STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 ESXi Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The ESXi host must use DOD-approved certificates.

DISA Rule

SV-258784r1212385_rule

Vulnerability Number

V-258784

Group Title

SRG-OS-000480-VMM-002000

Rule Version

ESXI-80-000229

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Join the ESXi host to vCenter before replacing the certificate.

Obtain a DOD-issued certificate and private key for the host following the requirements below:

Key size: 2048 bits or more (PEM encoded)

Key format: PEM
VMware supports PKCS8 and PKCS1 (RSA keys)
x509 version 3

SubjectAltName must contain DNS Name=<machine_FQDN>

CRT (Base-64) format

Contains the following Key Usages: Digital Signature, Non Repudiation, Key Encipherment

Start time of one day before the current time

CN (and SubjectAltName) set to the host name (or IP address) that the ESXi host has in the vCenter Server inventory

From the vSphere Web Client, select the ESXi host's vCenter Server >> Configure >> System >> Advanced Settings.

Select the "vpxd.certmgmt.mode" value and ensure it is set to "custom".

Put the host into maintenance mode.

Temporarily enable Secure Shell (SSH) on the host. Use Secure Copy Protocol (SCP) to transfer the new certificate and key to /tmp. SSH to the host. Back up the existing certificate and key:

# mv /etc/vmware/ssl/rui.crt /etc/vmware/ssl/rui.crt.bak
# mv /etc/vmware/ssl/rui.key /etc/vmware/ssl/rui.key.bak

Copy the new certificate and key to "/etc/vmware/ssl/" and rename them to "rui.crt" and "rui.key" respectively.

Restart management agents to implement the new certificate:

# services.sh restart

Check Contents

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Certificate.

If the issuer is not a DOD-approved certificate authority, or other AO-approved certificate authority, this is a finding.

If the host will never be accessed directly (virtual machine console connections bypass vCenter), this is not a finding.

Vulnerability Number

V-258784

Documentable

False

Rule Version

ESXI-80-000229

Severity Override Guidance

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Certificate.

If the issuer is not a DOD-approved certificate authority, or other AO-approved certificate authority, this is a finding.

If the host will never be accessed directly (virtual machine console connections bypass vCenter), this is not a finding.

Check Content Reference

M

Target Key

5562