3.18 (L1) Host must have an accurate DCUI.Access list

Information

The DCUI.Access parameter in VMware ESXi is used to specify a list of users who are permitted to access the Direct Console User Interface (DCUI) of the ESXi host, especially when Lockdown Mode is enabled. This parameter helps in controlling and securing access to the ESXi host by allowing only authorized users to override Lockdown Mode and access the DCUI, particularly in scenarios where the host becomes isolated from vCenter. The parameter governing this behavior is DCUI.Access.

A properly configured DCUI.Access list ensures that only authorized users can override Lockdown Mode to access DCUI, providing a fail-safe against loss of management capability especially if the host loses connection to vCenter.

Solution

To set a trusted users list for DCUI, perform the following from the vSphere web client:

- From the vSphere Web Client, select the host.
- Click Configure then expand System
- Select Advanced System Settings then click Edit
- Enter DCUI.Access in the filter.
- Set the DCUI.Access attribute is set to a comma-separated list of the users who are allowed to override lockdown mode.

Impact:

Misconfiguration could lead to unauthorized access or potential lockout scenarios, making it crucial to validate the list and ensure the host's attachment to vCenter alongside correctly configured access and exception lists prior to Lockdown Mode activation.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-2, 800-53|CM-7(5), 800-53|CM-10, CSCv7|14.6, CSCv7|16.6

Plugin: VMware

Control ID: 51306be5b8165f4c47a1a6fc5748c0eff8416ad9ecf9913db7cb9beacdd894ad