6.2 Ensure uniqueness of CHAP authentication secrets for iSCSI traffic

Information

Challenge-Handshake Authentication Protocol (CHAP) requires both client and host to
know the secret (password) to establish a connection. Each mutual authentication secret should be unique.

*Rationale*

If all mutual authentication secrets are unique, compromise of one secret does not allow an
attacker to authenticate to other hosts or clients using that same secret.


NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Perform the following-

1. From the vSphere Web Client, navigate to 'Hosts'.
2. Click on a host.
3. Click on 'Configure' -> 'Storage' -> 'Storage Adapters'.
4. Select the iSCSI adapter to configure OR click the green plus symbol to create a new
adapter.
5. Under Adapter Details, click the Properties tab and click 'Edit' in the Authentication
panel.
6. Specify authentication method.
1.
. None
. Use unidirectional CHAP if required by target
. Use unidirectional CHAP unless prohibited by target
. Use unidirectional CHAP
. Use bidirectional CHAP.7. Specify the outgoing CHAP name.
o Make sure that the name you specify matches the name configured on the
storage side.
. To set the CHAP name to the iSCSI adapter name, select Use initiator
name.
. To set the CHAP name to anything other than the iSCSI initiator name,
deselect Use initiator name and type a name in the Name text box.8. Enter an outgoing CHAP secret to be used as part of authentication. Use the same
secret as your storage side secret.
9. If configuring with bidirectional CHAP, specify incoming CHAP credentials.
o Make sure your outgoing and incoming secrets do not match.10. Click OK.
11. Click the second to last symbol to rescan the iSCSI adapter.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: VMware

Control ID: 52136adbb9c6a7a5987be8822ae3a7fa2c59c66d1178f68ecbcbda700af82737