SRG-OS-99999-ESXI5-000147 - The system must ensure uniqueness of CHAP authentication secrets.

Information

The mutual authentication secret for each host must be different and the secret for each client authenticating to the server must be different as well. This ensures if a single host is compromised, an attacker cannot create another arbitrary host and authenticate to the storage device. With a single shared secret, compromise of one host can allow an attacker to authenticate to the storage device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Client, select the host, and then choose: Configuration - Storage Adaptors - iSCSI Initiator Properties - CHAP - CHAP
(Target Authenticates Host) - configure the authentication secret.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_ESXi5_Server_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Group-ID|V-39303, Rule-ID|SV-250665r798994_rule, STIG-ID|SRG-OS-99999-ESXI5-000147, STIG-Legacy|SV-51119, STIG-Legacy|V-39303, Vuln-ID|V-250665

Plugin: VMware

Control ID: ed0563486a530be36311d37e30fe5558b693efd60ab222ef90db5955a6490761