Users Guide

Logging into CMC using a smart card
To use this feature, you must have an Enterprise License. You can log in to CMC using a smart card. Smart cards provide Two Factor
Authentication (TFA) that provide two-layers of security:
Physical smart card device.
Secret code such as a password or PIN.
Users must verify their credentials using the smart card and the PIN.
NOTE: You cannot use the IP address to log in to CMC using the Smart Card login. Kerberos validates your credentials based on
the Fully Qualied Domain Name (FQDN).
Before you log in as an Active Directory user using a Smart Card, make sure to:
Upload a Trusted Certicate Authority (CA) certicate (CA-signed Active Directory certicate) to CMC
Congure the DNS server.
Enable Active Directory login.
Enable Smart Card login.
To log in to CMC as an Active Directory user using a smart card:
1 Log in to CMC using the link https://<cmcname.domain-name>.
The CMC Login page is displayed asking you to insert a smart card.
NOTE
: If you changed the default HTTPS port number (port 80), access the CMC web page using <cmcname.domain-
name>:<port number>, where cmcname is the CMC host name for CMC,
domain-name
is the domain name, and
port
number
is the HTTPS port number.
2 Insert the smart card and click Login.
The PIN dialog box is displayed.
3 Type the PIN and click Submit.
NOTE
: If the smart card user is present in Active Directory, an Active Directory password is not required. Else, you have to
log in by using an appropriate username and password.
You are logged in to CMC with your Active Directory credentials.
Logging into CMC using Single Sign-On
When Single Sign-On (SSO) is enabled, you can log in to CMC without providing your domain user authentication credentials, such as user
name and password. To use this feature, you must have an Enterprise License.
NOTE
: You cannot use the IP address to log in to the SSO. Kerberos validates your credentials against the Fully Qualied Domain
Name (FQDN).
Before logging in to CMC using SSO, make sure that:
You have logged in to your system using a valid Active Directory user account.
Single Sign-On option is enabled during the Active Directory conguration.
To log in to CMC using SSO:
1 Log in to the client system using your network account.
2 Access the CMC web interface by using: https://<cmcname.domain-name>
For example, cmc-6G2WXF1.cmcad.lab,, where cmc-6G2WXF1 is the cmc-name and cmcad.lab is the domain name.
40
Logging into CMC