Skip to content

The ESXi host must use DOD-approved certificates.

An XCCDF Rule

Description

The default self-signed host certificate issued by the VMware Certificate Authority (VMCA) must be replaced with a DOD-approved certificate when the host will be accessed directly, such as during a virtual machine (VM) console connection. The use of a DOD certificate on the host assures clients the service they are connecting to is legitimate and properly secured.

ID
SV-258784r959010_rule
Version
ESXI-80-000229
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Join the ESXi host to vCenter before replacing the certificate.

Obtain a DOD-issued certificate and private key for the host following the requirements below:

Key size: 2048 bits or more (PEM encoded)