STIGQter STIGQter: STIG Summary:

VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 01 Jul 2026

CheckedNameTitle
☐SV-258801r958368_ruleThe Photon operating system must audit all account creations.
☐SV-258802r958388_ruleThe Photon operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
☐SV-258803r958390_ruleThe Photon operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.
☐SV-258804r958398_ruleThe Photon operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
☐SV-258805r958406_ruleThe Photon operating system must monitor remote access logins.
☐SV-258806r958408_ruleThe Photon operating system must have the OpenSSL FIPS provider installed to protect the confidentiality of remote access sessions.
☐SV-258807r958412_ruleThe Photon operating system must configure auditd to log to disk.
☐SV-258808r1015938_ruleThe Photon operating system must enable the auditd service.
☐SV-258809r958422_ruleThe Photon operating system must be configured to audit the execution of privileged functions.
☐SV-258810r958424_ruleThe Photon operating system must alert the ISSO and SA in the event of an audit processing failure.
☐SV-258811r958434_ruleThe Photon operating system must protect audit logs from unauthorized access.
☐SV-258812r958444_ruleThe Photon operating system must allow only authorized users to configure the auditd service.
☐SV-258813r958446_ruleThe Photon operating system must generate audit records when successful/unsuccessful attempts to access privileges occur.
☐SV-258814r1015939_ruleThe Photon operating system must enforce password complexity by requiring that at least one uppercase character be used.
☐SV-258815r1015940_ruleThe Photon operating system must enforce password complexity by requiring that at least one lowercase character be used.
☐SV-258816r1015941_ruleThe Photon operating system must enforce password complexity by requiring that at least one numeric character be used.
☐SV-258817r1015942_ruleThe Photon operating system must require the change of at least eight characters when passwords are changed.
☐SV-258818r1015943_ruleThe operating system must store only encrypted representations of passwords.
☐SV-258819r987796_ruleThe Photon operating system must not have the telnet package installed.
☐SV-258820r1015944_ruleThe Photon operating system must enforce one day as the minimum password lifetime.
☐SV-258821r1038967_ruleThe Photon operating systems must enforce a 90-day maximum password lifetime restriction.
☐SV-258822r1003637_ruleThe Photon operating system must prohibit password reuse for a minimum of five generations.
☐SV-258823r1015946_ruleThe Photon operating system must enforce a minimum 15-character password length.
☐SV-258824r1137691_ruleThe Photon operating system must require authentication upon booting into single-user and maintenance modes.
☐SV-258825r1003641_ruleThe Photon operating system must disable unnecessary kernel modules.
☐SV-258826r958482_ruleThe Photon operating system must not have duplicate User IDs (UIDs).
☐SV-258827r971535_ruleThe Photon operating system must use mechanisms meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.
☐SV-258828r1137695_ruleThe Photon operating system must restrict access to the kernel message buffer.
☐SV-258829r958528_ruleThe Photon operating system must be configured to use TCP syncookies.
☐SV-258830r970703_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions after 15 minutes.
☐SV-258831r958564_ruleThe Photon operating system /var/log directory must be restricted.
☐SV-258832r958566_ruleThe Photon operating system must reveal error messages only to authorized users.
☐SV-258833r991551_ruleThe Photon operating system must audit all account modifications.
☐SV-258834r991553_ruleThe Photon operating system must audit all account removal actions.
☐SV-258835r991554_ruleThe Photon operating system must implement only approved ciphers to protect the integrity of remote access sessions.
☐SV-258836r991555_ruleThe Photon operating system must initiate session audits at system startup.
☐SV-258837r991557_ruleThe Photon operating system must protect audit tools from unauthorized access.
☐SV-258838r1015947_ruleThe Photon operating system must enforce password complexity by requiring that at least one special character be used.
☐SV-258839r991567_ruleThe Photon operating system must use cryptographic mechanisms to protect the integrity of audit tools.
☐SV-258840r1003643_ruleThe operating system must automatically terminate a user session after inactivity time-outs have expired.
☐SV-258841r958726_ruleThe Photon operating system must enable symlink access control protection in the kernel.
☐SV-258842r1003645_ruleThe Photon operating system must audit the execution of privileged functions.
☐SV-258843r958736_ruleThe Photon operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
☐SV-258844r958752_ruleThe Photon operating system must allocate audit record storage capacity to store audit records when audit records are not immediately sent to a central audit record storage facility.
☐SV-258845r971542_ruleThe Photon operating system must immediately notify the SA and ISSO when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
☐SV-258846r1015948_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.
☐SV-258847r1050789_ruleThe Photon operating system must require users to reauthenticate for privilege escalation.
☐SV-258848r958928_ruleThe Photon operating system must implement address space layout randomization to protect its memory from unauthorized code execution.
☐SV-258849r958936_ruleThe Photon operating system must remove all software components after updated versions have been installed.
☐SV-258850r991578_ruleThe Photon operating system must generate audit records when successful/unsuccessful logon attempts occur.
