SV-258798r959010_rule
V-258798
SRG-OS-000480-VMM-002000
ESXI-80-000244
CAT II
10
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> System >> Advanced System Settings.
Click "Edit". Select the "VMkernel.Boot.execInstalledOnly" value and configure it to "true".
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name VMkernel.Boot.execInstalledOnly | Set-AdvancedSetting -Value True
If the ESXi host does not have a compatible TPM, this finding is downgraded to a CAT III.
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> System >> Advanced System Settings.
Select the "VMkernel.Boot.execInstalledOnly" value and verify that it is "true".
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name VMkernel.Boot.execInstalledOnly
If the "VMkernel.Boot.execInstalledOnly" setting is not "true", this is a finding.
V-258798
False
ESXI-80-000244
If the ESXi host does not have a compatible TPM, this finding is downgraded to a CAT III.
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> System >> Advanced System Settings.
Select the "VMkernel.Boot.execInstalledOnly" value and verify that it is "true".
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name VMkernel.Boot.execInstalledOnly
If the "VMkernel.Boot.execInstalledOnly" setting is not "true", this is a finding.
M
5562