4.2.1

Table Of Contents
4 Load the vCenter Server SSL certificate in Orchestrator from a URL address or file.
Option Action
Import from URL
Specify the URL of the vCenter Server:
https://
your_vcenter_server_IP_address
Import from file
Obtain the vCenter Server certificate file. The file is usually available at the
following locations:
n
C:\Documents and
Settings\AllUsers\ApplicationData\VMware\VMware
VirtualCenter\SSL\rui.crt
n
/etc/vmware/ssl/rui.crt
5 Click Import.
A message confirming that the import is successful appears.
6 Repeat the steps for each vCenter Server instance that you want to add to the Orchestrator server.
The imported certificate appears in the Imported SSL certificates list. On the Network tab, the red triangle
changes to a green circle to indicate that the component is now configured correctly.
What to do next
Each time you want to specify the use of an SSL connection to a vCenter Server instance, you must return to
the SSL Certificate tab on the Network tab and import the corresponding vCenter Server SSL certificate.
Configuring LDAP Settings
Orchestrator requires a connection to a working LDAP server on your infrastructure to manage user
permissions.
If you are using secure LDAP over SSL, Windows 2003 or 2008, and AD, verify that the LDAP Server Signing
Requirements group policy is disabled on the LDAP server.
IMPORTANT Multiple domains that have a two-way trust, but are not in the same tree, are not supported and
do not work with Orchestrator. The only configuration supported for multi-domain Active Directory is domain
tree. Forest and external trusts are unsupported.
1 Generate the LDAP Connection URL on page 43
The LDAP service provider uses a URL to configure the connection to the directory server. To generate
the LDAP connection URL, you must specify the LDAP host, port, and root.
2 Import the LDAP Server SSL Certificate on page 44
If your LDAP server uses SSL, you can import the SSL certificate file to the Orchestrator configuration
interface and activate secure connection between Orchestrator and LDAP.
3 Specify the Browsing Credentials on page 45
Orchestrator must read your LDAP structure to inherit its properties. You can specify the credentials
that Orchestrator uses to connect to an LDAP server.
4 Define the LDAP User and Group Lookup Paths on page 45
You can define the users and groups lookup information.
5 Define the LDAP Search Options on page 46
You can customize the LDAP search queries and make searching in LDAP more effective.
Installing and Configuring VMware vCenter Orchestrator
42 VMware, Inc.