Very quick walkthrough on how to integrate NSX-T and Workspace One Access (VIDM) This allows workspace one to create a OAuth connection with NSX-T where you can control user access via Active directory and instead of trying to manage local accounts.
Logon to NSX-T manager > System
data:image/s3,"s3://crabby-images/28094/280947f4acc57ad8810daf69e58c36cd9e654474" alt=""
settings > user management
data:image/s3,"s3://crabby-images/9ab72/9ab7237b3bacaf267143334daeda8f0963519b52" alt=""
Then Login into Workspace One Access >Catalog >Settings
data:image/s3,"s3://crabby-images/a9c11/a9c11efdd516eced02fb19f20feab84da6d48bd1" alt=""
Go to Remote App Access > Click on Create Client
data:image/s3,"s3://crabby-images/47be7/47be75811f7c59d10faceddd4567c5f08c44cd1a" alt=""
Select access type of ‘Service Client Token’
Fill in the Name of the Client ID, chose something like nsx-mgr-OAuth
Generate Shared Secret, copy it so then when we go back to Workspace One Access we can paste it in. Click Add or save
data:image/s3,"s3://crabby-images/22ca2/22ca2622c9526460bfd255c8e4ad3b37a1cc42dd" alt=""
Now back to NSX-T, fill in your FQDN for your workspace one appliance.
User Management > VMware Identity Manager
data:image/s3,"s3://crabby-images/cd610/cd610c9205a47292c4906e5f6ab65accbcbb346c" alt=""
Don’t click Save yet! we need the SSL Thumbprint
SSH into your Workspace One Appliance. We will get the SSL Thumbprint.
Change directory to /usr/local/horizon/conf
If you are using a CA Signed Certificate you will need to follow the prompt below.
openssl s_client -servername workspace.yourfqdn.io -connect workspace.yourfqdn.io:443 | openssl x509 -fingerprint -sha256 -noout
Copy and paste in the fingerprint given and click save.
data:image/s3,"s3://crabby-images/4f9ad/4f9ad14661416262f16118e613cfe9ce371ad020" alt=""
Leave a Reply