WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
  • VKS
  • Homelab
    • Resources
    • Nested Virtualization
  • VMware Nostalgia
  • Apple

vCenter Identity Federation with Authelia

04.16.2025 by William Lam // Leave a Comment

Gotta catch them all!? 😂

Looks like I will be adding another identity provider to my existing collection of IdPs (Authentik, KeyCloak, Synology SSO, Pocket ID, Zitadel and Kanidm) that can be used with vCenter Server and VMware Cloud Foundation (VCF) Identity Federation.

Authelia is another free and self-hosted IdP solution, which also supports Time-based one-time password (TOTP) out of the box and all configurations are managed in a couple of configuration files as there is no administrative web UI.

[Read more...]

Categories // VCSA, VMware Cloud Foundation, vSphere 8.0 Tags // Authelia, Identity Provider, OAuth, OIDC, vCenter Server, VCSA

vCenter Server Identity Federation with Kanidm

04.10.2025 by William Lam // 1 Comment

Looks like I will be expanding my collection of identity providers (Authentik, KeyCloak, Synology SSO, Pocket ID and Zitadel) that can be used with vCenter Server and/or VMware Cloud Foundation (VCF) Identity Federation!

Fellow colleague, Eric Gray just made me aware of another self-hosted IdP called Kanidm, which he had success setting up and thought I might be interested.


Kanidm is another basic free IdP that allows users to easily setup to play with vCenter Server and/or VCF Identity Federation, but what makes this IdP unique is that it is completely managed using a CLI, there is no web interface like ones listed above.

Additionally, Kanidm supports both traditional username/password authentication and modern passkeys. If you decide to use traditional passwords, Kanidm does require setting up Time-based One-Time Passwords (TOTP) using something like Google Authenticator and provides another factor of authentication, which is pretty neat!

[Read more...]

Categories // VCSA, VMware Cloud Foundation, vSphere 8.0 Tags // Identity Provider, Kanidm, OAuth, OIDC, vCenter Server, VCSA

Quick Tip - Retrieving vCenter Identity Federation Secret Token Expiry

04.09.2025 by William Lam // Leave a Comment

As part of setting up vCenter Server or VMware Cloud Foundation (VCF) Identity Federation, if your identity provider supports the SCIM (System for Cross-domain Identity Management) protocol, you must generate a token from vCenter Server. This token enables the identity provider to automatically publish users to the vCenter Server Identity Broker (vIDB), so that you can look up users from your identity provider for vSphere Role assignment.


The token that is generated by vCenter Server is known as a JWT (JSON Web Token) and once you have copied it, you can no longer retrieve the value, which is by design. In the vSphere UI, it does provide the expiry of the last JWT token that was generated and I was recently asked on how to retrieve this value?

[Read more...]

Categories // VCSA, VMware Cloud Foundation, vSphere 8.0 Tags // Identity Provider, JWT, OAuth, OIDC, vCenter Server, VCSA

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • …
  • 560
  • Next Page »

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Mastodon
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • Programmatically accessing the Broadcom Compatibility Guide (BCG) 05/06/2025
  • Quick Tip - Validating Broadcom Download Token  05/01/2025
  • Supported chipsets for the USB Network Native Driver for ESXi Fling 04/23/2025
  • vCenter Identity Federation with Authelia 04/16/2025
  • vCenter Server Identity Federation with Kanidm 04/10/2025

Advertisment

Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2025

 

Loading Comments...