7.1

Table Of Contents
n
Since Chrome uses the Internet Explorer conguration to enable Kerberos authentication, you must
congure Internet Explorer to allow Chrome to use the Internet Explorer conguration. See Google
documentation for information about how to congure Chrome for Kerberos authentication.
Procedure
1 Test Kerberos functionality by using the Chrome browser.
2 Log in to Directories Management at hps://myconnectorhost.domain.com/authenticate/.
If Kerberos authentication is successful, the test URL connects with the Web interface.
If all related Kerberos congurations are correct, the relative protocol (Kerberos) secures all interactions
between this Chrome browser instance and Directories Management. Users can use single sign-on access
their My Apps portal.
Scenario: Configure an Active Directory Link for a Highly Available
vRealize Automation
As a tenant administrator, you want to congure an Active Directory over LDAP directory connection to
support user authentication for your highly available vRealize Automation deployment.
Each vRealize Automation appliance includes a connector that supports user authentication, although only
one connector is typically congured to perform directory synchronization. It does not maer which
connector you choose to serve as the sync connector. To support Directories Management high availability,
you must congure a second connector that corresponds to your second vRealize Automation appliance,
which connects to your Identity Provider and points to the same Active Directory. With this conguration, if
one appliance fails, the other takes over management of user authentication.
In a high availability environment, all nodes must serve the same set of Active Directories, users,
authentication methods, etc. The most direct method to accomplish this is to promote the Identity Provider
to the cluster by seing the load balancer host as the Identity Provider host. With this conguration, all
authentication requests are directed to the load balancer, which forwards the request to either connector as
appropriate.
Prerequisites
n
Install a distributed vRealize Automation deployment with appropriate load balancers. See Installing
vRealize Automation 7.1.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click Add Directory.
3 Enter your specic Active Directory account seings, and accept the default options.
Option Sample Input
Directory Name
Add the IP address of your active directory domain name.
Sync Connector
Every vRealize Automation appliance contains a connector. Use any of the
available connectors.
Base DN
Enter the Distinguished Name (DN) of the starting point for directory
server searches. For example, cn=users,dc=corp,dc=local.
Configuring vRealize Automation
118 VMware, Inc.