6.5.1

Table Of Contents
Procedure
1 Connect to a vCenter Server system with the vSphere Web Client.
2 Browse to the host in the vSphere Web Client and click Configure.
3 Under Settings, select Authentication Services.
4 Click Join Domain.
5 Enter a domain.
Use the form name.tld, for example mydomain.com, or name.tld/container/path, for example,
mydomain.com/organizational_unit1/organizational_unit2.
6 Select Using Proxy Server.
7 Enter the IP address of the Authentication Proxy server, which is always the same as the IP address
of the vCenter Server system.
8 Click OK.
Enable Client Authentication for vSphere Authentication Proxy
By default, vSphere Authentication Proxy adds any host if it has the IP address of that host in its access
control list. For additional security, you can enable client authentication. If client authentication is enabled,
vSphere Authentication Proxy also checks the certificate of the host.
Prerequisites
n
Verify that the vCenter Server system trusts the host. By default, when you add a host to
vCenter Server, the host is assigned a certificate that is signed by a vCenter Server trusted root CA.
vSphere Authentication Proxy trusts vCenter Server trusted root CA.
n
If you plan on replacing ESXi certificates in your environment, perform the replacement before you
enable vSphere Authentication Proxy. The certificates on the ESXi host must match that of the host's
registration.
Procedure
1 Log in to the vCenter Server appliance or the vCenter Server Windows machine as a user with
administrator privileges.
2 Run the command to enable access to the Bash shell.
shell
3 Go to the directory where the camconfig script is located.
OS Location
vCenter Server Appliance
/usr/lib/vmware-vmcam/bin/
vCenter Server Windows
C:\Program Files\VMware\CIS\vmcamd\
vSphere Security
VMware, Inc. 94