| Checked | Name | Title |
|---|---|---|
| ☐ | SV-256778r889333_rule | vSphere UI must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive. |
| ☐ | SV-256779r889336_rule | vSphere UI must limit the number of concurrent connections permitted. |
| ☐ | SV-256780r889339_rule | vSphere UI must limit the maximum size of a POST request. |
| ☐ | SV-256781r889342_rule | vSphere UI must protect cookies from cross-site scripting (XSS). |
| ☐ | SV-256782r889345_rule | vSphere UI must record user access in a format that enables monitoring of remote access. |
| ☐ | SV-256783r889348_rule | vSphere UI must generate log records for system startup and shutdown. |
| ☐ | SV-256784r889351_rule | vSphere UI log files must only be accessible by privileged users. |
| ☐ | SV-256785r918981_rule | vSphere UI application files must be verified for their integrity. |
| ☐ | SV-256786r889357_rule | vSphere UI plugins must be authorized before use. |
| ☐ | SV-256787r889360_rule | vSphere UI must not be configured with the "UserDatabaseRealm" enabled. |
| ☐ | SV-256788r889363_rule | vSphere UI must be configured to limit access to internal packages. |
| ☐ | SV-256789r889366_rule | vSphere UI must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled. |
| ☐ | SV-256790r889369_rule | vSphere UI must have mappings set for Java servlet pages. |
| ☐ | SV-256791r889372_rule | vSphere UI must not have the Web Distributed Authoring (WebDAV) servlet installed. |
| ☐ | SV-256792r889375_rule | vSphere UI must be configured with memory leak protection. |
| ☐ | SV-256793r889378_rule | vSphere UI must not have any symbolic links in the web content directory tree. |
| ☐ | SV-256794r889381_rule | The vSphere UI directory tree must have permissions in an out-of-the-box state. |
| ☐ | SV-256795r889384_rule | vSphere UI must restrict its cookie path. |
| ☐ | SV-256796r889387_rule | vSphere UI must fail to a known safe state if system initialization fails, shutdown fails, or aborts fail. |
| ☐ | SV-256797r889390_rule | vSphere UI must limit the number of allowed connections. |
| ☐ | SV-256798r889393_rule | vSphere UI must set URIEncoding to UTF-8. |
| ☐ | SV-256799r889396_rule | vSphere UI must set the welcome-file node to a default web page. |
| ☐ | SV-256800r889399_rule | The vSphere UI must not show directory listings. |
| ☐ | SV-256801r889402_rule | vSphere UI must be configured to hide the server version. |
| ☐ | SV-256802r889405_rule | vSphere UI must be configured to show error pages with minimal information. |
| ☐ | SV-256803r889408_rule | vSphere UI must not enable support for TRACE requests. |
| ☐ | SV-256804r889411_rule | vSphere UI must have the debug option turned off. |
| ☐ | SV-256805r889414_rule | vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server. |
| ☐ | SV-256806r889417_rule | vSphere UI log files must be moved to a permanent repository in accordance with site policy. |
| ☐ | SV-256807r889420_rule | vSphere UI must be configured with the appropriate ports. |
| ☐ | SV-256808r889423_rule | vSphere UI must disable the shutdown port. |
| ☐ | SV-256809r889426_rule | vSphere UI must set the secure flag for cookies. |
| ☐ | SV-256810r889429_rule | The vSphere UI default servlet must be set to "readonly". |