STIGQter STIGQter: STIG Summary:

VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 30 Jan 2025

CheckedNameTitle
☐SV-256478r958368_ruleThe Photon operating system must audit all account creations.
☐SV-256479r958388_ruleThe Photon operating system must automatically lock an account when three unsuccessful logon attempts occur.
☐SV-256480r958390_ruleThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting Secure Shell (SSH) access.
☐SV-256481r958398_ruleThe Photon operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
☐SV-256482r958402_ruleThe Photon operating system must set a session inactivity timeout of 15 minutes or less.
☐SV-256483r958406_ruleThe Photon operating system must have the sshd SyslogFacility set to "authpriv".
☐SV-256484r958406_ruleThe Photon operating system must have sshd authentication logging enabled.
☐SV-256485r958406_ruleThe Photon operating system must have the sshd LogLevel set to "INFO".
☐SV-256486r958408_ruleThe Photon operating system must configure sshd to use approved encryption algorithms.
☐SV-256487r958412_ruleThe Photon operating system must configure auditd to log to disk.
☐SV-256488r958414_ruleThe Photon operating system must configure auditd to use the correct log format.
☐SV-256489r958422_ruleThe Photon operating system must be configured to audit the execution of privileged functions.
☐SV-256490r958422_ruleThe Photon operating system must have the auditd service running.
☐SV-256491r958424_ruleThe Photon operating system audit log must log space limit problems to syslog.
☐SV-256492r1038966_ruleThe Photon operating system audit log must attempt to log audit failures to syslog.
☐SV-256493r958434_ruleThe Photon operating system audit log must have correct permissions.
☐SV-256494r958436_ruleThe Photon operating system audit log must be owned by root.
☐SV-256495r958438_ruleThe Photon operating system audit log must be group-owned by root.
☐SV-256496r958444_ruleThe Photon operating system must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
☐SV-256497r958446_ruleThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
☐SV-256498r982195_ruleThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
☐SV-256499r982196_ruleThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.
☐SV-256500r982197_ruleThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.
☐SV-256501r982198_ruleThe Photon operating system must require that new passwords are at least four characters different from the old password.
☐SV-256502r982199_ruleThe Photon operating system must store only encrypted representations of passwords.
☐SV-256503r987796_ruleThe Photon operating system must use an OpenSSH server version that does not support protocol 1.
☐SV-256504r982188_ruleThe Photon operating system must be configured so that passwords for new users are restricted to a 24-hour minimum lifetime.
☐SV-256505r1038967_ruleThe Photon operating system must be configured so that passwords for new users are restricted to a 90-day maximum lifetime.
☐SV-256506r982201_ruleThe Photon operating system must prohibit password reuse for a minimum of five generations.
☐SV-256507r982202_ruleThe Photon operating system must enforce a minimum eight-character password length.
☐SV-256508r958472_ruleThe Photon operating system must require authentication upon booting into single-user and maintenance modes.
☐SV-256509r958480_ruleThe Photon operating system must disable the loading of unnecessary kernel modules.
☐SV-256510r958482_ruleThe Photon operating system must not have duplicate User IDs (UIDs).
☐SV-256511r982189_ruleThe Photon operating system must disable new accounts immediately upon password expiration.
☐SV-256512r958528_ruleThe Photon operating system must use Transmission Control Protocol (TCP) syncookies.
☐SV-256513r970703_ruleThe Photon operating system must configure sshd to disconnect idle Secure Shell (SSH) sessions.
☐SV-256514r970703_ruleThe Photon operating system must configure sshd to disconnect idle Secure Shell (SSH) sessions.
☐SV-256515r958566_ruleThe Photon operating system "/var/log" directory must be owned by root.
☐SV-256516r958566_ruleThe Photon operating system messages file must have the correct ownership and file permissions.
☐SV-256517r991551_ruleThe Photon operating system must audit all account modifications.
☐SV-256518r991551_ruleThe Photon operating system must audit all account modifications.
☐SV-256519r991552_ruleThe Photon operating system must audit all account disabling actions.
☐SV-256520r991553_ruleThe Photon operating system must audit all account removal actions.
☐SV-256521r991555_ruleThe Photon operating system must initiate auditing as part of the boot process.
☐SV-256522r991557_ruleThe Photon operating system audit files and directories must have correct permissions.
☐SV-256523r991558_ruleThe Photon operating system must protect audit tools from unauthorized modification and deletion.
☐SV-256524r991561_ruleThe Photon operating system must enforce password complexity by requiring that at least one special character be used.
☐SV-256525r991567_ruleThe Photon operating system package files must not be modified.
☐SV-256526r958732_ruleThe Photon operating system must audit the execution of privileged functions.
☐SV-256527r958752_ruleThe Photon operating system must configure auditd to keep five rotated log files.
☐SV-256528r958752_ruleThe Photon operating system must configure auditd to keep logging in the event max log file size is reached.
☐SV-256529r971542_ruleThe Photon operating system must configure auditd to log space limit problems to syslog.
☐SV-256530r982212_ruleThe Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
☐SV-256531r982212_ruleThe Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
☐SV-256532r982212_ruleThe  Photon operating system YUM repository must cryptographically verify the authenticity of all software packages during installation.
☐SV-256533r1050789_ruleThe Photon operating system must require users to reauthenticate for privilege escalation.
☐SV-256534r958850_ruleThe Photon operating system must configure sshd to use FIPS 140-2 ciphers.
