STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Jul 2026:

The Photon operating system must be configured to use the pam_deny.so module.

DISA Rule

SV-285222r1210426_rule

Vulnerability Number

V-285222

Group Title

SRG-OS-000480-GPOS-00228

Rule Version

PHTN-40-000267

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to and open:

/etc/sysctl.d/zz-stig-hardening.conf

Add or update the following line:

fs.suid_dumpable = 0

Note: "0" is recommended for normal operation. If core dumps need to be captured for troubleshooting purposes, then "2" is also an acceptable value.

At the command line, run the following command to load the new configuration:

# /sbin/sysctl --load /etc/sysctl.d/zz-stig-hardening.conf

Note: If the file zz-stig-hardening.conf does not exist, it must be created.

Check Contents

At the command line, run the following commands to verify the pam_deny.so module is used:

# grep '^auth' /etc/pam.d/system-auth

Example result:

auth required pam_faillock.so preauth
auth sufficient pam_unix.so
auth required pam_faillock.so authfail
auth optional pam_faildelay.so delay=4000000
auth required pam_deny.so

If the pam_deny.so module is not present, or is not configured as the last auth entry, this is a finding.

Vulnerability Number

V-285222

Documentable

False

Rule Version

PHTN-40-000267

Severity Override Guidance

At the command line, run the following commands to verify the pam_deny.so module is used:

# grep '^auth' /etc/pam.d/system-auth

Example result:

auth required pam_faillock.so preauth
auth sufficient pam_unix.so
auth required pam_faillock.so authfail
auth optional pam_faildelay.so delay=4000000
auth required pam_deny.so

If the pam_deny.so module is not present, or is not configured as the last auth entry, this is a finding.

Check Content Reference

M

Target Key

5569