6.0.3

Table Of Contents
Contents
About vSphere Security 7
Updated Information 9
1
Security in the vSphere Environment 11
Securing the ESXi Hypervisor 11
Securing vCenter Server Systems and Associated Services 13
Securing Virtual Machines 14
Securing the Virtual Networking Layer 14
Passwords in Your vSphere Environment 16
Security Best Practices and Resources 17
2
vSphere Authentication with vCenter Single Sign-On 19
Understanding vCenter Single Sign-On 20
Conguring vCenter Single Sign-On Identity Sources 29
vCenter Server Two-Factor Authentication 36
Using vCenter Single Sign-On as the Identity Provider for Another Service Provider 45
Managing the Security Token Service (STS) 47
Managing vCenter Single Sign-On Policies 51
Managing vCenter Single Sign-On Users and Groups 54
vCenter Single Sign-On Security Best Practices 59
Troubleshooting vCenter Single Sign-On 60
3
vSphere Security Certicates 65
Certicate Management Overview 66
Managing Certicates with the Platform Services Controller Web Interface 76
Managing Certicates with the vSphere Certicate Manager Utility 83
Manual Certicate Replacement 92
Managing Certicates and Services with CLI Commands 118
View vCenter Certicates with the vSphere Web Client 133
Set the Threshold for vCenter Certicate Expiration Warnings 133
4
vSphere Permissions and User Management Tasks 135
Understanding Authorization in vSphere 136
Understanding the vCenter Server Permission Model 136
Hierarchical Inheritance of Permissions 138
Multiple Permission Seings 139
Managing Permissions for vCenter Components 141
Global Permissions 144
Using Roles to Assign Privileges 147
Best Practices for Roles and Permissions 150
VMware, Inc.
3