8.3.3 Use secure protocols for virtual serial port access

Information

Virtual serial ports allow virtual machines to communicate over the network. Doing so
allows you to redirect the virtual serial port connection to a TCP/IP connection on the ESXi
host. If virtual serial ports are needed be sure they are configured to use secure protocols.

*Rationale*

Serial ports are interfaces for connecting peripherals to the virtual machine. They are often
used on physical systems to provide a direct, low-level connection to the console of a
server. Serial ports allow for debug level access, which often does not have strong controls
like logging or privileges.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configuring Virtual Serial Port Communications with Secure Network Protocols-. ssl - the equivalent of TCP+SSL
. tcp+ssl - SSL over TCP over IPv4 or IPv6
. tcp4+ssl - SSL over TCP over IPv4
. tcp6+ssl - SSL over TCP over IPv6
. telnet over TCP with SSL. The virtual machine and remote system can negotiate and
use SSL if the remote system supports the telnet authentication option. If not, the
connection uses unencrypted text (plain text)
. telnets - telnet over SSL over TCP. In this case, SSL negotiation begins immediately
and you cannot use the telnet authentication option.

See Also

https://workbench.cisecurity.org/files/145

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: VMware

Control ID: 1ecab1e4a1d93a07c860773a88673528b1265cd691d6a7a244d3a5d738b45df1