☐SV-256535r958928_ruleThe Photon operating system must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
☐SV-256536r958936_ruleThe Photon operating system must remove all software components after updated versions have been installed.
☐SV-256537r991570_ruleThe Photon operating system must generate audit records when the sudo command is used.
☐SV-256538r991578_ruleThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.
☐SV-256539r991580_ruleThe Photon operating system must audit the "insmod" module.
☐SV-256540r991585_ruleThe Photon operating system auditd service must generate audit records for all account creations, modifications, disabling, and termination events.
☐SV-256541r991587_ruleThe Photon operating system must use the "pam_cracklib" module.
☐SV-256542r991588_ruleThe Photon operating system must set the "FAIL_DELAY" parameter.
☐SV-256543r991588_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
☐SV-256544r991589_ruleThe Photon operating system must ensure audit events are flushed to disk at proper intervals.
☐SV-256545r991589_ruleThe Photon operating system must create a home directory for all new local interactive user accounts.
☐SV-256546r991589_ruleThe Photon operating system must disable the debug-shell service.
☐SV-256547r991589_ruleThe Photon operating system must configure sshd to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.
☐SV-256548r1051424_ruleThe Photon operating system must configure sshd to disable environment processing.
☐SV-256549r991589_ruleThe Photon operating system must configure sshd to disable X11 forwarding.
☐SV-256550r991589_ruleThe Photon operating system must configure sshd to perform strict mode checking of home directory configuration files.
☐SV-256551r991589_ruleThe Photon operating system must configure sshd to disallow Kerberos authentication.
☐SV-256552r991589_ruleThe Photon operating system must configure sshd to disallow authentication with an empty password.
☐SV-256553r991589_ruleThe Photon operating system must configure sshd to disallow compression of the encrypted session stream.
☐SV-256554r991589_ruleThe Photon operating system must configure sshd to display the last login immediately after authentication.
☐SV-256555r991589_ruleThe Photon operating system must configure sshd to ignore user-specific trusted hosts lists.
☐SV-256556r991589_ruleThe Photon operating system must configure sshd to ignore user-specific "known_host" files.
☐SV-256557r991589_ruleThe Photon operating system must configure sshd to limit the number of allowed login attempts per connection.
☐SV-256558r991589_ruleThe Photon operating system must be configured so the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.
☐SV-256559r991589_ruleThe Photon operating system must be configured so the "/etc/skel" default scripts are protected from unauthorized modification.
☐SV-256560r991589_ruleThe Photon operating system must be configured so the "/root" path is protected from unauthorized access.
☐SV-256561r991589_ruleThe Photon operating system must be configured so that all global initialization scripts are protected from unauthorized modification.
☐SV-256562r991589_ruleThe Photon operating system must be configured so that all system startup scripts are protected from unauthorized modification.
☐SV-256563r991589_ruleThe Photon operating system must be configured so that all files have a valid owner and group owner.
☐SV-256564r991589_ruleThe Photon operating system must be configured so the "/etc/cron.allow" file is protected from unauthorized modification.
☐SV-256565r991589_ruleThe Photon operating system must be configured so that all cron jobs are protected from unauthorized modification.
☐SV-256566r991589_ruleThe Photon operating system must be configured so that all cron paths are protected from unauthorized modification.
☐SV-256567r991589_ruleThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.
☐SV-256568r991589_ruleThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
☐SV-256569r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
☐SV-256570r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.
☐SV-256571r991589_ruleThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.
☐SV-256572r991589_ruleThe Photon operating system must log IPv4 packets with impossible addresses.
☐SV-256573r991589_ruleThe Photon operating system must use a reverse-path filter for IPv4 network traffic.
☐SV-256574r991589_ruleThe Photon operating system must not perform multicast packet forwarding.
☐SV-256575r991589_ruleThe Photon operating system must not perform IPv4 packet forwarding.
☐SV-256576r991589_ruleThe Photon operating system must send Transmission Control Protocol (TCP) timestamps.
☐SV-256577r991589_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.
☐SV-256578r991589_ruleThe Photon operating system must be configured to protect the Secure Shell ( SSH) private host key from unauthorized access.
☐SV-256579r991589_ruleThe Photon operating system must enforce password complexity on the root account.
☐SV-256580r991589_ruleThe Photon operating system must protect all boot configuration files from unauthorized modification.
☐SV-256581r991589_ruleThe Photon operating system must protect sshd configuration from unauthorized access.
☐SV-256582r991589_ruleThe Photon operating system must protect all "sysctl" configuration files from unauthorized access.
☐SV-256583r991590_ruleThe Photon operating system must set the "umask" parameter correctly.
☐SV-256584r991591_ruleThe Photon operating system must configure sshd to disallow HostbasedAuthentication.
☐SV-256585r982199_ruleThe Photon operating system must store only encrypted representations of passwords.
☐SV-256586r982201_ruleThe Photon operating system must ensure the old passwords are being stored.
☐SV-256587r991589_ruleThe Photon operating system must configure sshd to restrict AllowTcpForwarding.
☐SV-256588r991589_ruleThe Photon operating system must configure sshd to restrict LoginGraceTime.
☐SV-256589r959006_ruleThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, generate cryptographic hashes, and protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
☐SV-256590r991589_ruleThe Photon operating system must disable systemd fallback Domain Name System (DNS).