STIGQter STIGQter: STIG Summary:

VMware vSphere 7.0 vCenter Appliance STS Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 26 Jul 2023

CheckedNameTitle
☐SV-256745r889205_ruleThe Security Token Service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
☐SV-256746r889208_ruleThe Security Token Service must limit the number of concurrent connections permitted.
☐SV-256747r889211_ruleThe Security Token Service must limit the maximum size of a POST request.
☐SV-256748r889214_ruleThe Security Token Service must protect cookies from cross-site scripting (XSS).
☐SV-256749r889217_ruleThe Security Token Service must record user access in a format that enables monitoring of remote access.
☐SV-256750r918974_ruleThe Security Token Service must generate log records during Java startup and shutdown.
☐SV-256751r889223_ruleSecurity Token Service log files must only be modifiable by privileged users.
☐SV-256752r889226_ruleThe Security Token Service application files must be verified for their integrity.
☐SV-256753r889229_ruleThe Security Token Service must only run one webapp.
☐SV-256754r889232_ruleThe Security Token Service must not be configured with unused realms.
☐SV-256755r889235_ruleThe Security Token Service must be configured to limit access to internal packages.
☐SV-256756r889238_ruleThe Security Token Service must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled.
☐SV-256757r889241_ruleThe Security Token Service must have mappings set for Java servlet pages.
☐SV-256758r889244_ruleThe Security Token Service must not have the Web Distributed Authoring (WebDAV) servlet installed.
☐SV-256759r889247_ruleThe Security Token Service must be configured with memory leak protection.
☐SV-256760r889250_ruleThe Security Token Service must not have any symbolic links in the web content directory tree.
☐SV-256761r889253_ruleThe Security Token Service directory tree must have permissions in an out-of-the-box state.
☐SV-256762r889256_ruleThe Security Token Service must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail.
☐SV-256763r889259_ruleThe Security Token Service must limit the number of allowed connections.
☐SV-256764r889262_ruleThe Security Token Service must set "URIEncoding" to UTF-8.
☐SV-256765r889265_ruleThe Security Token Service must use the "setCharacterEncodingFilter" filter.
☐SV-256766r889268_ruleThe Security Token Service must set the welcome-file node to a default web page.
☐SV-256767r889271_ruleThe Security Token Service must not show directory listings.
☐SV-256768r889274_ruleThe Security Token Service must be configured to not show error reports.
☐SV-256769r889277_ruleThe Security Token Service must not enable support for TRACE requests.
☐SV-256770r918976_ruleThe Security Token Service must have the debug option disabled.
☐SV-256771r918979_ruleThe Security Token Service must be configured with the appropriate ports.
☐SV-256772r889286_ruleThe Security Token Service must disable the shutdown port.
☐SV-256773r889289_ruleThe Security Token Service must set the secure flag for cookies.
☐SV-256774r889292_ruleThe Security Token Service default servlet must be set to "readonly".
☐SV-256775r889295_ruleSecurity Token Service log data and records must be backed up onto a different system or media.