Configure a Single Sign-On Source in
VMware Aria
Operations
VMware Aria
Operations
As a system administrator or virtual
infrastructure administrator, you use single sign-on to activate SSO users to log in
securely to your
VMware Aria
Operations
environment. - Verify that the server system time of the single sign-on source andVMware Aria Operationsare synchronized. If you need to configure the Network Time Protocol (NTP), see VMware Aria Operations Cluster and Node Maintenance.
- Verify that the server system time of the single sign-on source andVMware Aria Operationsare synchronized. If you need to configure the Network Time Protocol (NTP), see information about cluster and node maintenance in the.VMware Aria OperationsGetting Started Guide
- Verify that you have access to a Platform Services Controller through thevCenter Server. See the VMware vSphere Information Center for more details.
After the single sign-on
source is configured, users are redirected to an SSO identity source for
authentication. When logged in, users can access other vSphere components such
as the
vCenter Server
without having to log in again.
- Log in toVMware Aria Operationsas an administrator.
- From the left menu, clickAdministration, and then click theAuthentication Sourcestile.
- ClickAdd.
- In the Add Source for User and Group Import dialog box, provide information for the single sign-on source.OptionActionSource Display NameType a name for the import source.Source TypeVerify that SSO SAML is displayed.HostEnter the IP address or FQDN of the host machine where the single sign-on server resides. If you enter the FQDN of the host machine, verify that every node in theVMware Aria Operationscluster can resolve the single sign-on host FQDN.PortSet the port to the single sign-on server listening port. By default, the port is set to 443.User NameEnter the user name that can log into the SSO server.PasswordEnter the password.Grant administrator role tovRealize Operations Managerfor future configuration?SelectYesso that the SSO source is reregistered automatically if you make changes to theVMware Aria Operationssetup. If you selectNo, and theVMware Aria Operationssetup is changed, single sign-on users will not be able to log in until you manually reregister the single sign-on source.Automatically redirect to vRealize Operations single sign-on URL?SelectYesto direct users to the vCenter single-sign on log in page. If you selectNo, users are not redirected to SSO for authentication.Import single sign-on user groups after adding the current source?SelectYesso that the wizard directs you to the Import User Groups page when you have completed the SSO source setup. If you want to import user accounts, or user groups at a later stage, selectNo.Advanced optionsIf your environment uses a load balancer, enter the IP address of the load balancer.
- ClickTestto test the source connection, and then clickOK.The certificate details are displayed.
- Select theAccept this Certificatecheck box, and clickOK.
- In the Import User Groups dialog box, import user accounts from an SSO server on another machine.OptionActionImport FromSelect the single sign-on server you specified when you configured the single sign-on source.Domain NameSelect the domain name from which you want to import user groups. If Active Directory is configured as the LDAP source in the PSC, you can only import universal groups and domain local groups if thevCenter Serverresides in the same domain.Result LimitEnter the number of results that are displayed when the search is conducted.Search PrefixEnter a prefix to use when searching for user groups.
- In the list of user groups displayed, select at least one user group, and clickNext.
- In the Roles and Objects pane, select a role from theSelect Roledrop-down menu, and select theAssign this role to the groupcheck box.
- Select the objects users of the group can access when holding this role.To assign permissions so that users can access all the objects inVMware Aria Operations, select theAllow access to all objects in the systemcheck box.
- ClickOK.
- Familiarize yourself with single-sign on and confirm that you have configured the single sign-on source correctly.
- Log out ofVMware Aria Operations.
- Log in to thevSphere Web Clientas one of the users in the user group you imported from the single sign-on server.
- In a new browser tab, enter the IP address of yourVMware Aria Operationsenvironment.
- If the single sign-on server is configured correctly, you are logged in toVMware Aria Operationswithout having to enter your user credentials.