You can set up your environment to require that users log in with an RSA SecurID token. SecurID setup is supported only from the command line.
See the two vSphere Blog posts about RSA SecurID setup for details.
Note: RSA Authentication Manager requires that the user ID is a unique identifier that uses 1 to 255 ASCII characters. The characters ampersand (&), percent (%), greater than (>), less than (<), and single quote (`) are not allowed.
Prerequisites
- Verify that your environment has a correctly configured RSA Authentication Manager and that users have RSA tokens. RSA Authentication Manager version 8.0 or later is required.
- Verify that the identity source that RSA Manager uses has been added to vCenter Single Sign-On. See Add or Edit a vCenter Single Sign-On Identity Source.
- Verify that the RSA Authentication Manager system can resolve the vCenter Server host name, and that the vCenter Server system can resolve the RSA Authentication Manager host name.
- Export the sdconf.rec file from the RSA Manager by selecting . To find sdconf.rec file, decompress the resulting AM_Config.zip file.
- Copy the sdconf.rec file to the vCenter Server node.
Procedure
Results
If user name and password authentication is disabled and RSA authentication is enabled, users must log in with their user name and RSA token. User name and password login is no longer possible.
Note: Use the user name format
userID@domainName or
userID@domain_upn_suffix.