VMware vSphere 8.0 vCenter Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000516
Group -
The vCenter Server must separate authentication and authorization for administrators.
Many organizations do both authentication and authorization using a centralized directory service such as Active Directory. Attackers who compromise an identity source can often add themselves to a...Rule Medium Severity -
SRG-APP-000516
Group -
SRG-APP-000516
Group -
The vCenter Server must remove unauthorized port mirroring sessions on distributed switches.
The vSphere Distributed Virtual Switch can enable port mirroring sessions allowing traffic to be mirrored from one source to a destination. If port mirroring is configured unknowingly this could al...Rule Medium Severity -
SRG-APP-000516
Group -
The vCenter Server must not override port group settings at the port level on distributed switches.
Port-level configuration overrides are disabled by default. Once enabled, this allows for different security settings to be set from what is established at the Port Group level. If overrides are no...Rule Medium Severity -
SRG-APP-000516
Group -
SRG-APP-000516
Group -
The vCenter Server must disable Secure Shell (SSH) access.
vCenter Server is delivered as an appliance, and intended to be managed through the VAMI, vSphere Client, and APIs. SSH is a troubleshooting and support tool and should only be enabled when necessa...Rule Medium Severity -
SRG-APP-000516
Group -
SRG-APP-000014
Group -
The vCenter Server must use DOD-approved encryption to protect the confidentiality of network sessions.
Using older unauthorized versions or incorrectly configuring protocol negotiation makes the gateway vulnerable to known and unknown attacks that exploit vulnerabilities in this protocol. In vCente...Rule Medium Severity -
SRG-APP-000516
Group -
The vCenter Server must disable accounts used for Integrated Windows Authentication (IWA).
If not used for their intended purpose, default accounts must be disabled. vCenter ships with several default accounts, two of which are specific to IWA and SASL/Kerberos authentication. If other m...Rule Medium Severity -
The vCenter Server must display the Standard Mandatory DOD Notice and Consent Banner before logon.
Display of the DOD-approved use notification before granting access to the application ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive ...Rule Medium Severity -
vCenter Server plugins must be verified.
The vCenter Server includes a vSphere Client extensibility framework, which provides the ability to extend the vSphere Client with menu selections or toolbar icons that provide access to vCenter Se...Rule Medium Severity -
The vCenter Server must uniquely identify and authenticate users or processes acting on behalf of users.
To ensure accountability and prevent unauthenticated access, organizational users must be identified and authenticated to prevent potential misuse and compromise of the system. Organizational user...Rule Medium Severity -
The vCenter Server must prohibit password reuse for a minimum of five generations.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. To meet password policy requirements, passwords must be...Rule Medium Severity -
The vCenter Server passwords must contain at least one uppercase character.
Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resistin...Rule Medium Severity -
The vCenter Server passwords must contain at least one numeric character.
Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resistin...Rule Medium Severity -
The vCenter Server passwords must contain at least one special character.
Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resistin...Rule Medium Severity -
The vCenter Server must enable revocation checking for certificate-based authentication.
The system must establish the validity of the user-supplied identity certificate using Online Certificate Status Protocol (OCSP) and/or Certificate Revocation List (CRL) revocation checking. Satis...Rule Medium Severity -
The vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority.
Untrusted certificate authorities (CA) can issue certificates, but they may be issued by organizations or individuals that seek to compromise DOD systems or by organizations with insufficient secur...Rule Medium Severity -
The vCenter Server must enable data at rest encryption for vSAN.
Applications handling data requiring "data at rest" protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest. Data encryption...Rule Medium Severity -
The vCenter server must enforce SNMPv3 security features where SNMP is required.
SNMPv3 supports commercial-grade security, including authentication, authorization, access control, and privacy. Previous versions of the protocol contained well-known security weaknesses that were...Rule Medium Severity -
The vCenter Server must set the distributed port group Forged Transmits policy to "Reject".
If the virtual machine operating system changes the Media Access Control (MAC) address, the operating system can send frames with an impersonated source MAC address at any time. This allows an oper...Rule Medium Severity -
The vCenter Server must restrict access to the default roles with cryptographic permissions.
In vSphere, the built-in "Administrator" role contains permission to perform cryptographic operations such as Key Management Server (KMS) functions and encrypting and decrypting virtual machine dis...Rule Medium Severity -
The vCenter Server must restrict access to cryptographic permissions.
These permissions must be reserved for cryptographic administrators where virtual machine encryption and/or vSAN encryption is in use. Catastrophic data loss can result from poorly administered cry...Rule Medium Severity -
The vCenter server configuration must be backed up on a regular basis.
vCenter server is the control plane for the vSphere infrastructure and all the workloads it hosts. As such, vCenter is usually a highly critical system in its own right. Backups of vCenter can now ...Rule Medium Severity -
The vCenter server must enable the OVF security policy for content libraries.
In the vSphere Client, you can create a local or a subscribed content library. By using content libraries, you can store and manage content in one vCenter Server instance. Alternatively, you can di...Rule Medium Severity -
The vCenter Server must disable CDP/LLDP on distributed switches.
The vSphere Distributed Virtual Switch can participate in Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP), as a listener, advertiser, or both. The information is sensitive, i...Rule Low Severity -
The vCenter Server must reset port configuration when virtual machines are disconnected.
Port-level configuration overrides are disabled by default. Once enabled, this allows for different security settings to be set from what is established at the Port Group level. If overrides are no...Rule Medium Severity -
The vCenter Server must enable data in transit encryption for vSAN.
Transit encryption must be enabled to prevent unauthorized disclosure information and to protect the confidentiality of organizational information. vSAN data-in-transit encryption has the followin...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.