6.5.1

Table Of Contents
n
Assign the vCenter Server Administrator role to one or more users in the Active Directory identity
source. Those users can then perform management tasks because they can authenticate and they
have vCenter Server administrator privileges.
Note The administrator of the vCenter Single Sign-On domain, administrator@vsphere.local by
default, cannot perform smart card authentication.
n
Set up the reverse proxy and restart the physical or virtual machine.
Procedure
1 Obtain the certificates and copy them to a folder that the sso-config utility can see.
Option Description
Windows Log in to the Platform Services Controller Windows installation and use WinSCP
or a similar utility to copy the files.
Appliance a Log in to the appliance console, either directly or by using SSH.
b Enable the appliance shell, as follows.
shell
chsh -s "/bin/bash" root
csh -s "bin/appliance/sh" root
c Use WinSCP or a similar utility to copy the certificates to
the /usr/lib/vmware-sso/vmware-sts/conf on the
Platform Services Controller.
d Optionally disable the appliance shell, as follows.
chsh -s "bin/appliancesh" root
2 From a Web browser, connect to the vSphere Web Client or the Platform Services Controller.
Option Description
vSphere Web Client
https://vc_hostname_or_IP/vsphere-client
Platform Services Controller
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP
address is the same as the vCenter Server host name or IP address.
3 Specify the user name and password for administrator@vsphere.local or another member of the
vCenter Single Sign-On Administrators group.
If you specified a different domain during installation, log in as administrator@mydomain.
4 Navigate to the vCenter Single Sign-On configuration UI.
Option Description
vSphere Web Client a From the Home menu, select Administration.
b Under Single Sign-On, click Configuration.
Platform Services Controller Click Single Sign-On and click Configuration.
Platform Services Controller Administration
VMware, Inc. 50