This section describes how to integrate RSA SecurID Access with VMware Cloud Director using a SAML SSO Agent.
Architecture Diagram
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to VMware Cloud Director. During configuration of the IdP you will need some information from the SP. This information includes (but is not limited to) Assertion Consumer Service URL and Service Provider Entity ID.
Procedure
-
Sign into RSA Cloud Administration Console and browse to Applications > Application Catalog, click Create From Template and select SAML Direct.
-
Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.
-
In Connection Profile, click on Import Metadata. Import the metadata file downloaded from Step 4 of Configure SAML in VMware Cloud Director.
-
Navigate to Initiate SAML Workflow section.
-
Connection URL field: Automatically populated as VMware Cloud Director metadata file is imported in Step 3 above.
-
Choose SP-Initiated.
-
-
Scroll down to SAML Identity Provider (Issuer) section. Click Generate Cert Bundle, enter the Common Name and Generate and Download the certificate.
-
Identity Provider URL - <Automatically generated>
-
Issuer Entity ID - <Automatically generated>
-
Select Choose File and upload the private key.
-
Select Choose File to import the public signing certificate.
-
Scroll down to the Service Provider section.
-
Scroll to the User Identity section, select the following values.
- Identifier Type – Email Address
-
Identity Source – name of your user identity source
-
Property – mail
-
Click Next Step.
-
On the User Access page, select Allow All Authenticated Users radio button.
-
Click Next Step.
-
On the Portal Display page, select Display in Portal.
-
Click Save and Finish.
-
Click Publish Changes.
Configure SAML in VMware Cloud Director
Perform these steps to configure VMware Cloud Director as an SSO Agent SAML SP to RSA Cloud Authentication Service.
Procedure
-
Log onto your VMware Cloud Director Service Provider Admin Portal.
-
From the top navigation bar, select Administration.
-
Under the Administration tab, click SAML. Click Edit.
The current SAML settings are displayed.
-
From the Service Provider tab, download the VMware Cloud Director SAML service provider metadata.
-
Enter an Entity ID for the system organization. This Entity ID uniquely identifies your system organization to RSA SecurID.
-
Examine the certificate expiration date and, if expiring soon, regenerate the certificate by clicking Regenerate.
-
Click Retrieve Metadata.
-
-
On the Identity Provider tab, upload the SAML metadata that you previously received from your identity provider.
-
Select Use SAML Identity Provider.
-
Either click the Browse icon () and upload the file, or copy and paste its content in the Metadata XML text box.
-
-
Click Save.
Configuration is complete.
Return to the main page for more certification related information.
Related Articles
Vmware vSphere vCenter 6.7 - Authentication Agent Configuration - RSA Ready SecurID Access Implementation Guide 196Number of Views VMware vSphere/vCenter 8.0.2 - Authentication Agent Configuration - RSA Ready Implementation Guide 131Number of Views Palo Alto NGFW Global Protect - SAML Relying Party Configuration - RSA Ready Implementation Guide 110Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 227Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 197Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Deploying RSA Authenticator 6.2.2 for Windows Using DISM RSA MFA Agent 2.4 for Microsoft Windows Installation and Administration Guide