The ESXi host must use DOD-approved certificates.
An XCCDF Rule
Description
<VulnDiscussion>The default self-signed host certificate issued by the VMware Certificate Authority (VMCA) must be replaced with a DOD-approved certificate when the host will be accessed directly, such as during a virtual machine (VM) console connection. The use of a DOD certificate on the host assures clients the service they are connecting to is legitimate and properly secured.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-256431r886074_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Join the ESXi host to vCenter before replacing the certificate.
Obtain a DOD-issued certificate and private key for the host following the requirements below:
Key size: 2048 bits or more (PEM encoded)