7.0

Table Of Contents
If the certificate is revoked, authentication fails.
You can configure authentication to fall back to CRL checking if it does not receive a response from the
OSCP responder or if the response is invalid.
Configure Certificate Authentication for Directories Management
You enable and configure certificate authentication from the vRealize Automation administration console
Directories Management feature.
Prerequisites
n
Obtain the Root certificate and intermediate certificates from the CA that signed the certificates
presented by your users.
n
(Optional) List of Object Identifier (OID)s of valid certificate policies for certificate authentication.
n
For revocation checking, the file location of the CRL, the URL of the OCSP server.
n
(Optional) OCSP Response Signing certificate file location.
n
Consent form content, if enabling a consent form to display before authentication.
Procedure
1 As a tenant administrator, navigate to Administration > Directories Management > Connectors
2 On the Connectors page, select the Worker link for the connector that is being configured.
3 Click Auth Adapters and then click CertificateAuthAdapter.
You are redirected to the identity manager sign in page.
4 In the CertificateAuthAdapter row, click Edit.
5 Configure the Certificate Authentication Adapter page.
Note An asterisk indicates a required field. All other fields are optional.
Option Description
*Name A name is required. The default name is CertificateAuthAdapter. You can change
this name.
Enable certificate adapter Select the check box to enable certificate authentication.
*Root and intermediate CA certificates Select the certificate files to upload. You can select multiple root CA and
intermediate CA certificates that are encoded as DER or PEM.
Uploaded CA certificates The uploaded certificate files are listed in the Uploaded Ca Certificates section of
the form.
You must restart the service before the new certificates are made available.
Click Restart Web Service to restart the service and add the certificates to the
trusted service.
Note Restarting the service does not enable certificate authentication. After the
service is restarted, continue configuring this page. Clicking Save at the end of
the page enables certificate authentication on the service.
Configuring vRealize Automation
VMware, Inc. 116