STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 vCenter Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2024:

The vCenter Server must enable revocation checking for certificate-based authentication.

DISA Rule

SV-256333r919043_rule

Vulnerability Number

V-256333

Group Title

SRG-APP-000175

Rule Version

VCSA-70-000080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Under Smart card authentication settings >> Certificate revocation, click the "Edit" button.

Configure revocation checking per site requirements. OCSP with CRL failover is recommended.

By default, both locations are pulled from the cert. CRL location can be overridden in this screen, and local responders can be specified via the sso-config command line tool. Refer to the supplemental document for more information.

Note: If FIPS mode is enabled on vCenter, OCSP revocation validation may not function and CRL used instead.

Check Contents

If a federated identity provider is configured and used for an identity source and supports Smartcard authentication, this is not applicable.

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Under Smart card authentication settings >> Certificate revocation, verify "Revocation check" does not show as disabled.

If "Revocation check" shows as disabled, this is a finding.

Vulnerability Number

V-256333

Documentable

False

Rule Version

VCSA-70-000080

Severity Override Guidance

If a federated identity provider is configured and used for an identity source and supports Smartcard authentication, this is not applicable.

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Under Smart card authentication settings >> Certificate revocation, verify "Revocation check" does not show as disabled.

If "Revocation check" shows as disabled, this is a finding.

Check Content Reference

M

Target Key

5517