VMware Cloud Community
tdubb123
Expert
Expert
Jump to solution

multiple vcenters - single sso or multiple sso

Untitled.pngI got 3 vcenters all located in different geographical sites. Is it best to create 3 different sso domains or just one?

If I do just one, then my psc will have to be located in just one site?

can i do a sso domain (vsphere.local) across all 3 sites and have them replicate?

Reply
0 Kudos
1 Solution

Accepted Solutions
npadmani
Virtuoso
Virtuoso
Jump to solution

when you deploy third PSC, to join existing SSO domain, either of existing PSC hostname will do. No such concept of master PSC host here.

Narendra Padmani VCIX6-DCV | VCIX7-CMA | VCI | TOGAF 9 Certified

View solution in original post

Reply
0 Kudos
4 Replies
npadmani
Virtuoso
Virtuoso
Jump to solution

it best to create 3 different sso domains or just one?

Enhanced Linked Mode lets you view and search across all linked vCenter Server systems and replicate roles, permissions, licenses, policies, and tags. Do you want this, then go for Enhanced Linked mode, which is having one SSO domain and multiple PSCs talking to it. In short when first PSC deployed, new SSO domain got created, from second instance onwards just point it to existing SSO domain. If you create different SSO domain per site, you don't have Enhanced linked mode.

if I do just one, then my psc will have to be located in just one site?


if you do just one SSO domain, No, your PSC doesn't need to be located at one site. I would go with per site at least 1 PSC deployment, may be more for higher availability and load balancing.


can i do a sso domain (vsphere.local) across all 3 sites and have them replicate?

First instance PSC deployment at Site 1, you create vSphere.local as your SSO domain, now at Site 2 and Site 3 when you deploy PSC, don't create domain but join existing vSphere.local domain, this will satisfy Enhanced Linked mode requirements and those multiple site VMDIR will be synching.

Narendra Padmani VCIX6-DCV | VCIX7-CMA | VCI | TOGAF 9 Certified
Reply
0 Kudos
tdubb123
Expert
Expert
Jump to solution

Thank you. it makes sense. will give it a try. Is there a "master psc" within the sso domain? After I setup another site to join the sso domain and I decide to add a third, do i make it join the first PSC or either existing psc will do?

Reply
0 Kudos
npadmani
Virtuoso
Virtuoso
Jump to solution

when you deploy third PSC, to join existing SSO domain, either of existing PSC hostname will do. No such concept of master PSC host here.

Narendra Padmani VCIX6-DCV | VCIX7-CMA | VCI | TOGAF 9 Certified
Reply
0 Kudos
tdubb123
Expert
Expert
Jump to solution

I was able to see enhanced linked mode only by logging in via the web client. but not the thick client. Is this by design?

Reply
0 Kudos