☐SV-258851r991580_ruleThe Photon operating system must be configured to audit the loading and unloading of dynamic kernel modules.
☐SV-258852r1137699_ruleThe Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
☐SV-258853r991587_ruleThe Photon operating system must prevent the use of dictionary words for passwords.
☐SV-258854r991588_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt in login.defs.
☐SV-258855r991589_ruleThe Photon operating system must ensure audit events are flushed to disk at proper intervals.
☐SV-258856r991590_ruleThe Photon operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
☐SV-258857r991591_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow HostbasedAuthentication.
☐SV-258858r1210418_ruleThe Photon operating system must be configured to use the pam_faillock.so module.
☐SV-258859r958388_ruleThe Photon operating system must prevent leaking information of the existence of a user account.
☐SV-258860r958388_ruleThe Photon operating system must audit logon attempts for unknown users.
☐SV-258861r958388_ruleThe Photon operating system must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-258862r1003649_ruleThe Photon operating system must persist lockouts between system reboots.
☐SV-258863r1015950_ruleThe Photon operating system must be configured to use the pam_pwquality.so module.
☐SV-258864r1015951_ruleThe Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation for all repos.
☐SV-258865r1003652_ruleThe Photon operating system must configure the Secure Shell (SSH) SyslogFacility.
☐SV-258866r958406_ruleThe Photon operating system must enable Secure Shell (SSH) authentication logging.
☐SV-258867r970703_ruleThe Photon operating system must terminate idle Secure Shell (SSH) sessions.
☐SV-258868r991551_ruleThe Photon operating system must audit all account modifications.
☐SV-258869r1210420_ruleThe Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
☐SV-258870r991591_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow authentication with an empty password.
☐SV-258871r991591_ruleThe Photon operating system must configure Secure Shell (SSH) to disable user environment processing.
☐SV-258872r991589_ruleThe Photon operating system must create a home directory for all new local interactive user accounts.
☐SV-258873r991589_ruleThe Photon operating system must disable the debug-shell service.
☐SV-258874r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Generic Security Service Application Program Interface (GSSAPI) authentication.
☐SV-258875r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disable X11 forwarding.
☐SV-258876r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to perform strict mode checking of home directory configuration files.
☐SV-258877r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow Kerberos authentication.
☐SV-258878r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to disallow compression of the encrypted session stream.
☐SV-258879r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to display the last login immediately after authentication.
☐SV-258880r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific trusted hosts lists.
☐SV-258881r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to ignore user-specific known_host files.
☐SV-258882r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to limit the number of allowed login attempts per connection.
☐SV-258883r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict AllowTcpForwarding.
☐SV-258884r991589_ruleThe Photon operating system must configure Secure Shell (SSH) to restrict LoginGraceTime.
☐SV-258885r991589_ruleThe Photon operating system must be configured so that the x86 Ctrl-Alt-Delete key sequence is disabled on the command line.
☐SV-258886r991589_ruleThe Photon operating system must not forward IPv4 or IPv6 source-routed packets.
☐SV-258887r991589_ruleThe Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
☐SV-258888r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
☐SV-258889r991589_ruleThe Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.
☐SV-258890r991589_ruleThe Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.
☐SV-258891r991589_ruleThe Photon operating system must log IPv4 packets with impossible addresses.
☐SV-258892r991589_ruleThe Photon operating system must use a reverse-path filter for IPv4 network traffic.
☐SV-258893r991589_ruleThe Photon operating system must not perform IPv4 packet forwarding.
☐SV-258894r991589_ruleThe Photon operating system must send TCP timestamps.
☐SV-258895r991589_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) public host key from unauthorized modification.
☐SV-258896r991589_ruleThe Photon operating system must be configured to protect the Secure Shell (SSH) private host key from unauthorized access.
☐SV-258897r991589_ruleThe Photon operating system must enforce password complexity on the root account.
☐SV-258898r991589_ruleThe Photon operating system must disable systemd fallback DNS.
☐SV-258899r991589_ruleThe Photon operating system must generate audit records for all access and modifications to the opasswd file.
☐SV-258900r991554_ruleThe Photon operating system must implement only approved Message Authentication Codes (MACs) to protect the integrity of remote access sessions.
☐SV-258901r991589_ruleThe Photon operating system must enable the rsyslog service.
☐SV-258902r1003655_ruleThe Photon operating system must be configured to use the pam_pwhistory.so module.
☐SV-258903r991589_ruleThe Photon operating system must enable hardlink access control protection in the kernel.
☐SV-258904r1210423_ruleThe Photon operating system must restrict core dumps.
☐SV-266062r1003658_ruleThe Photon operating system must configure AIDE to detect changes to baseline configurations.
☐SV-266063r1003661_ruleThe Photon operating system must not allow empty passwords.
☐SV-285222r1210426_ruleThe Photon operating system must be configured to use the pam_deny.so module.