STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-258801r958368_ruleThe Photon operating system must audit all account creations.
SV-258802r958388_ruleThe Photon operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-258803r958390_ruleThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.
SV-258804r958398_ruleThe Photon operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
SV-258805r958406_ruleThe Photon operating system must monitor remote access logins.
SV-258806r958408_ruleThe Photon operating system must have the OpenSSL FIPS provider installed to protect the confidentiality of remote access sessions.
SV-258807r958412_ruleThe Photon operating system must configure auditd to log to disk.
SV-258808r1015938_ruleThe Photon operating system must enable the auditd service.
SV-258809r958422_ruleThe Photon operating system must be configured to audit the execution of privileged functions.
SV-258810r958424_ruleThe Photon operating system must alert the ISSO and SA in the event of an audit processing failure.
SV-258811r958434_ruleThe Photon operating system must protect audit logs from unauthorized access.
SV-258812r958444_ruleThe Photon operating system must allow only authorized users to configure the auditd service.
SV-258813r958446_ruleThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-258814r1015939_ruleThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
SV-258815r1015940_ruleThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.
SV-258816r1015941_ruleThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.
SV-258817r1015942_ruleThe Photon operating system must require the change of at least eight characters when passwords are changed.
SV-258818r1015943_ruleThe operating system must store only encrypted representations of passwords.
SV-258819r987796_ruleThe Photon operating system must not have the telnet package installed.
SV-258820r1015944_ruleThe Photon operating system must enforce one day as the minimum password lifetime.
SV-258821r1038967_ruleThe Photon operating systems must enforce a 90-day maximum password lifetime restriction.
SV-258822r1003637_ruleThe Photon operating system must prohibit password reuse for a minimum of five generations.
SV-258823r1015946_ruleThe Photon operating system must enforce a minimum 15-character password length.
SV-258824r1137691_ruleThe Photon operating system must require authentication upon booting into single-user and maintenance modes.
SV-258825r1003641_ruleThe Photon operating system must disable unnecessary kernel modules.
SV-258826r958482_ruleThe Photon operating system must not have duplicate User IDs (UIDs).
SV-258827r971535_ruleThe Photon operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
SV-258828r1137695_ruleThe Photon operating system must restrict access to the kernel message buffer.
SV-258829r958528_ruleThe Photon operating system must be configured to use TCP syncookies.
SV-258830r970703_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions after 15 minutes.
SV-258831r958564_ruleThe Photon operating system /var/log directory must be restricted.
SV-258832r958566_ruleThe Photon operating system must reveal error messages only to authorized users.
SV-258833r991551_ruleThe Photon operating system must audit all account modifications.
SV-258834r991553_ruleThe Photon operating system must audit all account removal actions.
SV-258835r991554_ruleThe Photon operating system must implement only approved ciphers to protect the integrity of remote access sessions.
SV-258836r991555_ruleThe Photon operating system must initiate session audits at system startup.
SV-258837r991557_ruleThe Photon operating system must protect audit tools from unauthorized access.
SV-258838r1015947_ruleThe Photon operating system must enforce password complexity by requiring that at least one special character be used.
SV-258839r991567_ruleThe Photon operating system must use cryptographic mechanisms to protect the integrity of audit tools.
SV-258840r1003643_ruleThe operating system must automatically terminate a user session after inactivity time-outs have expired.
SV-258841r958726_ruleThe Photon operating system must enable symlink access control protection in the kernel.
SV-258842r1003645_ruleThe Photon operating system must audit the execution of privileged functions.
SV-258843r958736_ruleThe Photon operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
SV-258844r958752_ruleThe Photon operating system must allocate audit record storage capacity to store audit records when audit records are not immediately sent to a central audit record storage facility.
SV-258845r971542_ruleThe Photon operating system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-258846r1015948_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.
SV-258847r1050789_ruleThe Photon operating system must require users to reauthenticate for privilege escalation.
SV-258848r958928_ruleThe Photon operating system must implement address space layout randomization to protect its memory from unauthorized code execution.
SV-258849r958936_ruleThe Photon operating system must remove all software components after updated versions have been installed.
