STIGQter STIGQter: STIG Summary:

VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 30 Jan 2025

CheckedNameTitle
SV-256478r958368_ruleThe Photon operating system must audit all account creations.
SV-256479r958388_ruleThe Photon operating system must automatically lock an account when three unsuccessful logon attempts occur.
SV-256480r958390_ruleThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting Secure Shell (SSH) access.
SV-256481r958398_ruleThe Photon operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-256482r958402_ruleThe Photon operating system must set a session inactivity timeout of 15 minutes or less.
SV-256483r958406_ruleThe Photon operating system must have the sshd SyslogFacility set to "authpriv".
SV-256484r958406_ruleThe Photon operating system must have sshd authentication logging enabled.
SV-256485r958406_ruleThe Photon operating system must have the sshd LogLevel set to "INFO".
SV-256486r958408_ruleThe Photon operating system must configure sshd to use approved encryption algorithms.
SV-256487r958412_ruleThe Photon operating system must configure auditd to log to disk.
SV-256488r958414_ruleThe Photon operating system must configure auditd to use the correct log format.
SV-256489r958422_ruleThe Photon operating system must be configured to audit the execution of privileged functions.
SV-256490r958422_ruleThe Photon operating system must have the auditd service running.
SV-256491r958424_ruleThe Photon operating system audit log must log space limit problems to syslog.
SV-256492r1038966_ruleThe Photon operating system audit log must attempt to log audit failures to syslog.
SV-256493r958434_ruleThe Photon operating system audit log must have correct permissions.
SV-256494r958436_ruleThe Photon operating system audit log must be owned by root.
SV-256495r958438_ruleThe Photon operating system audit log must be group-owned by root.
SV-256496r958444_ruleThe Photon operating system must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-256497r958446_ruleThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-256498r982195_ruleThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
SV-256499r982196_ruleThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.
SV-256500r982197_ruleThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.
SV-256501r982198_ruleThe Photon operating system must require that new passwords are at least four characters different from the old password.
SV-256502r982199_ruleThe Photon operating system must store only encrypted representations of passwords.
SV-256503r987796_ruleThe Photon operating system must use an OpenSSH server version that does not support protocol 1.
SV-256504r982188_ruleThe Photon operating system must be configured so that passwords for new users are restricted to a 24-hour minimum lifetime.
SV-256505r1038967_ruleThe Photon operating system must be configured so that passwords for new users are restricted to a 90-day maximum lifetime.
SV-256506r982201_ruleThe Photon operating system must prohibit password reuse for a minimum of five generations.
SV-256507r982202_ruleThe Photon operating system must enforce a minimum eight-character password length.
SV-256508r958472_ruleThe Photon operating system must require authentication upon booting into single-user and maintenance modes.
SV-256509r958480_ruleThe Photon operating system must disable the loading of unnecessary kernel modules.
SV-256510r958482_ruleThe Photon operating system must not have duplicate User IDs (UIDs).
SV-256511r982189_ruleThe Photon operating system must disable new accounts immediately upon password expiration.
SV-256512r958528_ruleThe Photon operating system must use Transmission Control Protocol (TCP) syncookies.
SV-256513r970703_ruleThe Photon operating system must configure sshd to disconnect idle Secure Shell (SSH) sessions.
SV-256514r970703_ruleThe Photon operating system must configure sshd to disconnect idle Secure Shell (SSH) sessions.
SV-256515r958566_ruleThe Photon operating system "/var/log" directory must be owned by root.
SV-256516r958566_ruleThe Photon operating system messages file must have the correct ownership and file permissions.
SV-256517r991551_ruleThe Photon operating system must audit all account modifications.
SV-256518r991551_ruleThe Photon operating system must audit all account modifications.
SV-256519r991552_ruleThe Photon operating system must audit all account disabling actions.
SV-256520r991553_ruleThe Photon operating system must audit all account removal actions.
SV-256521r991555_ruleThe Photon operating system must initiate auditing as part of the boot process.
SV-256522r991557_ruleThe Photon operating system audit files and directories must have correct permissions.
SV-256523r991558_ruleThe Photon operating system must protect audit tools from unauthorized modification and deletion.
SV-256524r991561_ruleThe Photon operating system must enforce password complexity by requiring that at least one special character be used.
SV-256525r991567_ruleThe Photon operating system package files must not be modified.
SV-256526r958732_ruleThe Photon operating system must audit the execution of privileged functions.
SV-256527r958752_ruleThe Photon operating system must configure auditd to keep five rotated log files.
SV-256528r958752_ruleThe Photon operating system must configure auditd to keep logging in the event max log file size is reached.
SV-256529r971542_ruleThe Photon operating system must configure auditd to log space limit problems to syslog.
SV-256530r982212_ruleThe Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
SV-256531r982212_ruleThe Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
SV-256532r982212_ruleThe  Photon operating system YUM repository must cryptographically verify the authenticity of all software packages during installation.
SV-256533r1050789_ruleThe Photon operating system must require users to reauthenticate for privilege escalation.
