users.
Chapter 2 Host Management with the VMware Host Client
VMware, Inc. 17