5.5

Table Of Contents
n
Verify that you have access to an OpenAM or Active Directory Federation Services SAML identity
provider.
n
Create an XML file with the following metadata from your SAML identity provider.
n
The location of the single sign-on service
n
The location of the single logout service
n
The location of the service's X.509 certificate
For information on configuring and acquiring metadata from an OpenAM or Active Directory
Federation Services SAML provider, consult the documentation for your SAML provider.
Procedure
1 Click Administration.
2 In the left pane, select Settings > Federation.
3 Select Use SAML Identity Provider.
4 Copy and paste the SAML provider metadata XML into the text box or click Browse to upload the
metadata XML file.
5 Click Apply.
What to do next
n
Configure your SAML provider with vCloud Director metadata. See your SAML provider's
documentation and the vCloud Director Installation and Upgrade Guide.
n
Configure your SAML provider to provide tokens with the following attribute mappings.
n
email address = "EmailAddress"
n
user name = "UserName"
n
full name = "FullName"
n
user's groups = "Groups"
n
Import users and groups from your SAML provider.
n
Install the JCE unlimited strength jurisdiction policy files. See
Install Java Cryptography Extension Unlimited Strength Jurisdiction
Policy Files
Install Java Cryptography Extension unlimited strength jurisdiction files to remove restrictions on
cryptographic strength in JCE. These restrictions can prevent users from successfully logging in to vCloud
Director using vSphere Single Sign On.
Because of import control restrictions of some countries, the version of the JCE policy files that are bundled
in the JRE bundled in vCloud Director, allow strong but limited cryptography to be used, which is
insufficient to deal with the encryption strength used by the SAML identity provider.
Prerequisites
Verify that you are a system administrator.
Procedure
1 In the /opt/vmware/vcloud-director/jre/bin/java -version directory, identify the version of Java
used by vCloud Director.
Chapter 3 Working in an Organization
VMware, Inc. 37