ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

VCP6.7-DCV Objective 4.8 – Configure an SSO domain

By Vladan SEGET | Last Updated: January 4, 2020

Shares

Today we'll cover another objective from VCP-DCV 2019 certification and we'll talk about VMware clusters. Chapter after chapter we're getting closer to fill the blueprint objectives and help students to study and pass the Professional vSphere 6.7 Exam 2019. Today's chapter: VCP6.7-DCV Objective 4.8 – Configure an SSO domain.

You should not rely on our information only, but use those guides as a complementary resource. Perhaps it is also a good idea to download the older VCP6.5-DCV study guide PDF as the structure of each chapter is much more detailed and IMHO gives better support to study.

Check out: VMware Certification Changes in 2019. No mandatory recertification after 2 years. Older certification holders (up to VCP5) can pass the new exam without a mandatory course, only recommended courses are listed).

You can become VCP-DCV 2019 certified even if passing the VCP6.5-DCV exam. Did you know?

To become VCP-DCV 2019 certified you have 3 different choices of exam:

  1. Professional vSphere 6.7 Exam 2019
  2. VCP6.5-DCV: VMware Certified Professional 6.5 – Data Center Virtualization exam (our VCP6.5-DCV Study Guide Page which is complete)
  3. VCP6.5-DCV DELTA: VMware Certified Professional 6.5 – Data Center Virtualization Delta exam

Note: You must be VCP5, or VCP6. If, not, you must attend a class and you have no “Delta” exam option.

The Professional vSphere 6.7 Exam 2019 (2V0-21.19) which leads to VMware Certified Professional – Data Center Virtualization 2019 (VCP-DCV 2019) certification is:

  • A 70-item exam
  • Passing score of 300 using a scaled scoring method.
  • Candidates are given 115 minutes to complete the exam

This guide is available as Free PDF!

Free Download at Nakivo – VCP6.7-DCV Study Guide.

VCP-DCV 2019 Study Guide

VCP-DCV 2019 Study Guide

VCP6.7-DCV Objective 4.8 – Configure an SSO domain

vCenter SSO allows vSphere components to communicate with each other through a secure token mechanism. vCenter SSO uses:

  • Security Token Service (STS)
  • SSL for secure traffic
  • Authentication of users through Microsoft AD or OpenLDAP
  • Authentication of solution through certificates

Check vSphere Platform Services Controler Administration PDF for further explanation on how SSO and handshakes works.

Each Platform Services Controller (PSC) is associated with a vCenter Single Sign-On domain. The domain name defaults to vsphere.local, but you can change it during the installation of the first Platform Services Controller.

Tip: What is the VMware Platform Services controller (PSC) ?

The domain determines the local authentication space. You can split a domain into multiple sites, and assign each Platform Services Controller and vCenter Server instance to a site. Sites are logical constructs, but usually, correspond to geographic location.

You can organize Platform Services Controller domains into logical sites. A site in the VMware Directory Service is a logical container for grouping Platform Services Controller instances within a vCenter Single Sign-On domain.

Deployment types:

  • Embedded – All services that are bundled with the Platform Services Controller are deployed together with the vCenter Server services on the same virtual machine or physical server.
  • External – Only the vCenter Server services are deployed on the virtual machine or physical server. You must register such a vCenter Server instance with a Platform Services controller instance that you previously deployed or installed.

Worth to note that:

With vSphere 6.7 Update 2, VMware is announcing the deprecation of external PSCs. With VMware vCenter Server enhanced link mode introduced in vSphere 6.7, infrastructure teams can link up to fifteen vCenter Server instances in the embedded PSC topology, eliminating the need for load balancers and simplifying architectures.

When deploying a new VCSA, you have a choice to deploy embedded or external PSC.

And then during the configuration phase, you have to specify SSO domain, or join an existing SSO domain. Also, you have to create or enter the administrator's password.

Once the VCSA is deployed you can access the SSO config through Administration > SSO

Once there you must join the PSC to Microsoft AD and then only to ad AD as an identity source.

Using the vSphere Client, log in to a vCenter Server associated with the Platform Services Controller (PSC) as a user with administrator privileges in the local vCenter Single Sign-On domain

Select Administration > Expand Single Sign-On and click Configuration > Click Active Directory Domain > Click Join AD, specify the domain, optional organizational unit, and user name and password, and click Join.

Other then Microsoft AD (starting with version WS 2003) you can configure identity source as OpenLDAP in vSphere client.

If you select the Active Directory (Integrated Windows Authentication) identity source type, you can use the local machine account as your SPN (Service Principal Name) or specify an SPN explicitly. You can use this option only if the vCenter Single Sign-On server is joined to an Active Directory domain. (that was our case).

vCenter SSO Components

STS (security token service) – This service issues security assertion markup language (SAML) tokens. Those tokens represents the identity of a user in one of the identity source types supported by vCenter SSO. The vCenter Single Sign-On service signs all tokens with a signing certificate, and stores the token signing certificate on disk. The certificate for the service itself is also stored on disk.

