SV-256438r959010_rule
V-256438
SRG-OS-000480-VMM-002000
ESXI-70-000086
CAT II
10
To configure SSL syslog endpoint certificate checking it must be turned on and also the trusted certificate chain must be added to ESXi's trusted store.
From the vSphere Client go to Hosts and Clusters.
Select the ESXi Host >> Configure >> System >> Advanced System Settings.
Select the "Syslog.global.logCheckSSLCerts" value and set it to "true".
Copy the PEM formatted trusted CA certificate so that is accessible to the host and append the contents to /etc/vmware/ssl/castore.pem by running the follow command:
# <path/to/cacert> >> /etc/vmware/ssl/castore.pem
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name Syslog.global.logCheckSSLCerts | Set-AdvancedSetting -Value "true"
Copy the PEM formatted trusted CA certificate so that is accessible to the host.
$esxcli = Get-EsxCli -v2
$arguments = $esxcli.system.security.certificatestore.add.CreateArgs()
$arguments.filename = <path/to/cacert>
$esxcli.system.security.certificatestore.add.Invoke($arguments)
If SSL is not used for a syslog target, this is not applicable.
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> System >> Advanced System Settings.
Select the "Syslog.global.logCheckSSLCerts" value and verify it is set to "true".
or
From a PowerCLI command prompt while connected to the ESXi host run the following command:
Get-VMHost | Get-AdvancedSetting -Name Syslog.global.logCheckSSLCerts
If the "Syslog.global.logCheckSSLCerts" setting is not set to "true", this is a finding.
V-256438
False
ESXI-70-000086
If SSL is not used for a syslog target, this is not applicable.
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> System >> Advanced System Settings.
Select the "Syslog.global.logCheckSSLCerts" value and verify it is set to "true".
or
From a PowerCLI command prompt while connected to the ESXi host run the following command:
Get-VMHost | Get-AdvancedSetting -Name Syslog.global.logCheckSSLCerts
If the "Syslog.global.logCheckSSLCerts" setting is not set to "true", this is a finding.
M
5518