7.4

Table Of Contents
n
When Certificate Authentication is configured, and the service appliance is set up behind a load
balancer, make sure that the Directories Management connector is configured with SSL pass-through
at the load balancer and not configured to terminate SSL at the load balancer. This configuration
ensures that the SSL handshake is between the connector and the client in order to pass the
certificate to the connector.
Configuring a Third-Party Identity Provider Instance to Authenticate Users
You can configure a third-party identity provider to be used to authenticate users in the
Directories Management service.
Complete the following tasks prior to using the administration console to add the third-party identity
provider instance.
n
Verify that the third-party instances are SAML 2.0 compliant and that the service can reach the third-
party instance.
n
Obtain the appropriate third-party metadata information to add when you configure the identity
provider in the administration console. The metadata information you obtain from the third-party
instance is either the URL to the metadata or the actual metadata.
Configure a Third Party Identity Provider Connection
vRealize Automation is supplied with a default identity provider connection instance. Users may want to
create additional identity provider connections to support just-in-time user provisioning or other custom
configurations.
vRealize Automation is supplied with an default identity provider. In most cases, the default provider is
sufficient for customer needs. If you use an existing enterprise identity management solution, you can set
up a custom identity provider to redirect users to your existing identity solution.
When using a custom identity provider, Directories Management uses SAML metadata from that provider
to establish a trust relationship with the provider. After this relationship is established, Directories
Management maps the users from the SAML assertion to the list of internal vRealize Automation users
based the subject name ID.
Prerequisites
n
Configure the network ranges that you want to direct to this identity provider instance for
authentication. See Add or Edit a Network Range.
n
Access to the third-party metadata document. This can be either the URL to the metadata or the
actual metadata.
n
Log in to vRealize Automation as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Identity Providers.
This page displays all configured Identity Providers.
Configuring vRealize Automation
VMware, Inc. 135