Skip to content

VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000516-AS-000237

    <GroupDescription></GroupDescription>
    Group
  • The vCenter STS service must enable "ENFORCE_ENCODING_IN_GET_WRITER".

    &lt;VulnDiscussion&gt;Some clients try to guess the character encoding of text media when the mandated default of ISO-8859-1 should be used. Some b...
    Rule Medium Severity
  • SRG-APP-000141-AS-000095

    <GroupDescription></GroupDescription>
    Group
  • The vCenter STS service manager webapp must be removed.

    &lt;VulnDiscussion&gt;Tomcat provides management functionality through either a default manager webapp or through local editing of the configuratio...
    Rule Medium Severity
  • SRG-APP-000141-AS-000095

    <GroupDescription></GroupDescription>
    Group
  • The vCenter STS service host-manager webapp must be removed.

    &lt;VulnDiscussion&gt;Tomcat provides host management functionality through either a default host-manager webapp or through local editing of the co...
    Rule Medium Severity
  • SRG-APP-000014-AS-000009

    <GroupDescription></GroupDescription>
    Group
  • The vCenter STS service must be configured to use strong encryption ciphers.

    &lt;VulnDiscussion&gt;Tomcat has several remote communications channels. Examples are user requests via http/https, communication to a backend data...
    Rule Medium Severity
  • SRG-APP-000033-AS-000024

    <GroupDescription></GroupDescription>
    Group
  • The vCenter STS service cookies must have secure flag set.

    &lt;VulnDiscussion&gt;The secure flag is an option that can be set by the application server when sending a new cookie to the user within an HTTP R...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules