Item Search

NameAudit NamePluginCategory
ESXI-70-000010 - The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

ACCESS CONTROL

ESXI-70-000013 - The ESXi host Secure Shell (SSH) daemon must not allow host-based authentication.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

CONFIGURATION MANAGEMENT

ESXI-70-000015 - The ESXi host Secure Shell (SSH) daemon must not allow authentication using an empty password.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

CONFIGURATION MANAGEMENT

ESXI-70-000016 - The ESXi host Secure Shell (SSH) daemon must not permit user environment settings.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

CONFIGURATION MANAGEMENT

ESXI-70-000021 - The ESXi host Secure Shell (SSH) daemon must not allow compression or must only allow compression after successful authentication.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

CONFIGURATION MANAGEMENT

ESXI-70-000023 - The ESXi host Secure Shell (SSH) daemon must be configured to not allow X11 forwarding.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

CONFIGURATION MANAGEMENT

ESXI-70-000090 - The ESXi host rhttpproxy daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

ACCESS CONTROL

PHTN-30-000003 - The Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting Secure Shell (SSH) access.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

ACCESS CONTROL

PHTN-30-000006 - The Photon operating system must have the sshd SyslogFacility set to 'authpriv' - authpriv.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

ACCESS CONTROL

PHTN-30-000015 - The Photon operating system audit log must attempt to log audit failures to syslog.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000017 - The Photon operating system audit log must be owned by root.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000022 - The Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-30-000026 - The Photon operating system must use an OpenSSH server version that does not support protocol 1.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

PHTN-30-000027 - The Photon operating system must be configured so that passwords for new users are restricted to a 24-hour minimum lifetime.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-30-000062 - The Photon operating system must require users to reauthenticate for privilege escalation.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-30-000069 - The Photon operating system must audit the 'insmod' module - insmod moduleDISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000072 - The Photon operating system must set the 'FAIL_DELAY' parameter.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000075 - The Photon operating system must create a home directory for all new local interactive user accounts.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000080 - The Photon operating system must configure sshd to disable X11 forwarding.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000084 - The Photon operating system must configure sshd to disallow compression of the encrypted session stream.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000089 - The Photon operating system must be configured so the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000092 - The Photon operating system must be configured so that all global initialization scripts are protected from unauthorized modification.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000093 - The Photon operating system must be configured so that all system startup scripts are protected from unauthorized modification.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000097 - The Photon operating system must be configured so that all cron paths are protected from unauthorized modification.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000101 - The Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000102 - The Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000105 - The Photon operating system must not perform multicast packet forwarding.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000112 - The Photon operating system must protect sshd configuration from unauthorized access.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000114 - The Photon operating system must set the 'umask' parameter correctly.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000118 - The Photon operating system must ensure the old passwords are being stored.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION

VCLU-70-000019 - Lookup Service must limit the number of allowed connections.DISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCLU-70-000020 - Lookup Service must set URIEncoding to UTF-8.DISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

VCLU-70-000029 - Lookup Service must be configured with the appropriate ports.DISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix

CONFIGURATION MANAGEMENT

VCPF-70-000012 - Performance Charts must have Multipurpose Internet Mail Extensions (MIMEs) that invoke operating system shell programs disabled.DISA STIG VMware vSphere 7.0 Perfcharts Tomcat v1r1Unix

CONFIGURATION MANAGEMENT

VCPF-70-000019 - Performance Charts must limit the number of allowed connectionsDISA STIG VMware vSphere 7.0 Perfcharts Tomcat v1r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCPF-70-000030 - Rsyslog must be configured to monitor and ship Performance Charts log files.DISA STIG VMware vSphere 7.0 Perfcharts Tomcat v1r1Unix

AUDIT AND ACCOUNTABILITY

VCPF-70-000031 - Performance Charts must be configured with the appropriate ports.DISA STIG VMware vSphere 7.0 Perfcharts Tomcat v1r1Unix

CONFIGURATION MANAGEMENT

VCST-70-000007 - Security Token Service log files must only be modifiable by privileged users.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

AUDIT AND ACCOUNTABILITY

VCST-70-000019 - The Security Token Service must limit the number of allowed connections.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCST-70-000025 - The Security Token Service must not enable support for TRACE requests.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

VCST-70-000050 - Security Token Service log data and records must be backed up onto a different system or media.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

AUDIT AND ACCOUNTABILITY

VCUI-70-000005 - vSphere UI must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCUI-70-000007 - vSphere UI log files must only be accessible by privileged users.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

AUDIT AND ACCOUNTABILITY

VCUI-70-000009 - vSphere UI plugins must be authorized before use.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

CONFIGURATION MANAGEMENT

VMCH-70-000002 - Drag and drop operations must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000004 - Virtual disk shrinking must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000005 - Virtual disk wiping must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000013 - Console connection sharing must be limited on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000018 - Shared salt values must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000025 - Logging must be enabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT