VCTR-67-000078 - The vCenter Server must disable Password and Windows integrated authentication.

Information

All forms of authentication other than CAC must be disabled. Password authentication can be temporarily reenabled for emergency access to the local SSO domain accounts, but it must be disabled as soon as CAC authentication is functional.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Client, go to Administration >> Single Sign-On >> Configuration >> Smart Card Authentication.

Next to 'Authentication methods', click 'Edit'.

Click the 'Enable smart card authentication' radio button and click 'Save'.

To reenable password authentication for troubleshooting purposes, run the following command on the vCenter server:

C:\Program Files\VMware\VCenter server\VMware Identity Services\sso-config.bat -set_authn_policy -pwdAuthn true -winAuthn false -certAuthn false -securIDAuthn false -t vsphere.local

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-243133r879887_rule, STIG-ID|VCTR-67-000078, Vuln-ID|V-243133

Plugin: VMware

Control ID: 18dba439cd0874af71163055dcde4f0e642c8a95a603bf33ff71e905004dc29f