SV-256534r958850_ruleThe Photon operating system must configure sshd to use FIPS 140-2 ciphers.
SV-256535r958928_ruleThe Photon operating system must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
SV-256536r958936_ruleThe Photon operating system must remove all software components after updated versions have been installed.
SV-256537r991570_ruleThe Photon operating system must generate audit records when the sudo command is used.
SV-256538r991578_ruleThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.
SV-256539r991580_ruleThe Photon operating system must audit the "insmod" module.
SV-256540r991585_ruleThe Photon operating system auditd service must generate audit records for all account creations, modifications, disabling, and termination events.
SV-256541r991587_ruleThe Photon operating system must use the "pam_cracklib" module.
SV-256542r991588_ruleThe Photon operating system must set the "FAIL_DELAY" parameter.
SV-256543r991588_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-256544r991589_ruleThe Photon operating system must ensure audit events are flushed to disk at proper intervals.
SV-256545r991589_ruleThe Photon operating system must create a home directory for all new local interactive user accounts.
SV-256546r991589_ruleThe Photon operating system must disable the debug-shell service.
SV-256547r991589_ruleThe Photon operating system must configure sshd to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.
SV-256548r1051424_ruleThe Photon operating system must configure sshd to disable environment processing.
SV-256549r991589_ruleThe Photon operating system must configure sshd to disable X11 forwarding.
SV-256550r991589_ruleThe Photon operating system must configure sshd to perform strict mode checking of home directory configuration files.
SV-256551r991589_ruleThe Photon operating system must configure sshd to disallow Kerberos authentication.
SV-256552r991589_ruleThe Photon operating system must configure sshd to disallow authentication with an empty password.
SV-256553r991589_ruleThe Photon operating system must configure sshd to disallow compression of the encrypted session stream.
SV-256554r991589_ruleThe Photon operating system must configure sshd to display the last login immediately after authentication.
SV-256555r991589_ruleThe Photon operating system must configure sshd to ignore user-specific trusted hosts lists.
SV-256556r991589_ruleThe Photon operating system must configure sshd to ignore user-specific "known_host" files.
SV-256557r991589_ruleThe Photon operating system must configure sshd to limit the number of allowed login attempts per connection.
SV-256558r991589_ruleThe Photon operating system must be configured so the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.
SV-256559r991589_ruleThe Photon operating system must be configured so the "/etc/skel" default scripts are protected from unauthorized modification.
SV-256560r991589_ruleThe Photon operating system must be configured so the "/root" path is protected from unauthorized access.
SV-256561r991589_ruleThe Photon operating system must be configured so that all global initialization scripts are protected from unauthorized modification.
SV-256562r991589_ruleThe Photon operating system must be configured so that all system startup scripts are protected from unauthorized modification.
SV-256563r991589_ruleThe Photon operating system must be configured so that all files have a valid owner and group owner.
SV-256564r991589_ruleThe Photon operating system must be configured so the "/etc/cron.allow" file is protected from unauthorized modification.
SV-256565r991589_ruleThe Photon operating system must be configured so that all cron jobs are protected from unauthorized modification.
SV-256566r991589_ruleThe Photon operating system must be configured so that all cron paths are protected from unauthorized modification.
SV-256567r991589_ruleThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.
SV-256568r991589_ruleThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-256569r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-256570r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.
SV-256571r991589_ruleThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.
SV-256572r991589_ruleThe Photon operating system must log IPv4 packets with impossible addresses.
SV-256573r991589_ruleThe Photon operating system must use a reverse-path filter for IPv4 network traffic.
SV-256574r991589_ruleThe Photon operating system must not perform multicast packet forwarding.
SV-256575r991589_ruleThe Photon operating system must not perform IPv4 packet forwarding.
SV-256576r991589_ruleThe Photon operating system must send Transmission Control Protocol (TCP) timestamps.
SV-256577r991589_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.
SV-256578r991589_ruleThe Photon operating system must be configured to protect the Secure Shell ( SSH) private host key from unauthorized access.
SV-256579r991589_ruleThe Photon operating system must enforce password complexity on the root account.
SV-256580r991589_ruleThe Photon operating system must protect all boot configuration files from unauthorized modification.
SV-256581r991589_ruleThe Photon operating system must protect sshd configuration from unauthorized access.
SV-256582r991589_ruleThe Photon operating system must protect all "sysctl" configuration files from unauthorized access.
SV-256583r991590_ruleThe Photon operating system must set the "umask" parameter correctly.
SV-256584r991591_ruleThe Photon operating system must configure sshd to disallow HostbasedAuthentication.
SV-256585r982199_ruleThe Photon operating system must store only encrypted representations of passwords.
SV-256586r982201_ruleThe Photon operating system must ensure the old passwords are being stored.
SV-256587r991589_ruleThe Photon operating system must configure sshd to restrict AllowTcpForwarding.
SV-256588r991589_ruleThe Photon operating system must configure sshd to restrict LoginGraceTime.
SV-256589r959006_ruleThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, generate cryptographic hashes, and protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-256590r991589_ruleThe Photon operating system must disable systemd fallback Domain Name System (DNS).