VCF SSO Configuration had a little bit of a facelift from 9.0, I would say for the better. However, the architectures in deploying as an Instance or Embedded (in the vCenter) remain. The identity broker services continue to remain as a VCF Management Service runtime service.
From the VCF Operations console under Manage>>Fleet Management >> Identity & Access you will find 2 tabs, the first one you must do before you can Configure SSO is go through and check all of the Prerequisites to have an understanding or capabilities and features.

Now you may click ‘Configure SSO’

A UI appears with a series of steps to ensure successfull configuration appears, starting with the first one will be the ‘Deployment Mode’

The options appear different whether you select Instance or Embedded, as you can see, when selecting Instance, only my VCF Instance which has the identity broker deployment will appear

**Not a step but just sharing, when you select Embedded, you simply select the VCF Instance you want to configure, only one at a time can be performed from the following screen.

Since we selected Instance for the previous step we clicked ‘Configure’ and now selecting our Identity Provider

You will find the many supported supported options, for me it will be AD/LDAP

This will open up a series of additional steps to configure the IDP

This is populating AD related information

The next screen is simple Review and you can click Finish.
For Step 3 of iDP we will Configure User & Group Provisioning

The first 2 steps of the wizard I kept Defaults and continued to ‘Group Provisioning’
Here I entered the DN for my Groups and it searches it immediately and lists for selection

You may repeat the same steps for the User Provisioning

The next step will be Test login, you can click on ‘TEST LOGIN’ and it will bring up a vSphere console

The option with an SSO login should be at login and once logged in with a selected User or User part of a group, it should simply authenticate as this (no permissions are granted yet, simply a test)

When you go back to the Operations console wizard, will see a Successful message

We’re half way there

The next step is Enabling SSO for vCenter and NSX, I’m selecting to do both and click Configure

A confirmation appears

The wizard will appear with a sub-status and you can click on that refresh until all components are configured to complete Step 3

The final step is to begin assigning VCF Roles, click Start

I’m going to first assign a Security Group and click ‘Assign’

The example shows selecting access to a specific Instance

Followed by the pre-built role

When you go back to the Groups screen, you now see the VCF Role assigned to respective Group

This completes the Wizard

There is an option to Export your configuration for backup.

VCF SSO Overview will now be populated with an interface to make any setting changes

Leave a Reply