Redirect 301 /ads.txt https://srv.adstxtmanager.com/19390/vmorecloud.com VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs) Mastodon

latest posts

- Advertisement -
VMoreCloud
VirtualizationVMware

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
10views

In Part 3 of the VCF 9 SSO series, we’ll be integrating VCF Operations, Logs and Automation with the Identity Broker.

First up – Operations.

Log into Operations as the Local Administrator, browse to Fleet Management/Identity and Access. Click on Operations appliance.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Continue and then we can select the Identity Broker cluster.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

We’ll get the warning for the role mapping requirement:

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Confirm and Continue.

Now we can set a role mapping from the SSO Source. Click Administration/Control Panel/Access Control/User Groups.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Import from Source

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Add the group and click Finish.

Then Edit the group and assign the Administrator role for All Objects.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Save, and we’re finished with Operations.

Next up – Automation.

The first step is the same as Operations – go back to Fleet Management / Identity and Access, select automation appliance and “Configure”

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

We get the same warning again about Role Mappings.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

The link in the above warning will open the automation console for you, open it in a new tab and log in with the built-in admin account.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

In the left panel, click Access Control, then groups. Import Groups.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Add the AD Group name, and assign the role then click save. That’s Automation finished!

Lastly – we’ll configure Logs.

Go back to Fleet Management / Identity and Access. Select “VCF Other Components” and then click Continue.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

We’ll be prompted with the following. Add the name for the client, and click “Generate OIDC Client”.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Now log into Logs as the local admin, browse to Configuration then Authentication. Click Edit on the VCF SSO section.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Copy and Paste the values from the OIDC Client and click Test Connection.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Accept the SSL Cert.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

And now we should see a “Success” notification.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Save and we will see that VCF SSO is enabled.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Remember to go back to Operations and click Save on the new client.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

I also had to edit the client to fix the URIs. By default these were configured with the IP address, but I updated to the FQDNs.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Now we can add a role mapping. Browse to Management / Access Control.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click New Group and fill the details.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Save.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

And that’s it, we’re done! Active Directory SSO has now been configured for Operations, Automation and Logs.

Leave a Response