STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 vCenter Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2024:

The vCenter Server must disable Username/Password and Windows Integrated Authentication.

DISA Rule

SV-256363r885700_rule

Vulnerability Number

V-256363

Group Title

SRG-APP-000516

Rule Version

VCSA-70-000283

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Next to "Authentication method", click "Edit".

Select the radio button to "Enable smart card authentication".

Click "Save".

To reenable password authentication for troubleshooting purposes, run the following command on the vCenter Server Appliance:

# /opt/vmware/bin/sso-config.sh -set_authn_policy -pwdAuthn true -winAuthn false -certAuthn false -securIDAuthn false -t vsphere.local

Check Contents

If a federated identity provider is configured and used for an identity source, this is not applicable.

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Under "Authentication method", examine the allowed methods.

If "Smart card authentication" is not enabled and "Password and windows session authentication" is not disabled , this is a finding.

Vulnerability Number

V-256363

Documentable

False

Rule Version

VCSA-70-000283

Severity Override Guidance

If a federated identity provider is configured and used for an identity source, this is not applicable.

From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.

Under "Authentication method", examine the allowed methods.

If "Smart card authentication" is not enabled and "Password and windows session authentication" is not disabled , this is a finding.

Check Content Reference

M

Target Key

5517