SV-256368r885715_rule
V-256368
SRG-APP-000516
VCSA-70-000288
CAT II
10
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider.
Click the "Identity Sources" tab.
For each identity source of type "Active Directory over LDAP" where LDAPS is not configured, highlight the item and click "Edit".
Ensure the primary and secondary server URLs, if specified, are configured for "ldaps://".
At the bottom, click the "Browse" button, select the AD LDAP cert previously exported to the local computer, click "Open", and "Save" to complete modifications.
Note: With LDAPS, the server must be a specific domain controller and its specific certificate or the domain alias with a certificate that is valid for that URL.
If LDAP is not used as an identity provider, this is not applicable.
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider.
Click the "Identity Sources" tab.
For each identity source of type "Active Directory over LDAP", if the "Server URL" does not indicate "ldaps://", this is a finding.
V-256368
False
VCSA-70-000288
If LDAP is not used as an identity provider, this is not applicable.
From the vSphere Client, go to Administration >> Single Sign On >> Configuration >> Identity Provider.
Click the "Identity Sources" tab.
For each identity source of type "Active Directory over LDAP", if the "Server URL" does not indicate "ldaps://", this is a finding.
M
5517