Skip to content

The vCenter Server must disable Username/Password and Windows Integrated Authentication.

An XCCDF Rule

Description

All forms of authentication other than Common Access Card (CAC) must be disabled. Password authentication can be temporarily reenabled for emergency access to the local Single Sign-On (SSO) accounts or Active Directory user/pass accounts, but it must be disabled as soon as CAC authentication is functional.

ID
SV-258950r961863_rule
Version
VCSA-80-000283
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Next to "Authentication method", click "Edit".

Select to radio button to "Enable smart card authentication".