A user and group directory, for example OpenLDAP or Active Directory over LDAP, that vCenter Single Sign-On authenticates against. Federating with an external identity provider is the alternative approach.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains Identity source in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- OpenLDAP
Free directory software implementing LDAP, developed as open source. vCenter accepts it as an identity source, though vCenter's SSO domain should be given a name distinct from any existing OpenLDAP or Active Directory domain.
- Active Directory over LDAP
Lets vCenter Single Sign-On authenticate against Active Directory by speaking LDAP to it, ideally over LDAPS. With Integrated Windows Authentication gone from vCenter 9.0, either this or identity federation must be used instead.
- vCenter Single Sign-On
Handles vCenter authentication by issuing tokens to people and solutions, keeping a local domain (normally vsphere.local) and connecting to outside identity providers.
- External
API Management virtual network mode in which the gateway stays public but can call private back ends inside the VNet.
- Identity provider
Microsoft Entra ID is one example: a system that keeps identity records up to date and lets applications hand off sign-in, permission checks and logging to it.
Related terms
- Microsoft Entra Kerberos
Azure Files identity source where Entra ID hands out the Kerberos tickets for SMB access. It supports hybrid identities and, more recently, cloud-only ones; each storage account can have just one identity source.