Bug 1616385
| Summary: | virt-v2v Fails with IMS when Using AD Credentials for VMware Provider | |||
|---|---|---|---|---|
| Product: | Red Hat CloudForms Management Engine | Reporter: | Chris Keller <ckeller> | |
| Component: | Automate | Assignee: | Greg McCullough <gmccullo> | |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Kedar Kulkarni <kkulkarn> | |
| Severity: | high | Docs Contact: | ||
| Priority: | high | |||
| Version: | 5.9.3 | CC: | bthurber, ckeller, fdupont, hkataria, lavenel, mkanoor, mpovolny, obarenbo, simaishi, smallamp, tfitzger | |
| Target Milestone: | GA | Keywords: | TestOnly, ZStream | |
| Target Release: | 5.10.0 | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | 5.10.0.12 | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 1623557 (view as bug list) | Environment: | ||
| Last Closed: | 2019-02-12 16:53:18 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1619668, 1623557 | |||
|
Description
Chris Keller
2018-08-15 18:50:56 UTC
@Chris, we plan to use esx:// URIs and connect directly to the ESXi hosts because vCenter is a bottleneck. In your experience, have you seen customers using AD authentication for the hosts ? Also, do you think they would push back using root user anyway ? @Fabien, in my experience SSH is usually disabled on ESXi hosts and AD authentication is not enabled. However, it is easy to enable both of these and VMware has plenty of documentation to support. Most VMware administrators are receptive to enabling SSH but there is ALWAYS push back when we ask to use root. Adding the ability to use a service account in AD for vCenter & ESXi along with documentation on required permissions would be very beneficial. I would also consider the use of a service account as a best practice because several security standards (e.g. DISA STIG, ISO-27001, NIST) mandate the use of unique accounts for auditing purposes. @Chris, we don't use SSH, simply connection to ESXi API. It is still using root user, as this is the only local account available. @Fabien, in that case it is easy to add AD authentication [1] to ESXi. I would assume adding AD authentication would cover the API as well, but am not sure. [1] - https://kb.vmware.com/s/article/2075361 Associated PR: https://github.com/ManageIQ/manageiq-content/pull/407 PR merged. Moving to POST. With 5.10.0.17 I was able to get the migration to work when my ESXi host was authenticated using active directory, username of format ADDOMAIN\ADUSer and migration was successful. |