SV-256363r885700_rule
V-256363
SRG-APP-000516
VCSA-70-000283
CAT III
10
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.
Next to "Authentication method", click "Edit".
Select the radio button to "Enable smart card authentication".
Click "Save".
To reenable password authentication for troubleshooting purposes, run the following command on the vCenter Server Appliance:
# /opt/vmware/bin/sso-config.sh -set_authn_policy -pwdAuthn true -winAuthn false -certAuthn false -securIDAuthn false -t vsphere.local
If a federated identity provider is configured and used for an identity source, this is not applicable.
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.
Under "Authentication method", examine the allowed methods.
If "Smart card authentication" is not enabled and "Password and windows session authentication" is not disabled , this is a finding.
V-256363
False
VCSA-70-000283
If a federated identity provider is configured and used for an identity source, this is not applicable.
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider >> Smart Card Authentication.
Under "Authentication method", examine the allowed methods.
If "Smart card authentication" is not enabled and "Password and windows session authentication" is not disabled , this is a finding.
M
5517