6.0.3

Table Of Contents
Procedure
1 Change to the directory where the sso-config script is located.
Option Description
Windows
C:\Program Files\VMware\VCenter server\VMware Identity
Services
Appliance
/opt/vmware/bin
2 To enable RSA SecurID authentication, run the following command.
sso-config.[sh|bat] -t tenantName -set_authn_policy –securIDAuthn true
tenantName is the name of the vCenter Single Sign-On domain, vsphere.local by default.
3 (Optional) To disable other authentication methods, run the following command.
sso-config.sh -set_authn_policy -pwdAuthn false -winAuthn false -certAuthn false -t
vsphere.local
4 To congure the environment so that the tenant at the current site uses the RSA site, run the following
command.
sso-config.[sh|bat] -set_rsa_site [-t tenantName] [-siteID Location] [-agentName Name] [-
sdConfFile Path]
For example:
sso-config.sh -set_rsa_site -agentName SSO_RSA_AUTHSDK_AGENT -sdConfFile /tmp/sdconf.rec
You can specify the following options.
Option Description
siteID
Optional Platform Services Controller site ID. Platform Services Controller
supports one RSA Authentication Manager instance or cluster per site. If
you do not explicitly specify this option, the RSA conguration is for the
current Platform Services Controller site. Use this option only if you are
adding a dierent site.
agentName
Dened in RSA Authentication Manager.
sdConfFile
Copy of the sdconf.rec le that was downloaded from RSA Manager and
includes conguration information for the RSA Manager, such as the IP
address.
5 (Optional) To change the tenant conguration to nondefault values, run the following command.
sso-config.[sh|bat] -set_rsa_config [-t tenantName] [-logLevel Level] [-logFileSize Size] [-
maxLogFileCount Count] [-connTimeOut Seconds] [-readTimeOut Seconds] [-encAlgList
Alg1,Alg2,...]
The default is usually appropriate, for example:
sso-config.sh -set_rsa_config -t vsphere.local -logLevel DEBUG
6 (Optional) If your identity source is not using the User Principal Name as the user ID, set up the
identity source userID aribute.
The userID aribute determines which LDAP aribute is used as the RSA userID.
sso-config.[sh|bat] -set_rsa_userid_attr_map [-t tenantName] [-idsName Name] [-ldapAttr
AttrName] [-siteID Location]
vSphere Security
44 VMware, Inc.