Mastodon
VirtualizationVMware

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
191views

In Part 3 of the VCF 9 SSO series, we’ll be integrating VCF Operations, Logs and Automation with the Identity Broker.

First up – Operations.

Log into Operations as the Local Administrator, browse to Fleet Management/Identity and Access. Click on Operations appliance.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Continue and then we can select the Identity Broker cluster.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

We’ll get the warning for the role mapping requirement:

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Confirm and Continue.

Now we can set a role mapping from the SSO Source. Click Administration/Control Panel/Access Control/User Groups.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Import from Source

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Add the group and click Finish.

Then Edit the group and assign the Administrator role for All Objects.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Save, and we’re finished with Operations.

Next up – Automation.

The first step is the same as Operations – go back to Fleet Management / Identity and Access, select automation appliance and “Configure”

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

We get the same warning again about Role Mappings.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

The link in the above warning will open the automation console for you, open it in a new tab and log in with the built-in admin account.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

In the left panel, click Access Control, then groups. Import Groups.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Add the AD Group name, and assign the role then click save. That’s Automation finished!

Lastly – we’ll configure Logs.

Go back to Fleet Management / Identity and Access. Select “VCF Other Components” and then click Continue.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

We’ll be prompted with the following. Add the name for the client, and click “Generate OIDC Client”.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)
VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Now log into Logs as the local admin, browse to Configuration then Authentication. Click Edit on the VCF SSO section.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Copy and Paste the values from the OIDC Client and click Test Connection.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Accept the SSL Cert.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

And now we should see a “Success” notification.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Save and we will see that VCF SSO is enabled.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Remember to go back to Operations and click Save on the new client.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

I also had to edit the client to fix the URIs. By default these were configured with the IP address, but I updated to the FQDNs.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Now we can add a role mapping. Browse to Management / Access Control.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click New Group and fill the details.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

Click Save.

VCF 9 – Enable and Configure SSO Part 3 (Operations / Automation / Logs)

And that’s it, we’re done! Active Directory SSO has now been configured for Operations, Automation and Logs.

Leave a Response

Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.

Powered By
Best Wordpress Adblock Detecting Plugin | CHP Adblock