6.7

Table Of Contents
Prerequisites
The target service must fully support the SAML 2.0 standard and the SP metadata must have the
SPSSODescriptor element.
If the metadata do not follow the SAML 2.0 metadata schema precisely, you might have to edit the
metadata before you import it. For example, if you are using an Active Directory Federation Services
(ADFS) SAML service provider, you have to edit the metadata before you can import them. Remove the
following non-standard elements:
fed:ApplicationServiceType
fed:SecurityTokenServiceType
Procedure
1 Export the metadata from the service provider to a file.
2 Log in with the vSphere Web Client to the vCenter Server connected to the
Platform Services Controller.
3 Navigate to the Configuration UI.
a From the Home menu, select Administration.
b Under Single Sign On, click Configuration.
4 Import the SP metadata into vCenter Single Sign-On.
a Select the SAML Service Providers tab.
b In the Metadata from your SAML service provider dialog box, import the metadata by pasting
the XML string or by importing a file.
5 Export the vCenter Single Sign-On IDP metadata.
a In the Metadata for your SAML service provider text box, click Download.
b Specify a file location.
6 Log in to the SAML SP, for example VMware vRealize Automation 7.0, and follow the SP instructions
to add the vCenter Single Sign-On metadata to that service provider.
See the vRealize Automation documentation for details on importing the metadata into that product.
Security Token Service STS
The vCenter Single Sign-On Security Token Service (STS) is a Web service that issues, validates, and
renews security tokens.
Platform Services Controller Administration
VMware, Inc. 53