Geekdom

Geeks of the World Unite!

 

25

Jul

Adding LDAP authentication to ESX

Posted by Rich  Published in Linux, Technical

The ESX console and the VI Client (newly re-branded as vSphere) the two ways to get in to an ESX server.  When you have ‘multiple cooks’, it becomes a requirement to be able to track who has done what on the system, and this is where ESX can be tweaked to provide granular authentication.

span style=text-decoration: underline;strongThe ESX Console/strong/span

The ESX console, honestly, should be avoided at all costs.  It is very easy to completely disrupt your VM’s if you make a mistake in the console.  However, the console is key in the event administrative steps are necessary, like importing a VMDK to a vmfs volume, enabling ssh, enabling monitoring, etc.

To enable LDAP authentication, log on to the console and enter the following command:
ul
liesxcfg-auth –enableldap –ldapserver=your.ldap.server.com –ldapbasedn=dc=yourdomain,dc=com/li
/ul
What this does it is enables the console to get user information from ldap as well as enable user authentication via LDAP.

A few services now need to be restart in order to reflect the new authentication scheme:
ul
li/etc/init.d/sshd restart/li
lifont style=position: absolute;overflow: hidden;height: 0;width: 0a href=http://www.videnov.com/#1084;#1077;#1073;#1077;#1083;#1080; #1074;#1072;#1088;#1085;#1072;/a/font/etc/init.d/vmware-vmkauthd restart/li
li/etc/init.d/mgmt-vmware restart/li
/ul
span style=text-decoration: underline;strongVI Client / vSphere Client
/strong/span

Now that the underlying system recognizes LDAP users and passwords, you have to enable them within the GUI and provide them with an access level.
ul
liStart up the VI Client and log in as root./li
liUnder File-gt;New select Add Permission.. and a new window will pop up./li
liOn the left side of the screen, toward the bottom, select Add../li
liFollow the prompts to add users and/or groups to the list on the left./li
liOn the right side, select the permission level you wish to grant them./li
/ul

Related Articles

  • Squid + NTLM authentication failing in a Windows 2008 Domain Environment (August 17th, 2010)
  • Generating self signed SSL certificates (August 14th, 2010)
  • Renew Self-Signed SSL Certificate on Linux (August 14th, 2010)
  • Windows 7 and Squid via NTLM authentication via Samba (July 16th, 2010)
  • Extend the root LVM with a live system (July 7th, 2009)

No user responded in this post

Subscribe to this post comment rss or trackback url

Search

Categories

  • Fun
  • Games
  • Linux
  • Movies
  • Rants
  • Solaris
  • Technical
  • Uncategorized
  • Windows

Archives

  • August 2010
  • July 2010
  • January 2010
  • July 2009
  • June 2009
  • May 2009
  • January 2009
  • December 2008
  • November 2008
  • September 2008
  • July 2008
  • June 2008
  • March 2008
  • February 2008
  • December 2007
  • August 2007
  • July 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • August 2005

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
July 2009
S M T W T F S
« Jun   Jan »
 1234
567891011
12131415161718
19202122232425
262728293031  

Blogroll

  • Brian Jones - Musings of an Anonymous Geek
  • Steve Elgersma - Random uploaded bits of Steve’s mind
  • WesMo Projects - Necessity Is The Mother Of Invention

Recent Post

  • Squid + NTLM authentication failing in a Windows 2008 Domain Environment
  • Generating self signed SSL certificates
  • Renew Self-Signed SSL Certificate on Linux
  • Windows 7 and Squid via NTLM authentication via Samba
  • iPhone SMS Archiving
  • Adding LDAP authentication to ESX
  • Extend the root LVM with a live system
  • Majordomo to Mailman migration
  • ESX/ESXi and the AMD Phenom X4 9500
  • Enabling SSH on ESXi

Recent Comments

  • VMware Workstation 6.5.0 + fedora 1… in Fedora 10 + VMware Workstation 6.5.0
  • Ben in Openvpn + Windows = One Awesome VPN Setup (Quick a…
  • Geekdom » Post Topic in Fedora (with Gnome) and VMWare Workstation 6.5 = k…
  • stephen01 in Fedora (with Gnome) and VMWare Workstation 6.5 = k…
  • Avoid One Thing » Blog Archiv… in MythTV Tweaks
  • I Organize » Blog Archive &ra… in Playing an iPod (or other music player) on a lapto…
  • iPod: Apple iPod Music Downloads, F… in Playing an iPod (or other music player) on a lapto…
  • Apple Ipod, Ipod Nano and Ipod Vide… in Playing an iPod (or other music player) on a lapto…
  • Rich in BIOS updates to a Mach Speed Viper K8M8MS rev 2 mo…
  • Rich in BIOS updates to a Mach Speed Viper K8M8MS rev 2 mo…
© 2007 Geekdom
Theme based upon one created by Wired Studios
Valid XHTML | Valid CSS 3.0
Powered by Wordpress