How to Configure the Automation Orchestrator Appliance authentication provider on 8.18.x
search cancel

How to Configure the Automation Orchestrator Appliance authentication provider on 8.18.x

book

Article ID: 383139

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Steps to Configure the Automation Orchestrator Appliance authentication provider on 8.18.x
  • You can now configure your Automation Orchestrator options such as the authentication provider with the Automation Orchestrator Appliance command line interface (CLI) only as the earlier existing configuration options in the Control Center have been removed. 

Environment

  • VMware Aria Automation Orchestrator 8.18.x

Resolution

  • Step to configure the Authentication Provider as Aria Automation:
     
    1. Login to the vRO/vRA appliance as root. 

    2. Retrieve the current auth provider by running the command:

      vracli vro authentication

    3. Run the following command to start the guided wizard and configure the authentication provider:

      vracli vro authentication wizard

    4. Select option 1 to choose the authentication provider.

      Select the type of the authentication provider:
      1. VMware Aria Automation
      2. vSphere
      1

    5. Enter the required information, such as the hostname, username, and password.

      Enter the hostname for the authentication provider: Aria_Automation_FQDN
      Enter an administrator username to authenticate with the provider: Admin_Username
      Enter the password for Admin_Username:


    6. Accept the Aria Automation certificate.

      Do you wish to accept the certificate? [y/N]: y

      You will not get any further messages on a successful configuration.


  • Steps to configure the Authentication Provider as vSphere:

    1. Login to the vRO/vRA appliance as root. 

    2. Retrieve the current auth provider by running the command:

      vracli vro authentication

    3. Run the following command to start the guided wizard and configure the authentication provider:

      vracli vro authentication wizard

    4. Select option 2 to choose the authentication provider.

      Select the type of the authentication provider:
      1. VMware Aria Automation
      2. vSphere
      2

    5. Enter the required information, such as the hostname, username, and password.

      Enter the hostname for the authentication provider: vCenter_FQDN
      Enter an administrator username to authenticate with the provider: [email protected]
      Enter the password for [email protected]:
      Enter the domain for the Administrator group (i.e. vsphere.local): vsphere.local
      Enter the Administrator group name: Administrators

    6. Accept the vCenter certificate.

      Do you wish to accept the certificate? [y/N]: y

      You will not get any further messages on a successful configuration.


  • You can run vracli vro authentication command to check the current configuration.

    Example output:

    # vracli vro authentication
    {
      "com.vmware.o11n.sso.redirect.uri": "https://vRO_FQDN/vco/",
      "com.vmware.o11n.sso.token.lifetime": "2592000",
      "com.vmware.o11n.sso.svcaccount": "####-########-####-####-####-############",
      "ch.dunes.authentication.provider": "vsphere",
      "vco.sso.ssl.certificate": "vco.vsphere.lookup-service.ssl.certificate",
      "com.vmware.o11n.sso.admin.group.name": "Administrators",
      "com.vmware.o11n.sso.clock.tolerance.sec": "600000",
      "vco.vsphere.lookup-service.cert.alias": "vco.vsphere.lookup-service.ssl.certificate",
      "com.vmware.o11n.sso.default.tenant": "vsphere.local",
      "com.vmware.o11n.sso.token.renew.count": "10",
      "vco.vsphere.lookup-service.url": "https://vCenter_FQDN/lookupservice/sdk",
      "com.vmware.o11n.sso.svcaccount.password": "##############################",
      "com.vmware.o11n.sso.admin.user.name": "[email protected]",
      "com.vmware.o11n.sso.serviceprovider-host": "https://vRO_FQDN",
      "com.vmware.o11n.sso.admin.group.domain": "vsphere.local"


  • If the vracli vro authentication wizard command does not work, you can use the following command to set up vCenter as the authentication provider.

    vracli vro authentication set -p vsphere -hn https://vCenter_FQDN -u [email protected] --tenant vsphere.local --admin-group Administrators --admin-group-domain vsphere.local

Additional Information