Introducing the Platform Services Controller Interface in vCenter Server 6.0 Update 1¶
Back in March, we introduced vSphere 6.0 and the new architecture for vCenter Server. With this new architecture you learned about the Platform Services Controller, a new functional component of vCenter that moves beyond just Single Sign-On to include additional platform services such as:
- Licensing Service
- Certificate Authority (VMCA)
- Certificate Store (VECS)
- Lookup Service for Component Registrations
In the 6.0 release, administration and configuration of the Platform Service Controller was primarily performed by an SSH session, the vSphere Web Client and selecting the node in System Configuration, or through the Direct Console User Interface of the appliance.
In vCenter Server 6.0 Update 1, we're excited to introduce the next stage of the administration with the Platform Services Controller Interface, a fully HTML5-based interface to administer and configure many of the services that run on the PSC.
Using the Platform Services Controller Interface you can perform tasks, such as:
- Adding and Editing Users and Groups for Single Sign-On
- Adding Single Sign-On Identity Sources
- Configuring Single Sign-On Policies (e.g., Password Policies)
- Adding Certificate Stores
- Adding and Revoking Certificates
Here is a quick overview of the Platform Services Controller User Interface available in vCenter Server 6.0 Update 1.
https://<fqdn-or-ip>/psc/ and login to the HTML5-based Platform Services Controller Interface with a Single-Sign On administrative user (e.g.,
Once you've logged into the the Platform Services Controller Interface, you'll be directed to the Home section.
Here you are presented with sections for Single Sign-On, Certificates and Appliance Settings.
Let's take a look at each of these below.
Recall that beginning with vSphere 6.0, vCenter Single Sign-On is part of the Platform Services Controller. The Platform Services Controller contains the shared services that support vCenter Server and vCenter Server components. vCenter Single Sign-On is essentially an authentication broker and security token exchange infrastructure. When a user or a solution user authenticates successfully to vCenter Single Sign-On, that user receives SAML token. Thereafter, the user can use the SAML token to authenticate to vCenter services and perform any actions that user has privileges. In vSphere 6.0, the vCenter Server management group of services needed to be deployed in order to administer and configure Single Sign-On through the vSphere Web Client. In vCenter Server 6.0 Update 1 the Platform Services Controller Interface provides you direct access to the configuration. This can be useful during initial deployment configuration or even troubleshooting exercises.
Single Sign-On > Users & Groups¶
Manage users, groups and registered solution users in the Single Sign-On domain (e.g.,
vsphere.local) by directly connecting to the Platform Services Controller.
Single Sign-On > Configuration¶
Manage policies, such as, rules and restrictions for passwords (complexity requirements and lockout) plus the Secure Token Service clock tolerance, renewal, and re-authentication, etc.
Add an identity sources for user authentication -- these sources can be a native Active Directory (Integrated Windows Authentication) domain or an OpenLDAP directory service.
Manage the certificates for Identity Sources as well as the Secure Token Service Signing certificates.
Certificates > Certificate Store¶
Add, delete and show details for certificates in VECS (vSphere Endpoint Certificate Store) Certificate Stores.
Certificates > Certificate Authority¶
In vCenter Server 6.0, the VMware Certificate Authority (VMCA) provides each vCenter Server, Solution User and ESXi hosts with certificates that are signed by VMCA. These certificates can be trusted through to a VMCA signed root certificate (default mode) or through to an Enterprise / Commercial CA (subordinate mode). Management was performed using the Certificate Manager python program or using the
Now, in vCenter Server 6.0 Update 1 you have the option to manage portions of the VMware Certificate Authority using the Platform Services Controller Interface, such as, viewing active, revoked and expired certificates as well as replacing the root signing certificate for the VMCA (equivalent to Option 2 in the Certificate Manager).
Certificates > Certificate Management¶
You can also renew and replace both Machine SSL Certificates and Solution User Certificates in from within the Platform Services Controller Interface (equivalent to the options to replace Machine SSL Certificates and Solution User Certificates in Certificate Manager).
Appliance Settings > Appliance Settings¶
If you're running the vCenter Server Appliance you can manage its settings, such as, access, networking, time synchronization, updates, plus the root account password and expiration from the Appliance Management User Interface that returned (previously, called the VAMI) in vCenter Server 6.0 Update 1.
Learn more about this return of the Appliance Management UI in vCenter Server 6.0 Update 1 from Matt Meyer's blog post.
Appliance Settings > Manage¶
In this section you can join the Platform Services Controller to your Active Directory domain, similar to how you can do so in the vSphere Web Client's System Configuration > Node option. This is just way simpler.
And there you have it. The all new Platform Services Controller Interface in vCenter Server 6.0 Update 1. A slick new, HTML5-driven inteface tto administer and configure many of the services that run on the PSC with ease.
This is not an official VMware document. This is a personal blog post. The information is provided as-is with no warranties and confers no rights. It is not intended to replace official VMware documentation. Please, refer to official VMware documentation for the most up-to-date information.