The vCenter Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
DISA Rule
SV-256318r919041_rule
Vulnerability Number
V-256318
Group Title
SRG-APP-000014
Rule Version
VCSA-70-000009
Severity
CAT I
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-000382 - Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services.
- CCI-001184 - Protect the authenticity of communications sessions.
- CCI-001453 - Implement cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002421 - Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission.
- CCI-002422 - Maintain the confidentiality and/or integrity of information during reception.
- CCI-002450 - Implement organization-defined types of cryptography for each specified cryptography use.
Weight
10
Fix Recommendation
At the command prompt on the vCenter Server Appliance, run the following commands:
# /usr/lib/vmware-TlsReconfigurator/VcTlsReconfigurator/reconfigureVc backup
# /usr/lib/vmware-TlsReconfigurator/VcTlsReconfigurator/reconfigureVc update -p TLSv1.2
vCenter services will be restarted as part of the reconfiguration. The operating system will not be restarted.
The "--no-restart" flag can be added to restart services at a later time.
Changes will not take effect until all services are restarted or the appliance is rebooted.
Note: This change should be performed on vCenter prior to ESXi.
Check Contents
At the command prompt on the vCenter Server Appliance, run the following command:
# /usr/lib/vmware-TlsReconfigurator/VcTlsReconfigurator/reconfigureVc scan
If the output indicates versions of TLS other than 1.2 are enabled, this is a finding.
Vulnerability Number
V-256318
Documentable
False
Rule Version
VCSA-70-000009
Severity Override Guidance
At the command prompt on the vCenter Server Appliance, run the following command:
# /usr/lib/vmware-TlsReconfigurator/VcTlsReconfigurator/reconfigureVc scan
If the output indicates versions of TLS other than 1.2 are enabled, this is a finding.
Check Content Reference
M
Target Key
5517