Administration Server – allows users with admin privileges to vCenter SSO to configure the SSO server and manage users and groups from the vSphere web client.

Do not name the domain name with your Microsoft Active Directory or OpenLDAP domain name.

VMware Directory Service (vmdir) – he VMware Directory service (vmdir) is associated with the domain you specify during installation and is included in each embedded deployment and on each Platform Services Controller. This service is a multi-tenanted, multi-mastered directory service that makes an LDAP directory available on port 389. The service still uses port 11711 for backward compatibility with vSphere 5.5 and earlier systems. It stores SSO information and also certificate information.

Identity Management Service – handles identity sources and STS authentication requests.

To configure vCenter Single Sign-On and manage vCenter Single Sign-On users and groups, the user [email protected] or a user in the vCenter Single Sign-On Administrators group must log in to the vSphere Client. After authentication, that user can access the vCenter Single Sign-On administration.

authenticated users can view all vCenter Server instances or other vSphere objects for which their role gives them privileges. No further authentication is required. After installation, the administrator of the vCenter Single Sign-On domain, [email protected] by default, has administrator access to both vCenter Single Sign-On and vCenter Server.

That user can then add identity sources, set the default identity source, and manage users and groups in the vCenter Single Sign-On domain.

There are some advantages when installing PSC on the same machine than having a separate PSC within your environment. The connection between vCenter Server and the Platform Services Controller is not over the network, and vCenter Server is not prone to outages caused by connectivity and name resolution issues between vCenter Server and the Platform Services Controller.

You'll configure SSO during the installation of the vCenter server and PSC (if installing embedded PSC).  When you install a Platform Services Controller, you are prompted to create a vCenter Single Sign-On domain or join an existing domain.

The domain name is used by the VMware Directory Service (vmdir) for all Lightweight Directory Access Protocol (LDAP) internal structuring. With vSphere 6.0 and later, you can give your vSphere domain a unique name. To prevent authentication conflicts, use a name that is not used by OpenLDAP, Microsoft Active Directory, and other directory services.

Note:  You cannot change the domain to which a Platform Services Controller or vCenter Server instance belongs.

After installation, the administrator of the vCenter Single Sign-On domain, [email protected] by default, has administrator access to both vCenter Single Sign-On and vCenter Server. That user can then add identity sources, set the default identity source, and manage users and groups in the vCenter Single Sign-On domain.

The SSO and identity sources can be found when you go to Menu > Administration > Single Sign-On > Configuration

Where to set a default SSO domain?

There you can add other identity sources. As you can see, I have added my Microsoft Active Directory (AD). However, you must previously add the Platform services controller to an active directory domain.

Groups in vCenter SSO Domain

The vCenter Single Sign-On domain has some predefined groups. If you add users to one of those groups, they will be able to perform the corresponding actions.

For all objects in the vCenter Server hierarchy, you can assign permissions by pairing a user and a role with the object. For example, you can select a resource pool and give a group of users read privileges to that resource pool object by giving them the corresponding role. For some services that are not managed by vCenter Server directly, membership in one of the vCenter Single Sign-On groups determines the privileges.

For example, a user who is a member of the Administrator group can manage vCenter Single Sign-On. A user who is a member of the CAAdmins group can manage the VMware Certificate Authority, and a user who is in the LicenseService.Administrators group can manage licenses.

Groups in the vsphere.local Domain

vCenter Single Sign-On allows vSphere components to communicate with each other through a secure token mechanism. vCenter Single Sign-On uses the following services:

  • STS (Security Token Service).
  • SSL for secure traffic.
  • Authentication of human users through Active Directory or OpenLDAP.
  • Authentication of solution users through certificates

Please have further look at Platform Services controller Administration PDF.

Do not rely only on our Study guide. Use the official documentation as well as your home lab for the study. Follow the progress of the VCP6.7-DCV Study Guide page for further updates.

More from ESX Virtualization

  • VCP6.7-DCV Objective 5.2 – Monitor resources of VCSA in a vSphere environment
  • What is VMware Platform Service Controller (PSC)?
  • What is vCenter Embedded Linked Mode in vSphere 6.7?
  • VMware vExpert 2019 – This is vExpert x11
  • How To Reset ESXi Root Password via Microsoft AD
  • How to Patch VMware vCenter Server Appliance (VCSA) 6.7 Offline

Stay tuned through RSS, and social media channels (Twitter, FB, YouTube)

Shares
5/5 - (1 vote)

| Filed Under: Server Virtualization Tagged With: Configure an SSO domain

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in