How to manage SSO Identity Service Providers (IdP) for VMware vSphere Foundation 9 (VVF)
search cancel

How to manage SSO Identity Service Providers (IdP) for VMware vSphere Foundation 9 (VVF)

book

Article ID: 436518

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere Foundation

Issue/Introduction

  • Upgrading from ELM (Enhanced Linked Mode) vSphere 8 environment to VVF 9.
  • VVF (vSphere Foundation license) does not support managing SSO from VCF Ops (Identity Broker via Fleet Management) as found in our “VMware Cloud Foundation 9.0.1 and VMware vSphere Foundation 9.0.1 Feature Comparison & Upgrade Paths” > search for “single sign-on” (images below).


  • Only the embedded broker is installed on the vCenter server(s) using the broker “vc-ws1a-broker service” service. Since VVF does not support VCF SSO the environment can leave ELM in place along with the existing IdP(s).

Resolution

  • No need to break ELM for VVF 9.

  • Manage SSO IdP(s) for the vSphere environment the same as you have been, from the VC vSphere client interface.

Additional Information

Question:

  • I keep seeing that ELM will not be supported (end of life) so is there any guidance or future plans to make a path forward for VVF?

 

Answer:

  • No, as ELM is the only method at this time for “linking” vCenter servers to a vSphere domain and replicating SSO IdP(s) for authentication.

    • VVF currently does not, and there is no indication that it will, support VCF 9 Identity Broker for managing vCenter servers from the VCF Ops via Fleet Manager (using vCenter “Groups”) for SSO management.

    • VCF 9 - Converge a vCenter Instance and ESX Hosts to vSphere Foundation Platform - You will not find any mention of the need to break ELM within the guide(s) to converge an existing vSphere infra to VVF 9 (VMware vSphere Foundation). You will however find in other guides/articles that mention ELM deprecated and needing to be broken for VCF 9 (vSphere Cloud Foundation).

    • Please make sure to carefully note in the articles you review for this if they state “VCF” (vSphere Cloud Foundation) or “VVF” (vSphere Foundation).