4.2 Ensure the vpxuser account's password is automatically changed every 10 or fewer days

Information

http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.security.doc/GUID-96210743-0C17-4AE9-89FC-76778EC9D06E.html

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Set the vCenter Password Expiration Value to 10
Get-AdvancedSetting -Entity $defaultVIServer -Name 'VirtualCenter.VimPasswordExpirationInDays' | Set-AdvancedSetting -Value 10

Impact-The password aging policy must not be shorter than the interval that is set to automatically
change the vpxuser password, otherwise vCenter might get locked out of an ESXi host.

Default Value-Password automatically changes every 30 days.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(d)

Plugin: VMware

Control ID: cc103ac9ee37428d0d92729761b018d6cf53cf36a17bd46d7962c35104cecc6e