6.0.3

Table Of Contents
n
Verify that the Platform Services Controller Web interface certicate is trusted by the end users
workstation; otherwise, the browser does not aempt the authentication.
n
Congure an Active Directory identity source and add it to vCenter Single Sign-On as an identity
source.
n
Assign the vCenter Server Administrator role to one or more users in the Active Directory identity
source. Those users can then authenticate because they are in the Active Directory group, and they have
vCenter Server administrator privileges. The administrator@vsphere.local user cannot perform smart
card authentication.
n
If you want to use the Platform Services Controller HA solution in your environment, complete all HA
conguration before you set up smart card authentication. See VMware Knowledge base article 2113085
(Windows) or 2113315 (vCenter Server Appliance).
Procedure
1 From a Web browser, connect to the Platform Services Controller by specifying the following URL:
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP address is the same as
the vCenter Server host name or IP address.
2 Specify the user name and password for administrator@vsphere.local or another member of the vCenter
Single Sign-On Administrators group.
If you specied a dierent domain during installation, log in as administrator@mydomain.
3 Browse to Single Sign-On > .
4 Click  Revocation  and enable or disable revocation checking.
5 If certicate policies are in eect in your environment, you can add a policy in the  policies
accepted pane.
Set Up RSA SecureID Authentication
You can set up your environment to require that users log in with an RSA SecureID token instead of a
password. SecureID setup is supported only from the command line.
N RSA Authentication Manager requires that the user ID is a unique identier that uses 1 to 255 ASCII
characters. The characters ampersand (&), percent (%), greater than (>), less than (<), and single quote (`) are
not allowed.
Prerequisites
n
Verify that your environment uses Platform Services Controller version 6.0 Update 2 or later, and that
you use vCenter Server version 6.0 or later. Upgrade version 5.5 nodes to version 6.0.
n
Verify that your environment has a correctly congured RSA Authentication Manager and that users
have RSA tokens. RSA Authentication Manager version 8.0 or later is required.
n
Verify that the identity source that RSA Manager uses has been added to vCenter Single Sign-On. See
Add a vCenter Single Sign-On Identity Source,” on page 31.
n
Verify that the RSA Authentication Manager system can resolve the Platform Services Controller host
name, and that the Platform Services Controller system can resolve the RSA Authentication Manager
host name.
n
Export the sdconf.rec le from the RSA Manager by selecting Access > Authentication Agents >
Generate  . Decompress the resulting AM_Config.zip le to nd the sdconf.rec le.
n
Copy the sdconf.rec le to the Platform Services Controller node.
Chapter 2 vSphere Authentication with vCenter Single Sign-On
VMware, Inc. 43