vSphere 4.1 and integration of ads: how to easily distribute the keys to your VMware architecture?

Hello

I just read on the 'novelty' that involves a host constantly searching for a specific group and automatically assigning permission to administrators:

-


http://www.VMware.com/support/developer/VC-SDK/visdk41pubs/ApiReference/Vim.host.AuthenticationManager.html

By default, the ESX host assigns the Administrator role to the group "Admins ESX".

If the group does not exist when the host has joined the domain, the host will be

do not assign the role. In this case, you must create the "Admins ESX"

Group in Active Directory. The host will periodically check the domain controller

for the Group and assign the role when the group exists.

-


I really hope I'm wrong, but in my view, this means that it is very easy for any unauthorized staff get on the hosts full administrator rights.

Everyone of rights AD to create a group (and VMware admins unaware of this "feature"). They would just create the group 'Admins ESX', define them as a member of it and voila. I just have to wait for 4.1 ESX hosts to detect and to grant full permissions.

Needless to say, a lot of IT (and even related) can create groups in big AD environment, most of them not being not not areas or VMware Admins admins (operators of telephone line comes to mind).

so 2 questions:

1 - am I missing something?

2 otherwise, we can expect a fix to this vulnerability?

Concerning

OK - so to say a warning dialogue and maybe an alarm if we don't see the Admin group after a certain period?

dB

Tags: VMware

Similar Questions

Maybe you are looking for