7.1

Table Of Contents
e Enter the appropriate password in the Bind DN Password text box that appears when you select
the connector.
f Click Add Connector.
g Edit the host name to point to your load balancer.
You connected your corporate Active Directory to vRealize Automation and congured Directories
Management for high availability.
What to do next
To provide enhanced security, you can congure bi-directional trust between your identity provider and
your Active Directory. See “Congure a Bi Directional Trust Relationship Between vRealize Automation and
Active Directory,” on page 84.
Configure Smart Card Authentication for vRealize Automation
As a system administrator, you must congure smart card authentication for your vRealize Automation
deployment using Directories Management.
Directories Management supports multiple identity providers and connector clusters for each congured
Active Directory. To use smart card authentication, you can set up either a single external connector or a
connector cluster with an appropriate identity provider behind a load balancer that permits SSL
passthrough.
There are various certicate conguration options available for use with smart card authentication. See
“Conguring a Certicate or Smart Card Adapter for Use with Directories Management,” on page 106.
Prerequisites
n
Congure an appropriate Active Directory connection for use with your vRealize Automation
deployment.
n
Download the OVA le required to congure a connector from VMware vRealize Automation Tools
and SDK.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Generate a Connector Activation Token on page 121
Before you deploy the connector virtual appliance to use for smart card authentication, generate an
activation code for the new connector from the vRealize Automation console. The activation code is
used to establish communication between Directories Management and the connector.
2 Deploy the Connector OVA File on page 121
After downloading a connector OVA le, you can deploy it using the VMware vSphere Client or
vSphere Web Client.
3 Congure Connector Seings on page 122
After deploying the connector OVA, you must run the Setup wizard to activate the appliance and
congure the administrator passwords.
4 Apply Public Certicate Authority on page 123
When Directories Management is installed, a default SSL certicate is generated. You can use the
default certicate for testing purposes, but you should generate and install commercial SSL certicates
for production environments.
5 Create a Workspace Identity Provider on page 125
You must create a Workspace identity provider for use with an external connector.
Configuring vRealize Automation
120 VMware, Inc.