6.7

Table Of Contents
dir-cli ssogroup create
Create a group inside the local domain (vsphere.local by default).
Use this command if you want to create groups to manage user permissions for the vCenter Single Sign-
On domain. For example, if you create a group and then add it to the Administrators group of the vCenter
Single Sign-On domain, then all users that you add to that group have administrator permissions for the
domain.
It is also possible to give permissions to vCenter inventory objects to groups in the vCenter Single Sign-
On domain. See the vSphere Security documentation.
Option Description
--name <name>
Name of the group in vmdir. Maximum length is 487 characters.
--description <description>
Optional description for the group.
--login <admin_user_id>
The administrator of the local vCenter Single Sign-On domain,
administrator@vsphere.local by default.
--password <admin_password>
Password of the administrator user. If you do not specify the
password, you are prompted.
dir-cli trustedcert publish
Publishes a trusted root certificate to vmdir.
Option Description
--cert <file>
Path to certificate file.
--crl <file>
This option is not supported by VMCA.
--login <admin_user_id>
The administrator of the local vCenter Single Sign-On domain,
administrator@vsphere.local by default.
--password <admin_password>
Password of the administrator user. If you do not specify the
password, you are prompted.
--chain
Specify this option if you are publishing a chained certificate. No
option value is needed.
dir-cli trustedcert publish
Publishes a trusted root certificate to vmdir.
Option Description
--cert <file>
Path to certificate file.
--crl <file>
This option is not supported by VMCA.
--login <admin_user_id>
The administrator of the local vCenter Single Sign-On domain,
administrator@vsphere.local by default.
Platform Services Controller Administration
VMware, Inc. 166