7.4

Table Of Contents
Logging in with OCSP Certificate Checking
When you configure Certificate Status Protocol (OCSP) revocation checking, sends a request to an
OCSP responder to determine the revocation status of a specific user certificate. The server uses the
OCSP signing certificate to verify that the responses it receives from the OCSP responder are genuine.
If the certificate is revoked, authentication fails.
You can configure authentication to fall back to CRL checking if it does not receive a response from the
OSCP responder or if the response is invalid.
Configure Certificate Authentication for Directories Management
You enable and configure certificate authentication from the vRealize Automation administration console
Directories Management feature.
Prerequisites
n
Obtain the Root certificate and intermediate certificates from the CA that signed the certificates
presented by your users.
n
(Optional) List of Object Identifier (OID)s of valid certificate policies for certificate authentication.
n
For revocation checking, the file location of the CRL, the URL of the OCSP server.
n
(Optional) OCSP Response Signing certificate file location.
n
Consent form content, if enabling a consent form to display before authentication.
Procedure
1 As a tenant administrator, navigate to Administration > Directories Management > Connectors
2 On the Connectors page, select the Worker link for the connector that is being configured.
3 Click Auth Adapters and then click CertificateAuthAdapter.
You are redirected to the identity manager sign in page.
4 In the CertificateAuthAdapter row, click Edit.
5 Configure the Certificate Authentication Adapter page.
Note An asterisk indicates a required field. All other fields are optional.
Option Description
*Name A name is required. The default name is CertificateAuthAdapter. You can change
this name.
Enable certificate adapter Select the check box to enable certificate authentication.
*Root and intermediate CA certificates Select the certificate files to upload. You can select multiple root CA and
intermediate CA certificates that are encoded as DER or PEM.
Configuring vRealize Automation
VMware, Inc. 133