Two-factor authentication
VMware Cloud Director® supports two authentication methods — through the local user base and through SAML single sign-on (SSO) technology.
You can connect two-factor authentication using any service. Using the system Multifactor you can connect two-factor authentication via SSO for individual users. Local authentication will work in parallel. In Cloud Director, the user base with local access and SSO access will be shared.
Connect two-factor authentication via Multifactor
Install Multifactor
- Check in Multifactor control panels.
- Install the Multifactor mobile app.
Create a SAML application
- В Multifactor control panels go to Resources.
- Click Add resource.
- In the block Website select SAML application.
- Enter the name of the resource.
- Select an account provider.
- If you've chosen Active Directory, enter the portal address.
- Optional: to have the user automatically created in Multifactor the first time he/she authorizes in Cloud Director, enable the toggle switch Register new users.
- Optional: for the system to require the user to configure the 2FA and not allow authorization in Cloud Director without it, check the checkbox Enable self-customization/ Deny access.
- Click Save.
- On the SAML application page in the block Multifactor metadata download the SAML application metadata file.
customize SAML application
-
From control panels open the Cloud Director panel: VMware-based cloud → Cloud Director.
-
Open the tab Administration.
-
Go to the section Identity Providers →SAML.
-
Click Configure.
-
Open the tab Service Provider.
-
In the field Entity ID paste in the address of your cloud:
- Moscow —
https://vcd-msk.selectel.ru/tenant/<s-xxxx>/
- St. Petersburg —
https://vcd.selectel.ru/tenant/<s-xxxx>/
Specify
<s-xxxx>
— organization name, can be viewed in the Cloud Director address bar or in the control panels under VMware-based cloud on the list of organizations. - Moscow —
-
Open the tab Identity Provider.
-
Turn on the toggle switch Use SAML Identity Provider.
-
Download SAML application metadata file.
-
Click Save.
-
Open the tab Service Provider.
-
In the field Service Provider Metadata click Retrieve Metadata. The metadata file will download to your device.
-
В Multifactor control panels go to Resources.
-
In the SAML application line, click Parameters.
-
In the block Service provider click Download metadata and download the file.
Add users
- From control panels open the Cloud Director panel: VMware-based cloud → Cloud Director.
- Open the tab Administration.
- Go to the section Access Control → Users.
- Click Import Users.
- Enter the logins of users who will be able to connect through SSO.
- Select the role that will be assigned to users.
- Click Save.
Sign in with two-factor authentication
- From control panels open the Cloud Director panel: VMware-based cloud → Cloud Director.
- In the upper right corner in the menu click Log out.
- The page opens Selectel vCloud Director Logout Page.
- Click Login with Single Sign On.
- Log in with your vendor account.
- A one-time code will be sent to the Multifactor app.
- Enter code.