The vCenter VAMI service must implement HTTP Strict Transport Security (HSTS).
An XCCDF Rule
Description
HSTS instructs web browsers to only use secure connections for all future requests when communicating with a website. Doing so helps prevent SSL protocol attacks, SSL stripping, cookie hijacking, and other attempts to circumvent SSL protection.
- ID
- SV-259157r1003730_rule
- Version
- VCLD-80-000099
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Navigate to and open:
/opt/vmware/etc/lighttpd/applmgmt-lighttpd.conf
If header "Strict-Transport-Security" is not present, add the following line to the end of the file: