TAM Lab 048 - Moving vSphere Authentication from LDAP to LDAPS

preview_player
Показать описание


Рекомендации по теме
Комментарии
Автор

Would have been helpful to show which contents of the certificate chain you copied into the text file to create the cert. Is it the whole thing or what?

shaneusmaximus
Автор

the 2 GPO settings that you changed here.. .is that a requirements for LDAPs to work?
im a bit confused as to why you enabled those 2 settings.... what happens if you dont change those settings? will LDAPs still work?

RogerDingoDing
Автор

Integrated Windows Auth still uses unsigned LDAP for non-authentication purposes and generates 2889 events. I wish this video would address migrating from Integrated to LDAPS because I can not add the latter without destroying the former, apparently.

jasonwoerner
Автор

What happens if you remove an existing Identity Source from which you had AD groups used in Global Permission ? Are you going to lose all those groups ? (ie will they get removed?)
Another way to put it: what happens if I remove my current “AD over LDAP” IS (which is used in Global Permissions) then re-add it using ldaps. Will all AD groups still be there in Global Permission?

loeffelm
Автор

Hi, if we have vCenter connected to the AD via IWA, what's the impact on changing to LDAPS?

Thanks.

RicardoSaramago
Автор

The issue with your design is that you shouldn't be running Cert Services on an AD controller. "With AD CS you have another problem in that you cannot
remove Active Directory (in the event you want to decommission a DC for
example) without first removing AD CS from that DC." Every demonstration I see for this process talks about using Certificate services on a domain controller and it is not best practices.

kevinwood