DISA VMware vSphere 8.0 ESXi STIG v2r3 Unix

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA VMware vSphere 8.0 ESXi STIG v2r3 Unix

Updated: 9/2/2026

Authority: DISA STIG

Plugin: Unix

Revision: 1.4

Estimated Item Count: 24

File Details

Filename: DISA_VMware_vSphere_8.0_ESXi_STIG_Bare_Metal_Host_v2r3.audit

Size: 51.8 kB

MD5: 73075937b115dfa44210713d157cb811
SHA256: 1ad6d7292a6b15d40d0e65ef1faa01912dd0a337b1c7281ea64cbb171b73e8ac

Audit Items

DescriptionCategories
DISA_STIG_VMware_vSphere_8.0_ESXi_v2r3_Unix.audit from DISA VMware vSphere 8.0 ESXi STIG v2r3
ESXI-80-000014 - The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.
ESXI-80-000052 - The ESXi host Secure Shell (SSH) daemon must ignore .rhosts files.
ESXI-80-000085 - The ESXi host must implement Secure Boot enforcement.
ESXI-80-000094 - The ESXi host must enable Secure Boot.
ESXI-80-000133 - The ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance level must be verified.
ESXI-80-000187 - The ESXi host Secure Shell (SSH) daemon must be configured to only use FIPS 140-2 validated ciphers.
ESXI-80-000192 - The ESXi host Secure Shell (SSH) daemon must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system.
ESXI-80-000202 - The ESXi host Secure Shell (SSH) daemon must not allow host-based authentication.
ESXI-80-000204 - The ESXi host Secure Shell (SSH) daemon must not permit user environment settings.
ESXI-80-000207 - The ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports.
ESXI-80-000209 - The ESXi host Secure Shell (SSH) daemon must not permit tunnels.
ESXI-80-000210 - The ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions.
ESXI-80-000211 - The ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions.
ESXI-80-000212 - The ESXi host must disable Simple Network Management Protocol (SNMP) v1 and v2c.
ESXI-80-000229 - The ESXi host must use DOD-approved certificates.
ESXI-80-000230 - The ESXi host Secure Shell (SSH) daemon must disable port forwarding.
ESXI-80-000236 - The ESXi host must not be configured to override virtual machine (VM) configurations.
ESXI-80-000237 - The ESXi host must not be configured to override virtual machine (VM) logger settings.
ESXI-80-000238 - The ESXi host must require TPM-based configuration encryption.
ESXI-80-000245 - The ESXi host must use sufficient entropy for cryptographic operations.
ESXI-80-000247 - The ESXi host must use DOD-approved encryption to protect the confidentiality of network sessions.
ESXI-80-000248 - The ESXi host must disable key persistence.
ESXI-80-000249 - The ESXi host must deny shell access for the dcui account.