6.0.3

Table Of Contents
Use the Platform Services Controller Web Interface to Manage Smart Card
Authentication
You can enable and disable smart card authentication, customize the login banner, and set up the revocation
policy from the Platform Services Controller Web interface.
When you congure smart card authentication from the command line, you always set up the
Platform Services Controller using the sso-config command rst. Then you can perform other tasks by
using the Platform Services Controller Web interface.
1 Congure the Platform Services Controller so that the Web browser requests submission of the smart
card certicate when the user logs in.
2 Congure the authentication policy. You can congure the policy by using the sso-config script or the
Platform Services Controller Web interface. Conguration of supported authentication types and
revocation seings is stored in VMware Directory Service and replicated across all
Platform Services Controller instances in a vCenter Single Sign-On domain.
If smart card authentication is enabled and other authentication methods are disabled, users are then
required to log in using smart card authentication.
If login from the vSphere Web Client is not working, and if user name and password authentication is
turned o, a root or administrator user can turn user name and password authentication back on from the
Platform Services Controller command line by running the following command. The example is for
Windows; for Linux, use sso-config.sh.
sso-config.bat -set_authn_policy -pwdAuthn true
Prerequisites
n
Verify that your environment uses Platform Services Controller version 6.0 Update 2 or later, and that
you use vCenter Server version 6.0 or later. Upgrade version 5.5 nodes to version 6.0.
n
Verify that an enterprise Public Key Infrastructure (PKI) is set up in your environment, and that
certicates meet the following requirements:
n
A User Principal Name (UPN) that corresponds to an Active Directory account in the Subject
Alternative Name (SAN) extension.
n
Client Authentication must be specied in the Application Policy or Enhanced Key Usage eld of a
certicate, or the browser does not show that certicate.
n
Verify that the Platform Services Controller Web interface certicate is trusted by the end users
workstation; otherwise, the browser does not aempt the authentication.
n
Congure an Active Directory identity source and add it to vCenter Single Sign-On as an identity
source.
n
Assign the vCenter Server Administrator role to one or more users in the Active Directory identity
source. Those users can then authenticate because they are in the Active Directory group, and they have
vCenter Server administrator privileges. The administrator@vsphere.local user cannot perform smart
card authentication.
n
If you want to use the Platform Services Controller HA solution in your environment, complete all HA
conguration before you set up smart card authentication. See VMware Knowledge Base article 2112085
(Windows) or 2113315 (vCenter Server Appliance).
vSphere Security
40 VMware, Inc.