If you use NFS 4.1 storage with Kerberos, you must add each ESXi host to an Active Directory domain and enable Kerberos authentication. Kerberos integrates with Active Directory to enable single sign-on and provides an extra layer of security when used across an insecure network connection.
Set up an AD domain and a domain administrator account with the rights to add hosts to the domain.
- Navigate to the host.
- Click the Configure tab.
- Under System, click Authentication Services.
- Add the ESXi host to an Active Directory domain.
The directory services type changes to Active Directory.
- In the Authentication Services pane, click Join Domain.
- Supply the domain settings, and click OK.
- Configure or edit credentials for an NFS Kerberos user.
The state for NFS Kerberos credentials changes to Enabled.
- In the NFS Kerberos Credentials pane, click Edit.
- Enter a user name and password.
Files stored in all Kerberos datastores are accessed using these credentials.