2.7

Table Of Contents
Procedure
1 Click the Organization Settings tab.
2 Click Settings, then click Security.
3 (By Organization user management mode only) Choose one of the following Allow public registration
settings.
Setting Description
No
User registration is by invitation only.
Yes
Users can see the organization and register themselves.
4 Choose one of the following Allow System Administrator to log into Org settings.
Setting Description
No
Do not allow the system addministrator to log into the organization.
Yes
Allow the system administrator to log into the organization.
5 Click Apply to accept the settings.
About vCenter Single Sign-On
You use VMware
®
vCenter™ Single Sign-On to authenticate and manage users of VMware
®
vFabric™ Data
Director. vCenter Single Sign-On is an authentication broker and a security token exchange that provides a
secure way to access your vSphere and Data Director environments.
When you use Data Director with vSphere 5.1 and vCenter Single Sign-On, you do not log directly into vFabric
Data Director and vCenter Server with a security domain defined only by your vFabric Data Director
environment. When you log in to vFabric Data Director, you pass authentication to the vCenter Single Sign-
On server, which you can configure with multiple identity sources such as Active Directory and OpenLDAP.
After authentication, your user name and password are exchanged for a security token which you use to access
vFabric Data Director.
Register vFabric Data Director with the vCenter Single Sign-On Service
You register vFabric Data Director with the vCenter Single Sign-On service so that you can give access to users
from multiple identity sources such as Active Directory and OpenLDAP.
To register more than one vFabric Data Director instance (individual deployments of vFabric Data Director)
with a vCenter Single Sign-On service, you must create a Data Director solution user with a unique certificate
on the vCenter Single Sign-On service for each instance of vFabric Data Director that you want to register. To
create a unique certificate, import a custom Management Server SSL key and certificate to replace the key and
certificate generated by vFabric Data Director for each instance of Data Director that you want to register. Each
certificate must have a unique Subject Distinguished Name (subject DN) To create a unique certificate, see
“Import Management Server Key and Certificate,” on page 208.
After you create a unique certificate for each Data Director instance, you can register each instance with the
vSphere Single Sign-On service.
Prerequisites
n
Deploy a vCenter Single Sign-On server.
n
Ensure clock synchronization between the vFabric Data Director Management Server and the vCenter
Single Sign-On server.
n
Verify that you have the Lookup Service URL of the Single Sign-On service.
Chapter 3 Managing Users and Roles
VMware, Inc. 41