You configure the Certificate (Cloud Deployment) authentication method from the Auth Methods page in the VMware Identity Manager console, and then you select the authentication method to use in the built-in identity provider.
You can configure x509 certificate authentication to allow clients to authenticate with certificates on their desktop and mobile devices.
Prerequisites
- Obtain the root certificate and intermediate certificates from the CA that signed the certificates presented by your users.
- (Optional) List of Object Identifier (OID) of valid certificate policies for certificate authentication.
- For revocation checking, the file location of the CRL and the URL of the OCSP server.
- (Optional) OCSP Response Signing certificate file location.
- Consent form content, if a consent form displays before authentication.
Procedure
What to do next
- Add the certificate authentication method to the default access policy.
- When Certificate Authentication is configured, and the service appliance is set up behind a load balancer, make sure that the VMware Identity Manager connector is configured with SSL pass-through at the load balancer and not configured to terminate SSL at the load balancer. This configuration ensures that the SSL handshake is between the connector and the client in order to pass the certificate to the connector.