6.3.2 (L1) Host iSCSI client, if enabled, must employ unique CHAP authentication secrets

Information

Challenge-Handshake Authentication Protocol (CHAP) requires both client and host to know a secret to establish a connection. It is essential to employ unique CHAP authentication secrets for each iSCSI session to ensure secure communications. The parameter governing this behavior is outlined in the iSCSI or iSER storage adapter configuration under CHAP settings.

Utilizing unique CHAP authentication secrets for each iSCSI session promotes secure data transmission and mitigates the risk of unauthorized access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To change the values of CHAP secrets so they are unique, perform the following:

- From the vSphere Web Client, select the host.
- Click Configure then expand Storage
- Select Storage Adapters then select the iSCSI Adapter.
- Under Properties click on Edit next to Authentication
- Next to Authentication Method specify the authentication method from the dropdown.
- None
- Use unidirectional CHAP if required by target
- Use unidirectional CHAP unless prohibited by target
- Use unidirectional CHAP
- Use bidirectional CHAP

- Specify the outgoing CHAP name.

- Make sure that the name you specify matches the name configured on the storage side.
- To set the CHAP name to the iSCSI adapter name, select "Use initiator name".
- To set the CHAP name to anything other than the iSCSI initiator name, deselect "Use initiator name" and type a name in the Name text box.

<xhtml:ol start="8"> - Enter an outgoing CHAP secret to be used as part of authentication. Use the same secret as your storage side secret.
- If configuring with bidirectional CHAP, specify incoming CHAP credentials.

- Make sure your outgoing and incoming secrets do not match.

<xhtml:ol start="10"> - If configuring with bidirectional CHAP, specify incoming CHAP credentials.

- Make sure your outgoing and incoming secrets do not match.

<xhtml:ol start="11"> - Click OK
- Click the second to last symbol labeled Rescan Adapter

Impact:

While enhancing security, misconfiguration or sharing of CHAP secrets across sessions could potentially lead to connectivity issues or unauthorized access.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: VMware

Control ID: cc3ce74cc65037f11e57e878b380233d03939702cdfc6d3ae498f36894269016