SV-256342r885637_rule
V-256342
SRG-APP-000427
VCSA-70-000195
CAT II
10
Obtain a DOD-issued certificate and private key for each vCenter in the system following the requirements below:
Key size: 2048 bits or more (PEM encoded)
CRT format (Base-64)
x509 version 3
SubjectAltName must contain DNS Name=<machine_FQDN>
Contains the following Key Usages: Digital Signature, Non Repudiation, Key Encipherment
Export the entire certificate issuing chain up to the root in Base-64 format. Concatenate the individual certificates into one file with the ".cer" extension.
From the vSphere Client, go to Administration >> Certificates >> Certificate Management >> Machine SSL Certificate.
Click Actions >> Import and Replace Certificate.
Select the "Replace with external CA certificate" radio button and click "Next".
Supply the CA-issued certificate , the exported roots file, and the private key.
Click "Replace".
From the vSphere Client, go to Administration >> Certificates >> Certificate Management >> Machine SSL Certificate.
Click "View Details" and examine the "Issuer Information" block.
If the issuer specified is not a DOD-approved certificate authority, this is a finding.
V-256342
False
VCSA-70-000195
From the vSphere Client, go to Administration >> Certificates >> Certificate Management >> Machine SSL Certificate.
Click "View Details" and examine the "Issuer Information" block.
If the issuer specified is not a DOD-approved certificate authority, this is a finding.
M
5517