5.1 Ensure the DCUI timeout is set to 600 seconds or less

Information

The Direct Console User Interface (DCUI) is used for directly logging into an
ESXi host and carrying out host management tasks. This setting terminates an idle DCUI session
after the specified number of seconds has elapsed.

*Rationale*

Terminating idle DCUI sessions helps avoid unauthorized usage of the DCUI originating from leftover login sessions.

Solution

To correct the DCUI timeout setting, perform the following steps:

1. From the vSphere Web Client, select the host.
2. Click "Configure" -> "Settings" -> "System" -> "Advanced System Settings".
3. Enter "UserVars\.DcuiTimeOut" in the filter.
4. Click "Edit".
5. Set the value for this parameter to 600 seconds or less.

Alternately, use the following PowerCLI command:

Get-VMHost | Get-AdvancedSetting -Name UserVars.DcuiTimeOut | Set- AdvancedSetting -Value 600

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CSCv7|16.11

Plugin: VMware

Control ID: eb1c2f5a0569d9c4cbfaf830e0f9b66ea0141687ce7c4d8089bc666562c49062