6.0.3

Table Of Contents
Configuring Smart Card Authentication for vCenter Single Sign-On
You can set up your environment to require smart card authentication when a user connects to a
vCenter Server or associated Platform Services Controller from the vSphere Web Client.
Smart Card Authentication Login
A smart card is a small plastic card with an embedded integrated circuit chip. Many government agencies
and large enterprises use smart cards such as Common Access Card (CAC) to increase the security of their
systems and to comply with security regulations. A Common Access Card is used in environments where
each machine includes a smart card reader, and where smart card hardware drivers that manage Common
Access Card are typically preinstalled.
When you congure smart card authentication for vCenter Single Sign-On, users who log in to a
vCenter Server or Platform Services Controller system are prompted to authenticate with a smart card and
PIN combination, as follows:
1 When the user inserts the smart card into the smart card reader, vCenter Single Sign-On reads the
certicates on the card.
2 vCenter Single Sign-On prompts the user to select a certicate, and then prompts the user for the PIN
for that certicate.
3 vCenter Single Sign-On checks whether the certicate on the smart card is known and whether the PIN
is correct. If the revocation checking is turned on, vCenter Single Sign-On also checks whether the
certicate is revoked.
4 If the certicate is known, and is not a revoked certicate, the user is authenticated and can then
perform tasks that user has permissions for.
N In most cases, it makes sense to leave user name and password authentication enabled during
testing. After testing is complete, disable user name and password authentication and enable smart card
authentication. After that, the vSphere Client allows only smart card login. Only users with root or
administrator privileges on the machine can reenable user name and password by logging into
thePlatform Services Controller directly.
Use the Command Line to Configure Smart Card Authentication
You can use the sso-config utility to congure smart card authentication from the command line. The utility
supports all smart card conguration tasks.
When you congure smart card authentication from the command line, you always set up the
Platform Services Controller using the sso-config command rst. Then you can perform other tasks by
using the Platform Services Controller Web interface.
1 Congure the Platform Services Controller so that the Web browser requests submission of the smart
card certicate when the user logs in.
2 Congure the authentication policy. You can congure the policy by using the sso-config script or the
Platform Services Controller Web interface. Conguration of supported authentication types and
revocation seings is stored in VMware Directory Service and replicated across all
Platform Services Controller instances in a vCenter Single Sign-On domain.
If smart card authentication is enabled and other authentication methods are disabled, users are then
required to log in using smart card authentication.
Chapter 2 vSphere Authentication with vCenter Single Sign-On
VMware, Inc. 37