STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 31 Oct 2023

CheckedNameTitle
☐SV-258801r933464_ruleThe Photon operating system must audit all account creations.
☐SV-258802r933467_ruleThe Photon operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
☐SV-258803r933470_ruleThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.
☐SV-258804r933473_ruleThe Photon operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
☐SV-258805r933476_ruleThe Photon operating system must monitor remote access logins.
☐SV-258806r933479_ruleThe Photon operating system must have the OpenSSL FIPS provider installed to protect the confidentiality of remote access sessions.
☐SV-258807r933482_ruleThe Photon operating system must configure auditd to log to disk.
☐SV-258808r933485_ruleThe Photon operating system must enable the auditd service.
☐SV-258809r933488_ruleThe Photon operating system must be configured to audit the execution of privileged functions.
☐SV-258810r933491_ruleThe Photon operating system must alert the ISSO and SA in the event of an audit processing failure.
☐SV-258811r933494_ruleThe Photon operating system must protect audit logs from unauthorized access.
☐SV-258812r933497_ruleThe Photon operating system must allow only authorized users to configure the auditd service.
☐SV-258813r933500_ruleThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
☐SV-258814r933503_ruleThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
☐SV-258815r933506_ruleThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.
☐SV-258816r933509_ruleThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.
☐SV-258817r933512_ruleThe Photon operating system must require the change of at least eight characters when passwords are changed.
☐SV-258818r933515_ruleThe operating system must store only encrypted representations of passwords.
☐SV-258819r933518_ruleThe Photon operating system must not have the telnet package installed.
☐SV-258820r933521_ruleThe Photon operating system must enforce one day as the minimum password lifetime.
☐SV-258821r933524_ruleThe Photon operating systems must enforce a 90-day maximum password lifetime restriction.
☐SV-258822r933527_ruleThe Photon operating system must prohibit password reuse for a minimum of five generations.
☐SV-258823r933530_ruleThe Photon operating system must enforce a minimum 15-character password length.
☐SV-258824r933533_ruleThe Photon operating system must require authentication upon booting into single-user and maintenance modes.
☐SV-258825r933536_ruleThe Photon operating system must disable unnecessary kernel modules.
☐SV-258826r933539_ruleThe Photon operating system must not have duplicate User IDs (UIDs).
☐SV-258827r933542_ruleThe Photon operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
☐SV-258828r933545_ruleThe Photon operating system must restrict access to the kernel message buffer.
☐SV-258829r933548_ruleThe Photon operating system must be configured to use TCP syncookies.
☐SV-258830r933551_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions after 15 minutes.
☐SV-258831r933554_ruleThe Photon operating system /var/log directory must be restricted.
☐SV-258832r933557_ruleThe Photon operating system must reveal error messages only to authorized users.
☐SV-258833r933560_ruleThe Photon operating system must audit all account modifications.
☐SV-258834r933563_ruleThe Photon operating system must audit all account removal actions.
☐SV-258835r933566_ruleThe Photon operating system must implement only approved ciphers to protect the integrity of remote access sessions.
☐SV-258836r933569_ruleThe Photon operating system must initiate session audits at system startup.
☐SV-258837r933572_ruleThe Photon operating system must protect audit tools from unauthorized access.
☐SV-258838r933575_ruleThe Photon operating system must enforce password complexity by requiring that at least one special character be used.
☐SV-258839r933578_ruleThe Photon operating system must use cryptographic mechanisms to protect the integrity of audit tools.
☐SV-258840r933581_ruleThe operating system must automatically terminate a user session after inactivity time-outs have expired.
☐SV-258841r933584_ruleThe Photon operating system must enable symlink access control protection in the kernel.
☐SV-258842r933587_ruleThe Photon operating system must audit the execution of privileged functions.
☐SV-258843r933590_ruleThe Photon operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
☐SV-258844r933593_ruleThe Photon operating system must allocate audit record storage capacity to store audit records when audit records are not immediately sent to a central audit record storage facility.
☐SV-258845r935564_ruleThe Photon operating system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
☐SV-258846r933599_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.
☐SV-258847r933602_ruleThe Photon operating system must require users to reauthenticate for privilege escalation.
☐SV-258848r933605_ruleThe Photon operating system must implement address space layout randomization to protect its memory from unauthorized code execution.
☐SV-258849r933608_ruleThe Photon operating system must remove all software components after updated versions have been installed.
