6.7

Table Of Contents
3 Enable Kerberos Authentication in Active Directory
If you use NFS 4.1 storage with Kerberos, you must add each ESXi host to an Active Directory
domain and enable Kerberos authentication. Kerberos integrates with Active Directory to enable
single sign-on and provides an extra layer of security when used across an insecure network
connection.
What to do next
After you configure your host for Kerberos, you can create an NFS 4.1 datastore with Kerberos enabled.
Configure DNS for NFS 4.1 with Kerberos
When you use NFS 4.1 with Kerberos, you must change the DNS settings on ESXi hosts. The settings
must point to the DNS server that is configured to hand out DNS records for the Kerberos Key Distribution
Center (KDC). For example, use the Active Directory server address if AD is used as a DNS server.
Procedure
1 Navigate to the host.
2 Click the Configure tab.
3 Under Networking, click TCP/IP configuration, and click the Edit TCP/IP stack configuration icon.
4 Enter the DNS setting information.
Option Description
Domain AD Domain Name
Preferred DNS server AD Server IP
Search domains AD Domain Name
Configure Network Time Protocol for NFS 4.1 with Kerberos
If you use NFS 4.1 with Kerberos, configure Network Time Protocol (NTP) to make sure all ESXi hosts on
the vSphere network are synchronized.
The best practice is to use the Active Domain server as the NTP server.
Procedure
1 Navigate to the host.
2 Click the Configure tab.
3 Under System, select Time Configuration.
4 Click Edit and set up the NTP server.
a Select Use Network Time Protocol (Enable NTP client).
b Set the NTP Service Startup Policy.
vSphere Storage
VMware, Inc. 176