ESXi : set-dcui-access

Information

Set DCUI.Access to allow trusted users to override lockdown mode.
Lockdown mode disables direct host access requiring that admins manage hosts from vCenter Server. However, if a host becomes isolated from vCenter Server, the admin is locked out and can no longer manage the host. If you are using normal lockdown mode, you can avoid becoming locked out of an ESXi host that is running in lockdown mode, by setting DCUI.Access to a list of highly trusted users who can override lockdown mode and access the DCUI. The DCUI is not running in strict lockdown mode.
http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.security.doc/GUID-6779F098-48FE-4E22-B116-A8353D19FF56.html
http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.security.doc/GUID-88B24613-E8F9-40D2-B838-225F5FF480FF.html

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Web Client select the host, click "Manage" -> "Settings" -> "System" -> "Advanced Sytem Settings". Enter "DCUI.Access" in the filter. Enter comma separated user accounts who are authorized to access DCUI even in case of lockdown mode.

Caution: Do not remove root user.

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vSphere_6_0_Hardening_Guide_GA_15_Jun_2015.xls

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: VMware

Control ID: 58140108d093c6ef29ea7cd36e6e3ba2f389d65269bc771cb6b95c288c443bda