☐SV-258850r933611_ruleThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.
☐SV-258851r933614_ruleThe Photon operating system must be configured to audit the loading and unloading of dynamic kernel modules.
☐SV-258852r933617_ruleThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
☐SV-258853r933620_ruleThe Photon operating system must prevent the use of dictionary words for passwords.
☐SV-258854r933623_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt in login.defs.
☐SV-258855r933626_ruleThe Photon operating system must ensure audit events are flushed to disk at proper intervals.
☐SV-258856r933629_ruleThe Photon operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
☐SV-258857r933632_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow HostbasedAuthentication.
☐SV-258858r933635_ruleThe Photon operating system must be configured to use the pam_faillock.so module.
☐SV-258859r933638_ruleThe Photon operating system must prevent leaking information of the existence of a user account.
☐SV-258860r933641_ruleThe Photon operating system must audit logon attempts for unknown users.
☐SV-258861r933644_ruleThe Photon operating system must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-258862r933647_ruleThe Photon operating system must persist lockouts between system reboots.
☐SV-258863r933650_ruleThe Photon operating system must be configured to use the pam_pwquality.so module.
☐SV-258864r933653_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos.
☐SV-258865r933656_ruleThe Photon operating system must configure the Secure Shell (SSH) SyslogFacility.
☐SV-258866r933659_ruleThe Photon operating system must enable Secure Shell (SSH) authentication logging.
☐SV-258867r933662_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions.
☐SV-258868r933665_ruleThe Photon operating system must audit all account modifications.
☐SV-258869r933668_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
☐SV-258870r933671_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow authentication with an empty password.
☐SV-258871r933674_ruleThe Photon operating system must configure Secure Shell (SSH) to disable user environment processing.
☐SV-258872r933677_ruleThe Photon operating system must create a home directory for all new local interactive user accounts.
☐SV-258873r933680_ruleThe Photon operating system must disable the debug-shell service.
☐SV-258874r933683_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.
☐SV-258875r933686_ruleThe Photon operating system must configure Secure Shell (SSH) to disable X11 forwarding.
☐SV-258876r933689_ruleThe Photon operating system must configure Secure Shell (SSH) to perform strict mode checking of home directory configuration files.
☐SV-258877r933692_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Kerberos authentication.
☐SV-258878r933695_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow compression of the encrypted session stream.
☐SV-258879r933698_ruleThe Photon operating system must configure Secure Shell (SSH) to display the last login immediately after authentication.
☐SV-258880r933701_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific trusted hosts lists.
☐SV-258881r935567_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific known_host files.
☐SV-258882r933707_ruleThe Photon operating system must configure Secure Shell (SSH) to limit the number of allowed login attempts per connection.
☐SV-258883r933710_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict AllowTcpForwarding.
☐SV-258884r933713_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict LoginGraceTime.
☐SV-258885r933716_ruleThe Photon operating system must be configured so that the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.
☐SV-258886r933719_ruleThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.
☐SV-258887r933722_ruleThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
☐SV-258888r933725_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
☐SV-258889r933728_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.
☐SV-258890r933731_ruleThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.
☐SV-258891r933734_ruleThe Photon operating system must log IPv4 packets with impossible addresses.
☐SV-258892r933737_ruleThe Photon operating system must use a reverse-path filter for IPv4 network traffic.
☐SV-258893r933740_ruleThe Photon operating system must not perform IPv4 packet forwarding.
☐SV-258894r933743_ruleThe Photon operating system must send TCP timestamps.
☐SV-258895r933746_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.
☐SV-258896r933749_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) private host key from unauthorized access.
☐SV-258897r933752_ruleThe Photon operating system must enforce password complexity on the root account.
☐SV-258898r935569_ruleThe Photon operating system must disable systemd fallback DNS.
☐SV-258899r933758_ruleThe Photon operating system must generate audit records for all access and modifications to the opasswd file.
☐SV-258900r933761_ruleThe Photon operating system must implement only approved Message Authentication Codes (MACs) to protect the integrity of remote access sessions.
☐SV-258901r933764_ruleThe Photon operating system must enable the rsyslog service.
☐SV-258902r933767_ruleThe Photon operating system must be configured to use the pam_pwhistory.so module.
☐SV-258903r933770_ruleThe Photon operating system must enable hardlink access control protection in the kernel.
☐SV-258904r933773_ruleThe Photon operating system must restrict core dumps.