6.7

Table Of Contents
In exceptional circumstances, the AD domain server is not reachable to authenticate the user credentials
on the smart card because of connectivity problems, network outage, or disasters. In that case, you can
log in to the ESXi DCUI by using the credentials of a local ESXi Administrator user. After logging in, you
can perform diagnostics or other emergency actions. The fallback to user name and password login is
logged. When the connectivity to AD is restored, smart card authentication is enabled again.
Note Loss of network connectivity to vCenter Server does not affect smart card authentication if the
Active Directory (AD) domain server is available.
Using Smart Card Authentication in Lockdown Mode
When enabled, lockdown mode on the ESXi host increases the security of the host and limits access to
the DCUI. Lockdown mode might disable the smart card authentication feature.
In normal lockdown mode, only users on the Exception Users list with administrator privileges can access
the DCUI. Exception users are host local users or Active Directory users with permissions defined locally
for the ESXi host. If you want to use smart card authentication in normal lockdown mode, you must add
users to the Exception Users list from the vSphere Web Client. These users do not lose their permissions
when the host enters normal lockdown mode and can log in to the DCUI. For more information, see
Specify Lockdown Mode Exception Users.
In strict lockdown mode, the DCUI service is stopped. As a result, you cannot access the host by using
smart card authentication.
Using the ESXi Shell
The ESXi Shell is disabled by default on ESXi hosts. You can enable local and remote access to the shell
if necessary.
To reduce the risk of unauthorized access, enable the ESXi Shell for troubleshooting only.
The ESXi Shell is independent of in lockdown mode. Even if the host is running in lockdown mode, you
can still log in to the ESXi Shell if it is enabled.
ESXi Shell Enable this service to access the ESXi Shell locally.
SSH Enable this service to access the ESXi Shell remotely by using SSH.
The root user and users with the Administrator role can access the ESXi Shell. Users who are in the
Active Directory group ESX Admins are automatically assigned the Administrator role. By default, only the
root user can run system commands (such as vmware -v) by using the ESXi Shell.
Note Do not enable the ESXi Shell unless you actually need access.
n
Use the vSphere Web Client to Enable Access to the ESXi Shell
You can use the vSphere Web Client to enable local and remote (SSH) access to the ESXi Shell and
to set the idle timeout and availability timeout.
vSphere Security
VMware, Inc. 98