n
Users who are in a domain that has been added to vCenter Single Sign-On as an identity source but is
not the default domain can log in to vCenter Server but must specify the domain in one of the following
ways.
n
Including a domain name prefix, for example, MYDOMAIN\user1
n
Including the domain, for example, [email protected]
n
Users who are in a domain that is not a vCenter Single Sign-On identity source cannot log in to
vCenter Server. If the domain that you add to vCenter Single Sign-On is part of a domain hierarchy,
Active Directory determines whether users of other domains in the hierarchy are authenticated or not.
vCenter Single Sign-On does not propagate permissions that result from nested groups from dissimilar
identity sources. For example, if you add the Domain Administrators group to the Local Administrators
group, the permissions is not propagated because Local OS and Active Directory are separate identity
sources.
Synchronizing Clocks on the vSphere Network
Before you install vCenter Single Sign-On, install the vSphere Web Client, or deploy the vCenter Server
Appliance, make sure that all machines on the vSphere network have their clocks synchronized.
If the clocks on vCenter Server network machines are not synchronized, SSL certificates, which are time-
sensitive, might not be recognized as valid in communications between network machines. Unsynchronized
clocks can result in authentication problems, which can cause the vSphere Web Client installation to fail or
prevent the vCenter Server Appliance vpxd service from starting.
Synchronize ESX and ESXi Clocks with a Network Time Server
Before you install vCenter Single Sign-On, the vSphere Web Client, or the vCenter Server appliance, make
sure all machines on the vSphere network have their clocks synchronized.
Procedure
1
From the vSphere Web Client, connect to the vCenter Server.
2
Select the host in the inventory.
3
Select the Manage tab.
4
Select Settings.
5
In the System section, select Time Configuration.
6
Click Edit and set up the NTP server.
a
Select Use Network Time Protocol (Enable NTP client).
b
Set the NTP Service Startup Policy.
c
Enter the IP addresses of the NTP servers to synchronize with.
d
Click Start or Restart in the NTP Service Status section.
7
Click OK.
The host synchronizes with the NTP server.
Chapter 3 Before You Install vCenter Server
VMware, Inc.
59
Summary of Contents for VS4-ENT-PL-A - vSphere Enterprise Plus
Page 6: ...vSphere Installation and Setup 6 VMware Inc ...
Page 8: ...vSphere Installation and Setup 8 VMware Inc ...
Page 10: ...vSphere Installation and Setup 10 VMware Inc ...
Page 28: ...vSphere Installation and Setup 28 VMware Inc ...
Page 70: ...vSphere Installation and Setup 70 VMware Inc ...
Page 100: ...vSphere Installation and Setup 100 VMware Inc ...
Page 122: ...vSphere Installation and Setup 122 VMware Inc ...
Page 138: ...vSphere Installation and Setup 138 VMware Inc ...