6.7

Table Of Contents
4 If the certificate is known, and is not a revoked certificate, the user is authenticated and can then
perform tasks that the user has permissions for.
Note It usually makes sense to leave user name and password authentication enabled during testing.
After testing is complete, disable user name and password authentication and enable smart card
authentication. Subsequently, the vSphere Client and the vSphere Web Client allow only smart card login.
Only users with root or administrator privileges on the machine can reenable user name and password
authentication by logging in to thePlatform Services Controller directly.
Configuring and Using Smart Card Authentication
You can set up your environment to require smart card authentication when a user connects to a
vCenter Server or associated Platform Services Controller from the either the vSphere Client or the
vSphere Web Client.
How you set up smart card authentication depends on the version of vSphere that you are using.
vSphere Version Procedure Links
6.0 Update 2
Later versions of vSphere
6.0
1 Set up the Tomcat server.
2 Enable and configure smart card
authentication.
vSphere 6.0 documentation center.
6.5 and later 1 Set up the reverse proxy.
2 Enable and configure smart card
authentication.
Configure the Reverse Proxy to Request Client
Certificates
Use the Command Line to Manage Smart Card
Authentication
Manage Smart Card Authentication
Configure the Reverse Proxy to Request Client Certificates
Before you enable smart card authentication, you have to configure the reverse proxy on the
Platform Services Controller system. If your environment uses an embedded Platform Services Controller,
you perform this task on the system where both vCenter Server and Platform Services Controller run.
Reverse proxy configuration is required in vSphere 6.5 and later.
Prerequisites
Copy the CA certificates to the Platform Services Controller system.
Procedure
1 Log in to the Platform Services Controller.
OS Description
Appliance Log in to the appliance shell as the root user.
Windows Log in to a Windows command prompt as an Administrator user.
Platform Services Controller Administration
VMware, Inc. 39