SV-256344r885643_rule
V-256344
SRG-APP-000575
VCSA-70-000253
CAT II
10
At the command prompt on the vCenter Server Appliance, run the following commands:
# appliancesh
# snmp.set --authentication SHA1
# snmp.set --privacy AES128
To change the security level of a user, run the following command:
# snmp.set --users <username>/<auth_password> <priv_password>/priv
At the command prompt on the vCenter Server Appliance, run the following commands:
# appliancesh
# snmp.get
Note: The "appliancesh" command is not needed if the default shell has not been changed for root.
If "Enable" is set to "False", this is not a finding.
If "Enable" is set to "True" and "Authentication" is not set to "SHA1", this is a finding.
If "Enable" is set to "True" and "Privacy" is not set to "AES128", this is a finding.
If any "Users" are configured with a "Sec_level" that does not equal "priv", this is a finding.
V-256344
False
VCSA-70-000253
At the command prompt on the vCenter Server Appliance, run the following commands:
# appliancesh
# snmp.get
Note: The "appliancesh" command is not needed if the default shell has not been changed for root.
If "Enable" is set to "False", this is not a finding.
If "Enable" is set to "True" and "Authentication" is not set to "SHA1", this is a finding.
If "Enable" is set to "True" and "Privacy" is not set to "AES128", this is a finding.
If any "Users" are configured with a "Sec_level" that does not equal "priv", this is a finding.
M
5517