STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 vCenter Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2024:

The vCenter Server Machine Secure Sockets Layer (SSL) certificate must be issued by a DOD certificate authority.

DISA Rule

SV-256342r885637_rule

Vulnerability Number

V-256342

Group Title

SRG-APP-000427

Rule Version

VCSA-70-000195

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Obtain a DOD-issued certificate and private key for each vCenter in the system following the requirements below:

Key size: 2048 bits or more (PEM encoded)
CRT format (Base-64)
x509 version 3
SubjectAltName must contain DNS Name=<machine_FQDN>
Contains the following Key Usages: Digital Signature, Non Repudiation, Key Encipherment

Export the entire certificate issuing chain up to the root in Base-64 format. Concatenate the individual certificates into one file with the ".cer" extension.

From the vSphere Client, go to Administration >> Certificates >> Certificate Management >> Machine SSL Certificate.

Click Actions >> Import and Replace Certificate.

Select the "Replace with external CA certificate" radio button and click "Next".

Supply the CA-issued certificate , the exported roots file, and the private key.

Click "Replace".

Check Contents

From the vSphere Client, go to Administration >> Certificates >> Certificate Management >> Machine SSL Certificate.

Click "View Details" and examine the "Issuer Information" block.

If the issuer specified is not a DOD-approved certificate authority, this is a finding.

Vulnerability Number

V-256342

Documentable

False

Rule Version

VCSA-70-000195

Severity Override Guidance

From the vSphere Client, go to Administration >> Certificates >> Certificate Management >> Machine SSL Certificate.

Click "View Details" and examine the "Issuer Information" block.

If the issuer specified is not a DOD-approved certificate authority, this is a finding.

Check Content Reference

M

Target Key

5517