6.5.1

Table Of Contents
Specifying a Nondefault Authentication Method
Administrators can set up a nondefault authentication method from the Platform Services Controller Web
interface, or by using the sso-config script.
n
For smart card authentication, you can perform the vCenter Single Sign-On setup from the
Platform Services Controller Web interface or by using sso-config. Setup includes enabling smart
card authentication and configuring certificate revocation policies.
n
For RSA SecurID, you use the sso-config script to configure RSA Authentication Manager for the
domain, and to enable RSA token authentication. You cannot configure RSA SecurID authentication
from the Web interface. However, if you enable RSA SecurID, that authentication method appears in
the Web interface.
Combining Authentication Methods
You can enable or disable each authentication method separately by using sso-config. Leave user
name and password authentication enabled initially, while you are testing a two-factor authentication
method, and set only one authentication method to enabled after testing.
Smart Card Authentication Login
A smart card is a small plastic card with an embedded integrated circuit chip. Many government agencies
and large enterprises use smart cards such as Common Access Card (CAC) to increase the security of
their systems and to comply with security regulations. A smart card is used in environments where each
machine includes a smart card reader. Smart card hardware drivers that manage the smart card are
typically preinstalled.
When you configure smart card authentication for vCenter Single Sign-On, you must set up your
environment before users can log in using smart card authentication.
n
If you are using vSphere 6.0 and earlier, verify that the Client Integration Plug-in is installed.
n
If you are using vSphere 6.5 and later, verify that the Enhanced Authentication Plug-In is installed.
See vSphere Installation and Setup.
Users who log in to a vCenter Server or Platform Services Controller system are then prompted to
authenticate with a smart card and PIN combination, as follows.
1 When the user inserts the smart card into the smart card reader, vCenter Single Sign-On reads the
certificates on the card.
2 vCenter Single Sign-On prompts the user to select a certificate, and then prompts the user for the PIN
for that certificate.
3 vCenter Single Sign-On checks whether the certificate on the smart card is known and whether the
PIN is correct. If revocation checking is turned on, vCenter Single Sign-On also checks whether the
certificate is revoked.
Platform Services Controller Administration
VMware, Inc. 42