Skip to content

The Security Token Service application files must be verified for their integrity.

An XCCDF Rule

Description

<VulnDiscussion>Verifying the Security Token Service application code is unchanged from its shipping state is essential for file validation and nonrepudiation of the Security Token Service. There is no reason the MD5 hash of the RPM original files should be changed after installation, excluding configuration files. Satisfies: SRG-APP-000131-WSR-000051, SRG-APP-000357-WSR-000150</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-256752r889226_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Reinstall the vCenter Server Appliance (VCSA) or roll back to a backup. 
 
VMware does not support modifying the Security Token Service installation files manually.