STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 31 Oct 2023:

The vCenter server must require authentication for published content libraries.

DISA Rule

SV-258961r934541_rule

Vulnerability Number

V-258961

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000295

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Content Libraries.

Select the target content library.

Select "Actions" then "Edit Settings".

Click the checkbox to "Enable user authentication for access to this content library".

Enter and confirm a password for the content library. Click "OK".

Note: Any subscribed content libraries will need to be updated to enable authentication and provide the password.

Check Contents

From the vSphere Client, go to Content Libraries.

Review the "Password Protected" column.

If a content library is published and is not password protected, this is a finding.

Vulnerability Number

V-258961

Documentable

False

Rule Version

VCSA-80-000295

Severity Override Guidance

From the vSphere Client, go to Content Libraries.

Review the "Password Protected" column.

If a content library is published and is not password protected, this is a finding.

Check Content Reference

M

Target Key

5573