SV-258850r991578_ruleThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.
SV-258851r991580_ruleThe Photon operating system must be configured to audit the loading and unloading of dynamic kernel modules.
SV-258852r1137699_ruleThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SV-258853r991587_ruleThe Photon operating system must prevent the use of dictionary words for passwords.
SV-258854r991588_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt in login.defs.
SV-258855r991589_ruleThe Photon operating system must ensure audit events are flushed to disk at proper intervals.
SV-258856r991590_ruleThe Photon operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-258857r991591_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow HostbasedAuthentication.
SV-258858r1210418_ruleThe Photon operating system must be configured to use the pam_faillock.so module.
SV-258859r958388_ruleThe Photon operating system must prevent leaking information of the existence of a user account.
SV-258860r958388_ruleThe Photon operating system must audit logon attempts for unknown users.
SV-258861r958388_ruleThe Photon operating system must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
SV-258862r1003649_ruleThe Photon operating system must persist lockouts between system reboots.
SV-258863r1015950_ruleThe Photon operating system must be configured to use the pam_pwquality.so module.
SV-258864r1015951_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos.
SV-258865r1003652_ruleThe Photon operating system must configure the Secure Shell (SSH) SyslogFacility.
SV-258866r958406_ruleThe Photon operating system must enable Secure Shell (SSH) authentication logging.
SV-258867r970703_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions.
SV-258868r991551_ruleThe Photon operating system must audit all account modifications.
SV-258869r1210420_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-258870r991591_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow authentication with an empty password.
SV-258871r991591_ruleThe Photon operating system must configure Secure Shell (SSH) to disable user environment processing.
SV-258872r991589_ruleThe Photon operating system must create a home directory for all new local interactive user accounts.
SV-258873r991589_ruleThe Photon operating system must disable the debug-shell service.
SV-258874r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.
SV-258875r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disable X11 forwarding.
SV-258876r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to perform strict mode checking of home directory configuration files.
SV-258877r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Kerberos authentication.
SV-258878r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow compression of the encrypted session stream.
SV-258879r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to display the last login immediately after authentication.
SV-258880r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific trusted hosts lists.
SV-258881r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific known_host files.
SV-258882r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to limit the number of allowed login attempts per connection.
SV-258883r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict AllowTcpForwarding.
SV-258884r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict LoginGraceTime.
SV-258885r991589_ruleThe Photon operating system must be configured so that the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.
SV-258886r991589_ruleThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.
SV-258887r991589_ruleThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-258888r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-258889r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.
SV-258890r991589_ruleThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.
SV-258891r991589_ruleThe Photon operating system must log IPv4 packets with impossible addresses.
SV-258892r991589_ruleThe Photon operating system must use a reverse-path filter for IPv4 network traffic.
SV-258893r991589_ruleThe Photon operating system must not perform IPv4 packet forwarding.
SV-258894r991589_ruleThe Photon operating system must send TCP timestamps.
SV-258895r991589_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.
SV-258896r991589_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) private host key from unauthorized access.
SV-258897r991589_ruleThe Photon operating system must enforce password complexity on the root account.
SV-258898r991589_ruleThe Photon operating system must disable systemd fallback DNS.
SV-258899r991589_ruleThe Photon operating system must generate audit records for all access and modifications to the opasswd file.
SV-258900r991554_ruleThe Photon operating system must implement only approved Message Authentication Codes (MACs) to protect the integrity of remote access sessions.
SV-258901r991589_ruleThe Photon operating system must enable the rsyslog service.
SV-258902r1003655_ruleThe Photon operating system must be configured to use the pam_pwhistory.so module.
SV-258903r991589_ruleThe Photon operating system must enable hardlink access control protection in the kernel.
SV-258904r1210423_ruleThe Photon operating system must restrict core dumps.
SV-266062r1003658_ruleThe Photon operating system must configure AIDE to detect changes to baseline configurations.
SV-266063r1003661_ruleThe Photon operating system must not allow empty passwords.
SV-285222r1210426_ruleThe Photon operating system must be configured to use the pam_deny.so module.