STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

The Photon operating system must use cryptographic mechanisms to protect the integrity of audit tools.

DISA Rule

SV-258839r991567_rule

Vulnerability Number

V-258839

Group Title

SRG-OS-000278-GPOS-00108

Rule Version

PHTN-40-000092

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

If the audit system binaries have been altered investigate the cause and then reinstall the audit package to restore the integrity of the package.

If performed on a VMware reinstalling the audit tools is not supported. The appliance should be restored from a backup or redeployed once the root cause is remediated.

Check Contents

Use the verification capability of rpm to check the MD5 hashes of the audit files on disk versus the expected ones from the installation package.

At the command line, run the following command:

# rpm -V audit | grep "^..5"

Example output:

S.5....T. c /etc/audit/auditd.conf

If there is any output for files that are not configuration files, this is a finding.

Vulnerability Number

V-258839

Documentable

False

Rule Version

PHTN-40-000092

Severity Override Guidance

Use the verification capability of rpm to check the MD5 hashes of the audit files on disk versus the expected ones from the installation package.

At the command line, run the following command:

# rpm -V audit | grep "^..5"

Example output:

S.5....T. c /etc/audit/auditd.conf

If there is any output for files that are not configuration files, this is a finding.

Check Content Reference

M

Target Key

5569