SRG-OS-99999-ESXI5-000160 - The system must use the vSphere Authentication Proxy to protect passwords when adding ESXi hosts to Active Directory.

Information

ESXi hosts configured to join an Active Directory domain using host profiles do not protect the passwords used for host authentication. To avoid transmitting clear text passwords, the vSphere Authentication Proxy must be used to configure hosts in an Active Directory.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere client, select 'Host Profiles'. Right click the Host Profile and select Edit. Choose 'Authentication configuration >> Active Directory Configuration >> Join Domain Method'. Set the Join Domain Method to 'Use vSphere Authentication Proxy to add the host to domain'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_ESXi5_Server_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Group-ID|V-39352, Rule-ID|SV-250673r799018_rule, STIG-ID|SRG-OS-99999-ESXI5-000160, STIG-Legacy|SV-51210, STIG-Legacy|V-39352, Vuln-ID|V-250673

Plugin: VMware

Control ID: bb30c76546fce6b9635596f87bb9692ebc3cceec20fc75bd49192faa8fade109