VMware Cloud Community
snejk
Contributor
Contributor

2FA for vCloud Director

Hi,

Does anyone have expirience with securing vCloud Director login page for tenants with 2 factor authentication? Is there any 3rd party solution which "just works" or is there any other method of implementing 2FA with vCloud Director? I've searched google and didn't find much about this topic.

11 Replies
KenNalbone
Enthusiast
Enthusiast

Did you ever find a solution to give your tenants 2fa?  My searching has mostly come up empty. No 2fa providers specifically mention vCloud Director.

Reply
0 Kudos
mjha
Hot Shot
Hot Shot

I will check this out with Our vCD development team and will get back to you soon with Answers

Please consider marking this answer "correct" or "helpful" if you think your query have been answered correctly. Manish Jha | Operations Support Engineer | vCloud Air Operations vExpert 2015-17 | vExpert-NSX | vExpert-Cloud | VCAP6-DCV | VCP6-DCV | RHCE-7 Website : http://vstellar.com
red_davelee
Enthusiast
Enthusiast

Hi Snejk

You can setup vCloud Director to use a SAML provider for authentication on a per-tenant basis.  I've set it up for Safenet's Secure Authentication Service for one of our customers who wanted 2fa.  I struggled with it initially but got it to work in the end.  I believe Safenet have now included instructions for using their service with vCloud Director.

Dave

KenNalbone
Enthusiast
Enthusiast

Alex, anything?

Reply
0 Kudos
SGenzer
VMware Employee
VMware Employee

vCloud Director tenants can configure SAML based identity federation with Active Directory. This blog contains a step by step explanation : Configure Active Directory Federation for vCloud Director Organization – Tom Fojta's Blog

Reply
0 Kudos
KenNalbone
Enthusiast
Enthusiast

Not really look for just AD, but multi-factor. I see that blog post contains details about using Safenet and RSA though. So it looks like I'll need to figure out how to setup a generic SAML connection with one of those or something like DUO which may be doable.

Reply
0 Kudos
VMsentinel
Contributor
Contributor

Out of curiosity, is there any update on this?

Did you find another solution?

We are also looking into a simple way to implement a phone call/sms as a 2nd factor for vCD.

Reply
0 Kudos
Acar83
Contributor
Contributor

ok for identity provider but a trivial qrcode for native 2fa token is welcome. 80% of installations in the world would immediately be safer. Think about it seriously, it's an easy feature to make.

Reply
0 Kudos
miskaste
Contributor
Contributor

You can try open source Keycloak by RedHat which is working fine. It have 2FA feature.

There are out here couple blogs how to implement. Like this one:

https://bakingclouds.com/configure-vcloud-director-to-use-keycloak-identity-as-saml-provider/

 

Reply
0 Kudos
bryanvaneeden
Hot Shot
Hot Shot

There are loads of possibilities now that you can use SAML and IDP's to configure tenant authentication and authorization. We use WS ONE Access in combination with our VCD installment to provide easy MFA to the environment. As can any other SAML based authentication tooling.

Visit my blog at https://vcloudvision.com!
ITaaP
Enthusiast
Enthusiast

We use SAML with Azure for other solutions and plan on using it for VCD tenants.

By the way, nice blog!

https://tactsol.com https://vmware.solutions
Reply
0 Kudos