Go LDAPS so password don't get sent in plaintext.
From a shell you run this per system and capture what is between the -BEGIN and -END to file
openssl s_client -showcerts -connect dc.domain.com:636 /dev/null|openssl x509 -outform PEM
This KB best explains it. You need to get certs from the DCs you will use. We have multisite so picked a DC from each as a preventative measure.
https://knowledge.broadcom.com/external/article/316596Chris Leblanc
Technical Analyst - VMware
VCP, MCSA, MCSE, PVTC, VCP-NV 2024
Chris.LeBlanc@dxcas.com<mailto:
chris.leblanc@dxcas.com>
Desk: 250-405-4686
Advanced Solutions, a DXC Technology Company
1101 - 4464 Markham Street
Victoria, BC V8Z 7X8
http://www.dxcas.com<http: www.dxcas.com>
Original Message:
Sent: 9/2/2025 9:49:00 AM
From: Nathanael Pacheco
Subject: How to enable Active Directory / LDAP authentication in vCenter 8.0?
Hello everyone,
I'm currently working on a vCenter 8.0 setup and I'd like to integrate it with our existing Active Directory for user authentication. I noticed that Integrated Windows Authentication (IWA) is deprecated, so I assume LDAP or LDAPS is now the way to go.
Could someone explain the correct process for enabling Active Directory over LDAP/LDAPS in vCenter 8.0? Specifically, how do I obtain the required certificate and configure the identity source in the vSphere Client?
Any guidance would be much appreciated.
Thanks in advance!
------------------------------
- Nathanael Pacheco
System Admin, High Desert Tea House
Algodones, New Mexico
------------------------------
</http:></mailto:chris.leblanc@dxcas.com>