Information
To assure accountability and prevent unauthenticated access, privileged users must utilize multifactor authentication to prevent potential misuse and compromise of the system.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
The following are pre-requisites to configuration smart card authentication for the ESXi DCUI:
-Active Directory domain that supports smart card authentication, smart card readers, and smart cards.
-ESXi joined to an Active Directory domain.
-Trusted certificates for root and intermediary certificate authorities.
From the vSphere Web Client select the ESXi Host and go to Configure >> System >> Authentication Services and click Edit and check 'Enable Smart Card Authentication' checkbox, at the Certificates tab, click the green plus sign to import trusted certificate authority certificates and click OK.