STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 31 Oct 2023

CheckedNameTitle
SV-258801r933464_ruleThe Photon operating system must audit all account creations.
SV-258802r933467_ruleThe Photon operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-258803r933470_ruleThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.
SV-258804r933473_ruleThe Photon operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
SV-258805r933476_ruleThe Photon operating system must monitor remote access logins.
SV-258806r933479_ruleThe Photon operating system must have the OpenSSL FIPS provider installed to protect the confidentiality of remote access sessions.
SV-258807r933482_ruleThe Photon operating system must configure auditd to log to disk.
SV-258808r933485_ruleThe Photon operating system must enable the auditd service.
SV-258809r933488_ruleThe Photon operating system must be configured to audit the execution of privileged functions.
SV-258810r933491_ruleThe Photon operating system must alert the ISSO and SA in the event of an audit processing failure.
SV-258811r933494_ruleThe Photon operating system must protect audit logs from unauthorized access.
SV-258812r933497_ruleThe Photon operating system must allow only authorized users to configure the auditd service.
SV-258813r933500_ruleThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-258814r933503_ruleThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
SV-258815r933506_ruleThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.
SV-258816r933509_ruleThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.
SV-258817r933512_ruleThe Photon operating system must require the change of at least eight characters when passwords are changed.
SV-258818r933515_ruleThe operating system must store only encrypted representations of passwords.
SV-258819r933518_ruleThe Photon operating system must not have the telnet package installed.
SV-258820r933521_ruleThe Photon operating system must enforce one day as the minimum password lifetime.
SV-258821r933524_ruleThe Photon operating systems must enforce a 90-day maximum password lifetime restriction.
SV-258822r933527_ruleThe Photon operating system must prohibit password reuse for a minimum of five generations.
SV-258823r933530_ruleThe Photon operating system must enforce a minimum 15-character password length.
SV-258824r933533_ruleThe Photon operating system must require authentication upon booting into single-user and maintenance modes.
SV-258825r933536_ruleThe Photon operating system must disable unnecessary kernel modules.
SV-258826r933539_ruleThe Photon operating system must not have duplicate User IDs (UIDs).
SV-258827r933542_ruleThe Photon operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
SV-258828r933545_ruleThe Photon operating system must restrict access to the kernel message buffer.
SV-258829r933548_ruleThe Photon operating system must be configured to use TCP syncookies.
SV-258830r933551_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions after 15 minutes.
SV-258831r933554_ruleThe Photon operating system /var/log directory must be restricted.
SV-258832r933557_ruleThe Photon operating system must reveal error messages only to authorized users.
SV-258833r933560_ruleThe Photon operating system must audit all account modifications.
SV-258834r933563_ruleThe Photon operating system must audit all account removal actions.
SV-258835r933566_ruleThe Photon operating system must implement only approved ciphers to protect the integrity of remote access sessions.
SV-258836r933569_ruleThe Photon operating system must initiate session audits at system startup.
SV-258837r933572_ruleThe Photon operating system must protect audit tools from unauthorized access.
SV-258838r933575_ruleThe Photon operating system must enforce password complexity by requiring that at least one special character be used.
SV-258839r933578_ruleThe Photon operating system must use cryptographic mechanisms to protect the integrity of audit tools.
SV-258840r933581_ruleThe operating system must automatically terminate a user session after inactivity time-outs have expired.
SV-258841r933584_ruleThe Photon operating system must enable symlink access control protection in the kernel.
SV-258842r933587_ruleThe Photon operating system must audit the execution of privileged functions.
SV-258843r933590_ruleThe Photon operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
SV-258844r933593_ruleThe Photon operating system must allocate audit record storage capacity to store audit records when audit records are not immediately sent to a central audit record storage facility.
SV-258845r935564_ruleThe Photon operating system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-258846r933599_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.
SV-258847r933602_ruleThe Photon operating system must require users to reauthenticate for privilege escalation.
SV-258848r933605_ruleThe Photon operating system must implement address space layout randomization to protect its memory from unauthorized code execution.
SV-258849r933608_ruleThe Photon operating system must remove all software components after updated versions have been installed.
