ESXi AD Login Fails After Disabling RC4 and SMBv2
search cancel

ESXi AD Login Fails After Disabling RC4 and SMBv2

book

Article ID: 423368

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

When attempting to log in to an ESXi 9.0 host using Active Directory (AD) credentials, the login fails with the following error:

"Cannot complete login due to an incorrect user name or password."

Environment

 

  • VMware ESXi: 9.0

  • Active Directory: Hardened environments where RC4 Kerberos encryption and SMBv1/v2 protocols are disabled.

 

 

Cause

By default, the authentication service used by ESXi (Likewise/lsass) may attempt to use legacy encryption types (RC4_HMAC) or older SMB dialects to communicate with Domain Controllers.
If the Domain Controllers are configured to only allow AES encryption (AES128/256) and SMBv3, the authentication handshake will fail even if the credentials are correct.

Resolution

Configure AD and join the ESXi host with RC4 and SMB v2.0 enabled
Once ESXi has finished joining the domain, disable RC4 and SMB v2.0 on the Active Directory side