6.5.1

Table Of Contents
Edit the vCenter Single Sign-On Token Policy
The vCenter Single Sign-On token policy specifies token properties such as the clock tolerance and
renewal count. You can edit the token policy to ensure that the token specification conforms to security
standards in your corporation.
Procedure
1 From a Web browser, connect to the vSphere Web Client or the Platform Services Controller.
Option Description
vSphere Web Client
https://vc_hostname_or_IP/vsphere-client
Platform Services Controller
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP
address is the same as the vCenter Server host name or IP address.
2 Specify the user name and password for administrator@vsphere.local or another member of the
vCenter Single Sign-On Administrators group.
If you specified a different domain during installation, log in as administrator@mydomain.
3 Navigate to the vCenter Single Sign-On configuration UI.
Option Description
vSphere Web Client a From the Home menu, select Administration.
b Under Single Sign-On, click Configuration.
Platform Services Controller Click Single Sign-On and click Configuration.
4 Click the Policies tab and select Token Policy.
The vSphere Web Client displays the current configuration settings. If you have not modified the
default settings, vCenter Single Sign-On uses them.
5 Edit the token policy configuration parameters.
Option Description
Clock tolerance Time difference, in milliseconds, that vCenter Single Sign-On tolerates between a
client clock and the domain controller clock. If the time difference is greater than
the specified value, vCenter Single Sign-On declares the token invalid.
Maximum token renewal count Maximum number of times that a token can be renewed. After the maximum
number of renewal attempts, a new security token is required.
Maximum token delegation count Holder-of-key tokens can be delegated to services in the vSphere environment. A
service that uses a delegated token performs the service on behalf of the principal
that provided the token. A token request specifies a DelegateTo identity. The
DelegateTo value can either be a solution token or a reference to a solution token.
This value specifies how many times a single holder-of-key token can be
delegated.
Platform Services Controller Administration
VMware, Inc. 67