SV-258850r933611_ruleThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.
SV-258851r933614_ruleThe Photon operating system must be configured to audit the loading and unloading of dynamic kernel modules.
SV-258852r933617_ruleThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-258853r933620_ruleThe Photon operating system must prevent the use of dictionary words for passwords.
SV-258854r933623_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt in login.defs.
SV-258855r933626_ruleThe Photon operating system must ensure audit events are flushed to disk at proper intervals.
SV-258856r933629_ruleThe Photon operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-258857r933632_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow HostbasedAuthentication.
SV-258858r933635_ruleThe Photon operating system must be configured to use the pam_faillock.so module.
SV-258859r933638_ruleThe Photon operating system must prevent leaking information of the existence of a user account.
SV-258860r933641_ruleThe Photon operating system must audit logon attempts for unknown users.
SV-258861r933644_ruleThe Photon operating system must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
SV-258862r933647_ruleThe Photon operating system must persist lockouts between system reboots.
SV-258863r933650_ruleThe Photon operating system must be configured to use the pam_pwquality.so module.
SV-258864r933653_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos.
SV-258865r933656_ruleThe Photon operating system must configure the Secure Shell (SSH) SyslogFacility.
SV-258866r933659_ruleThe Photon operating system must enable Secure Shell (SSH) authentication logging.
SV-258867r933662_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions.
SV-258868r933665_ruleThe Photon operating system must audit all account modifications.
SV-258869r933668_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-258870r933671_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow authentication with an empty password.
SV-258871r933674_ruleThe Photon operating system must configure Secure Shell (SSH) to disable user environment processing.
SV-258872r933677_ruleThe Photon operating system must create a home directory for all new local interactive user accounts.
SV-258873r933680_ruleThe Photon operating system must disable the debug-shell service.
SV-258874r933683_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.
SV-258875r933686_ruleThe Photon operating system must configure Secure Shell (SSH) to disable X11 forwarding.
SV-258876r933689_ruleThe Photon operating system must configure Secure Shell (SSH) to perform strict mode checking of home directory configuration files.
SV-258877r933692_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Kerberos authentication.
SV-258878r933695_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow compression of the encrypted session stream.
SV-258879r933698_ruleThe Photon operating system must configure Secure Shell (SSH) to display the last login immediately after authentication.
SV-258880r933701_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific trusted hosts lists.
SV-258881r935567_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific known_host files.
SV-258882r933707_ruleThe Photon operating system must configure Secure Shell (SSH) to limit the number of allowed login attempts per connection.
SV-258883r933710_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict AllowTcpForwarding.
SV-258884r933713_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict LoginGraceTime.
SV-258885r933716_ruleThe Photon operating system must be configured so that the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.
SV-258886r933719_ruleThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.
SV-258887r933722_ruleThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-258888r933725_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-258889r933728_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.
SV-258890r933731_ruleThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.
SV-258891r933734_ruleThe Photon operating system must log IPv4 packets with impossible addresses.
SV-258892r933737_ruleThe Photon operating system must use a reverse-path filter for IPv4 network traffic.
SV-258893r933740_ruleThe Photon operating system must not perform IPv4 packet forwarding.
SV-258894r933743_ruleThe Photon operating system must send TCP timestamps.
SV-258895r933746_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.
SV-258896r933749_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) private host key from unauthorized access.
SV-258897r933752_ruleThe Photon operating system must enforce password complexity on the root account.
SV-258898r935569_ruleThe Photon operating system must disable systemd fallback DNS.
SV-258899r933758_ruleThe Photon operating system must generate audit records for all access and modifications to the opasswd file.
SV-258900r933761_ruleThe Photon operating system must implement only approved Message Authentication Codes (MACs) to protect the integrity of remote access sessions.
SV-258901r933764_ruleThe Photon operating system must enable the rsyslog service.
SV-258902r933767_ruleThe Photon operating system must be configured to use the pam_pwhistory.so module.
SV-258903r933770_ruleThe Photon operating system must enable hardlink access control protection in the kernel.
SV-258904r933773_ruleThe Photon operating system must restrict core dumps.