6.5.1

Table Of Contents
Contents
About Platform Services Controller Administration 5
Updated Information 7
1
Getting Started with Platform Services Controller 8
vCenter Server and Platform Services Controller Deployment Types 8
Deployment Topologies with External Platform Services Controller Instances and High Availability 12
Understanding vSphere Domains, Domain Names, and Sites 14
Platform Services Controller Capabilities 15
Managing Platform Services Controller Services 16
Managing the Platform Services Controller Appliance 21
2
vSphere Authentication with vCenter Single Sign-On 23
Understanding vCenter Single Sign-On 24
Configuring vCenter Single Sign-On Identity Sources 31
vCenter Server Two-Factor Authentication 41
Using vCenter Single Sign-On as the Identity Provider for Another Service Provider 56
Security Token Service STS 58
Managing vCenter Single Sign-On Policies 64
Managing vCenter Single Sign-On Users and Groups 68
vCenter Single Sign-On Security Best Practices 78
3
vSphere Security Certificates 79
Certificate Requirements for Different Solution Paths 80
Certificate Management Overview 84
Managing Certificates with the Platform Services Controller Web Interface 95
Managing Certificates from the vSphere Web Client 104
Managing Certificates with the vSphere Certificate Manager Utility 105
Manual Certificate Replacement 120
4
Managing Services and Certificates With CLI Commands 153
Required Privileges for Running CLIs 154
Changing the certool Configuration Options 155
certool Initialization Commands Reference 156
certool Management Commands Reference 159
vecs-cli Command Reference 162
dir-cli Command Reference 168
VMware, Inc.
3