STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 ESXi Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 31 Oct 2023:

The ESXi host must enable Secure Boot.

DISA Rule

SV-258741r933284_rule

Vulnerability Number

V-258741

Group Title

SRG-OS-000278-VMM-001000

Rule Version

ESXI-80-000094

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From an ESXi shell, run the following command:

# /usr/lib/vmware/secureboot/bin/secureBoot.py -c

If the output indicates that Secure Boot cannot be enabled, correct the discrepancies and try again.

Once all discrepancies are resolved, the server ESXi is installed on can be updated to enable Secure Boot in the firmware.

To enable Secure Boot in the server's firmware follow the instructions for the specific manufacturer.

Check Contents

From an ESXi shell, run the following command:

# /usr/lib/vmware/secureboot/bin/secureBoot.py -s

If Secure Boot is not "Enabled", this is a finding.

Vulnerability Number

V-258741

Documentable

False

Rule Version

ESXI-80-000094

Severity Override Guidance

From an ESXi shell, run the following command:

# /usr/lib/vmware/secureboot/bin/secureBoot.py -s

If Secure Boot is not "Enabled", this is a finding.

Check Content Reference

M

Target Key

5562