7.1

Table Of Contents
Logging in with CRL Checking
When you enable certicate revocation, the Directories Management server reads a CRL to determine the
revocation status of a user certicate.
If a certicate is revoked, authentication through the certicate fails.
Logging in with OCSP Certificate Checking
When you congure Certicate Status Protocol (OCSP) revocation checking, Directories Management sends
a request to an OCSP responder to determine the revocation status of a specic user certicate. The
Directories Management server uses the OCSP signing certicate to verify that the responses it receives from
the OCSP responder are genuine.
If the certicate is revoked, authentication fails.
You can congure authentication to fall back to CRL checking if it does not receive a response from the
OSCP responder or if the response is invalid.
Configure Certificate Authentication for Directories Management
You enable and congure certicate authentication from the vRealize Automation administration console
Directories Management feature.
Prerequisites
n
Obtain the Root certicate and intermediate certicates from the CA that signed the certicates
presented by your users.
n
(Optional) A list of the Object Identiers (OID) of valid certicate policies for certicate authentication.
n
For revocation checking, the le location of the certicate revocation list and the URL of the OCSP
server.
n
(Optional) OCSP Response Signing certicate le location.
n
Consent form content, if a consent form is required to display before authentication.
Procedure
1 As a tenant administrator, navigate to Administration > Directories Management > Connectors
2 On the Connectors page, select the Worker link for the connector that is being congured.
3 Click Auth Adapters and then click .
You are redirected to the identity manager sign-in page.
4 Congure the Certicate Authentication Adapter page.
N An asterisk indicates that the information is required.
Option Description
*Name
A name is required. The default name is CerticateAuthAdapter. You can
change this name.
Enable certificate adapter
Select the check box to enable certicate authentication.
*Root and intermediate CA
certificates
Select the certicate les to upload. You can select multiple root CA and
intermediate CA certicates that are encoded as DER or PEM.
Uploaded CA certificates
The uploaded certicate les are listed in the Uploaded Ca Certicates
section of the form.
Use email if no UPN in certificate
If the user principal name (UPN) does not exist in the certicate, select this
check box to use the emailAddress aribute as the Subject Alternative
Name extension to validate user accounts.
Configuring vRealize Automation
108 VMware, Inc.