6.0.3

Table Of Contents
2 Browse to Administration > Single Sign-On > .
3 Click the Policies tab and select Lockout Policy.
4 Click Edit.
5 Edit the parameters.
Option Description
Description
Optional description of the lockout policy.
Max number of failed login attempts
Maximum number of failed login aempts that are allowed before the
account is locked.
Time interval between failures
Time period in which failed login aempts must occur to trigger a lockout.
Unlock time
Amount of time that the account remains locked. If you enter 0, the
administrator must unlock the account explicitly.
6 Click OK.
Edit the vCenter Single Sign-On Token Policy
ThevCenter Single Sign-On token policy species the clock tolerance, renewal count, and other token
properties. You can edit the vCenter Single Sign-On token policy to ensure that the token specication
conforms to your corporation's security standards.
Procedure
1 Log in to the vSphere Web Client.
2 Select Administration > Single Sign-On, and select .
3 Click the Policies tab and select Token Policy.
The vSphere Web Client displays the current conguration seings. If you have not modied the
default seings, vCenter Single Sign-On uses them.
4 Edit the token policy conguration parameters.
Option Description
Clock tolerance
Time dierence, in milliseconds, that vCenter Single Sign-On tolerates
between a client clock and the domain controller clock. If the time
dierence is greater than the specied value, vCenter Single Sign-On
declares the token invalid.
Maximum token renewal count
Maximum number of times that a token can be renewed. After the
maximum number of renewal aempts, a new security token is required.
Maximum token delegation count
Holder-of-key tokens can be delegated to services in the vSphere
environment. A service that uses a delegated token performs the service on
behalf of the principal that provided the token. A token request species a
DelegateTo identity. The DelegateTo value can either be a solution token or
a reference to a solution token. This value species how many times a
single holder-of-key token can be delegated.
Chapter 2 vSphere Authentication with vCenter Single Sign-On
VMware, Inc. 53