6.0.3

Table Of Contents
8 To specify the authentication conguration, click Edit next to Authentication  and select
or deselect authentication methods.
You cannot enable or disable RSA SecurID authentication from this Web interface. However, if RSA
SecurID has been enabled from the command line, the status appears in the Web interface.
Set Revocation Policies for Smart Card Authentication
You can customize certicate revocation checking, and you can specify where vCenter Single Sign-On looks
for information on revoked certicates.
You can customize the behavior by using the Platform Services Controller Web interface or by using the sso-
config script. The seings that you select depend in part on what the CA supports.
n
If revocation checking is disabled, vCenter Single Sign-On ignores any CRL or OCSP seings.
n
If revocation checking is enabled, the recommended setup depends on the PKI setup.
OCSP only
If the issuing CA supports an OCSP responder, enable OCSP and disable
using CRL as failover.
CRL only
If the issuing CA does not support OSCP, enable CRL checking and
disable OSCP checking.
Both OSCP and CRL
If the issuing CA supports both an OCSP responder and a CRL, vCenter
Single Sign-On checks the OCSP responder rst. If the responder returns
an unknown status or is not available, vCenter Single Sign-On checks the
CRL. For this case, enable both OCSP checking and CRL checking, and
enable CRL as failover for OCSP.
n
If revocation checking is enabled, advanced users can specify the following additional seings.
OSCP URL
By default, vCenter Single Sign-On checks the location of the OCSP
responder that is dened in the certicate being validated. You can
explicitly specify a location if the Authority Information Access extension
is absent from the certicate or if you want to override it, for example,
because it is not available in your environment.
Use CRL from
certificate
By default, vCenter Single Sign-On checks the location of the CRL that is
dened in the certicate being validated. Disable this option when the
CRL Distribution Point extension is absent from the certicate or if you
want to override the default.
CRL location
Use this property if you disable Use CRL from  and you want
to specify a location (le or HTTP URL) where the CRL is located.
In addition, you can further limit which certicates vCenter Single Sign-On accepts by adding a certicate
policy.
Prerequisites
n
Verify that your environment uses Platform Services Controller version 6.0 Update 2 or later, and that
you use vCenter Server version 6.0 or later. Upgrade version 5.5 nodes to version 6.0.
n
Verify that an enterprise Public Key Infrastructure (PKI) is set up in your environment, and that
certicates meet the following requirements:
n
A User Principal Name (UPN) that corresponds to an Active Directory account in the Subject
Alternative Name (SAN) extension.
n
Client Authentication must be specied in the Application Policy or Enhanced Key Usage eld of a
certicate, or the browser does not show that certicate.
vSphere Security
42 VMware, Inc.