Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
vsp_41_esx_server_config.pdf
Скачиваний:
9
Добавлен:
06.02.2016
Размер:
2.67 Mб
Скачать

Authentication and User Management

13

ESX handles user authentication and supports user and group permissions. In addition, you can encrypt connections to the vSphere Client and SDK.

This chapter includes the following topics:

n“Securing ESX Through Authentication and Permissions,” on page 173

n“About Users, Groups, Permissions, and Roles,” on page 174

n“Working with Users and Groups on ESX Hosts,” on page 178

n“Encryption and Security Certificates for ESX,” on page 183

Securing ESX Through Authentication and Permissions

When a vSphere Client or vCenter Server user connects to a ESX host, a connection is established with the VMware Host Agent process. The process uses the user names and passwords for authentication.

ESX uses the Pluggable Authentication Modules (PAM) structure for authentication when users access the ESX host using the vSphere Client, vSphere Web Access, or the service console. The PAM configuration for VMware services is located in /etc/pam.d/vmware-authd, which stores paths to authentication modules.

The default installation of ESX uses /etc/passwd authentication as Linux does, but you can configure ESX to use another distributed authentication mechanism. If you plan to use a third-party authentication tool instead of the ESX default implementation, see the vendor documentation for instructions. As part of setting up thirdparty authentication, you might be required to update the files in /etc/pam.d folder with new module information.

The reverse proxy in the VMware Host Agent (vmware-hostd) process listens on ports 80 and 443. vSphere Client or vCenter Server users connect to the host agent through these ports. The vmware-hostd process receives the user name and password from the client and forwards them to the PAM module to perform the authentication.

Figure 13-1 shows a basic example of how ESX authenticates transactions from the vSphere Client.

NOTE CIM transactions also use ticket-based authentication in connecting with the vmware-hostd process.

VMware, Inc.

173

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]