This section describes how to integrate RSA SecurID Access with VMware Cloud Director using a SAML SSO Agent.
Architecture Diagram
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to VMware Cloud Director. During configuration of the IdP you will need some information from the SP. This information includes (but is not limited to) Assertion Consumer Service URL and Service Provider Entity ID.
Procedure
-
Sign into RSA Cloud Administration Console and browse to Applications > Application Catalog, click Create From Template and select SAML Direct.
-
Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.
-
In Connection Profile, click on Import Metadata. Import the metadata file downloaded from Step 4 of Configure SAML in VMware Cloud Director.
-
Navigate to Initiate SAML Workflow section.
-
Connection URL field: Automatically populated as VMware Cloud Director metadata file is imported in Step 3 above.
-
Choose SP-Initiated.
-
-
Scroll down to SAML Identity Provider (Issuer) section. Click Generate Cert Bundle, enter the Common Name and Generate and Download the certificate.
-
Identity Provider URL - <Automatically generated>
-
Issuer Entity ID - <Automatically generated>
-
Select Choose File and upload the private key.
-
Select Choose File to import the public signing certificate.
-
Scroll down to the Service Provider section.
-
Scroll to the User Identity section, select the following values.
- Identifier Type – Email Address
-
Identity Source – name of your user identity source
-
Property – mail
-
Click Next Step.
-
On the User Access page, select Allow All Authenticated Users radio button.
-
Click Next Step.
-
On the Portal Display page, select Display in Portal.
-
Click Save and Finish.
-
Click Publish Changes.
Configure SAML in VMware Cloud Director
Perform these steps to configure VMware Cloud Director as an SSO Agent SAML SP to RSA Cloud Authentication Service.
Procedure
-
Log onto your VMware Cloud Director Service Provider Admin Portal.
-
From the top navigation bar, select Administration.
-
Under the Administration tab, click SAML. Click Edit.
The current SAML settings are displayed.
-
From the Service Provider tab, download the VMware Cloud Director SAML service provider metadata.
-
Enter an Entity ID for the system organization. This Entity ID uniquely identifies your system organization to RSA SecurID.
-
Examine the certificate expiration date and, if expiring soon, regenerate the certificate by clicking Regenerate.
-
Click Retrieve Metadata.
-
-
On the Identity Provider tab, upload the SAML metadata that you previously received from your identity provider.
-
Select Use SAML Identity Provider.
-
Either click the Browse icon () and upload the file, or copy and paste its content in the Metadata XML text box.
-
-
Click Save.
Configuration is complete.
Return to the main page for more certification related information.
Related Articles
VMware vSphere/vCenter 8.0.2 - Authentication Agent Configuration - RSA Ready Implementation Guide 135Number of Views F5 BIG-IP APM 14.1 - Authentication Agent Configuration - RSA Ready SecurID Access Implementation Guide 67Number of Views Vmware vSphere vCenter 6.7 - Authentication Agent Configuration - RSA Ready SecurID Access Implementation Guide 205Number of Views Microsoft Entra ID External Authentication Methods (EAM) - Relying Party Configuration Using OIDC - RSA Ready Implementati… 536Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 252Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes for RSA Authentication Manager 8.8 Generate a Certificate Signing Request (CSR) for the Web Tier RSA SecurID Software Token 4.1.2 and 4.2.1 for Mac OS X displays: No token storage device was detected. Verify that the de… RSA Authentication Manager 8.8 Security Configuration Guide