6.0.3

Table Of Contents
3 Add the certicate.
a Click Browse to browse to the key store JKS le that contains the new certicate and click Open
b Type the password when prompted.
c Click the top of the STS alias chain and click OK.
d Type the password again when prompted
4 Click OK.
5 Restart the Platform Services Controller node to start both the STS service and the vSphere Web Client.
Before the restart, authentication does not work correctly so the restart is essential.
Determine the Expiration Date of an LDAPS SSL Certificate
If you select a Active Directory LDAP Server and OpenLDAP Server identity source, and you decide to use
LDAPS, you can upload an SSL certicate for the LDAP trac. SSL certicates expire after a predened
lifespan. Knowing when a certicate expires lets you replace or renew the certicate before the expiration
date.
You see certicate expiration information only if you use an Active Directory LDAP Server and OpenLDAP
Server and specify an ldaps:// URL for the server. The Identity Sources TrustStore tab remains empty for
other types of identity sources or for ldap:// trac.
Procedure
1 Log in to the vSphere Web Client as administrator@vsphere.local or as another user with vCenter Single
Sign-On administrator privileges.
Users with vCenter Single Sign-On administrator privileges are in the Administrators group in the
vsphere.local domain.
2 Browse to Administration > Single Sign-On > .
3 Click the  tab, and then the Identity Sources TrustStore subtab.
4 Find the certicate and verify the expiration date in the Valid To text box.
You might see a warning at the top of the tab which indicates that a certicate is about to expire.
Managing vCenter Single Sign-On Policies
vCenter Single Sign-On policies enforce the security rules in your environment. You can view and edit the
default vCenter Single Sign-On passwords, lockout policies, and token policies.
Edit the vCenter Single Sign-On Password Policy
The vCenter Single Sign-On password policy is a set of rules and restrictions on the format and expiration of
vCenter Single Sign-On user passwords. The password policy applies only to users in the vCenter Single
Sign-On domain (vsphere.local).
By default, vCenter Single Sign-On passwords expire after 90 days. The vSphere Web Client reminds you
when your password is about to expire.
Procedure
1 Log in to the vSphere Web Client as administrator@vsphere.local or as another user with vCenter Single
Sign-On administrator privileges.
Users with vCenter Single Sign-On administrator privileges are in the Administrators group in the
vsphere.local domain.
Chapter 2 vSphere Authentication with vCenter Single Sign-On
VMware, Inc. 51